25 Mar 2026, 14:49 UTC27 viewsread 8 August 2026 Photo
🚨 TeamPCP expanded its supply chain attack to Checkmarx GitHub Actions, deploying the same CI credential stealer used in the Trivy breach.
Stolen tokens are reused to push malicious commits into other repos, enabling a cascading compromise across CI workflows.
🔗 Read → https://thehackernews.com/2026/03/teampcp-hacks-checkmarx-github-actions.html
Signed Gløįrę Shÿålęmbęrwą
25 Mar 2026, 14:49 UTC44 viewsread 8 August 2026 Photo
🚨 A malvertising campaign uses tax searches to deliver kernel-level EDR killers via rogue ScreenConnect installers.
Cloaking hides payloads; a signed Huawei driver is abused via BYOVD to disable Defender, Kaspersky, and SentinelOne before credential theft and lateral movement.
🔗 Read → https://thehackernews.com/2026/03/tax-search-ads-deliver-screenconnect.html
Signed Gløįrę Shÿålęmbęrwą
25 Mar 2026, 14:49 UTC86 viewsread 8 August 2026 Photo
🛑 A device code phishing campaign is hitting 340+ Microsoft 365 orgs using OAuth abuse.
Victims enter codes on real Microsoft pages, generating access and refresh tokens attackers reuse—even after password resets.
🔗 Read → https://thehackernews.com/2026/03/device-code-phishing-hits-340-microsoft.html
Signed Gløįrę Shÿålęmbęrwą
25 Mar 2026, 14:49 UTC97 viewsread 8 August 2026 Photo
⚡ A Russian botnet operator tied to #ransomware attacks on U.S. firms has been sentenced.
2 years prison + $100K fine for co-running TA551, which sold access to hacked systems used by gangs like BitPaymer, leading to $14M+ in extortion.
🔗 How TA551 enabled ransomware attacks on 70+ companies → https://thehackernews.com/2026/03/russian-hacker-sentenced-to-2-years-for.html
Signed Gløįrę Shÿålęmbęrwą
25 Mar 2026, 14:49 UTC25 viewsread 8 August 2026 Photo
🛑 A Russian access broker was sentenced to 81 months in U.S. prison for fueling ransomware attacks.
He sold network access to groups like Yanluowang, enabling dozens of intrusions and over $9M in confirmed losses across U.S. organizations.
🔗 Read → https://thehackernews.com/2026/03/us-sentences-russian-hacker-to-675.html
Signed Gløįrę Shÿålęmbęrwą
25 Mar 2026, 14:49 UTC64 viewsread 8 August 2026 Photo
Telegram blocked 43M+ channels in 2025, yet threat actors stayed.
Yochai Corem shows they adapted—rebuilding in days, gating access, and shifting sensitive comms off-platform while keeping Telegram for scale.
🔗 How criminals evolved despite Telegram’s crackdown → https://thehackernews.com/expert-insights/2026/03/telegrams-crackdown-changed-how-threat.html
Signed Gløįrę Shÿålęmbęrwą
25 Mar 2026, 14:49 UTC31 viewsread 8 August 2026 Photo
ActiveState Curated Catalog: Secure Open Source Built From Source.
Introducing the ActiveState Curated Catalog: a vetted source of truth for open-source. Instead of pulling from public registries, your team accesses a private catalog of rebuilt-from-source packages to ensure security and compliance from the start.
Start Free Course: https://thn.news/ai-code-catalogs
Signed Gløįrę Shÿålęmbęrwą
25 Mar 2026, 14:49 UTC35 viewsread 8 August 2026 Video
Security teams are using more tools—but still struggling to prioritize real risk.
Focus is shifting to exposure validation and business impact, not just alerts and scans, as highlighted at Gartner’s first event.
🔗 5 key learnings shaping modern security → https://thehackernews.com/2026/03/5-learnings-from-first-ever-gartner.html
Signed Gløįrę Shÿålęmbęrwą
25 Mar 2026, 14:49 UTC38 viewsread 8 August 2026 Photo
⚠️ ALERT: Fake resumes are infecting enterprise systems and the full attack runs in ~25 seconds.
Obfuscated VBScript deploys credential stealers and a Monero miner, using Dropbox, #WordPress C2, and SMTP for exfiltration. It selectively targets domain-joined machines.
🔗 Read → https://thehackernews.com/2026/03/hackers-use-fake-resumes-to-steal.html
Signed Gløįrę Shÿålęmbęrwą
25 Mar 2026, 14:49 UTC41 views0 reactionsread 8 August 2026 Photo
⚡ Cybersecurity tools improved, but teams still struggle with basics.
Missing understanding of their own systems leads to wrong priorities, poor tool choices, and weak risk focus. More tools do not fix this.
🔗 Why security still breaks without strong foundations → https://thehackernews.com/2026/03/the-hidden-cost-of-cybersecurity.html
Signed Gløįrę Shÿålęmbęrwą
25 Mar 2026, 14:49 UTC48 viewsread 8 August 2026 Photo
🚨 Attackers are abusing npm and GitHub to deliver malware disguised as dev tools.
Sudo password phishing during install triggers a multi-stage chain that deploys a RAT, stealing crypto wallets, credentials, SSH keys, and tokens.
🔗 Read → https://thehackernews.com/2026/03/ghost-campaign-uses-7-npm-packages-to.html
Signed Gløįrę Shÿålęmbęrwą
25 Mar 2026, 14:49 UTC53 viewsread 8 August 2026 Photo
🛑 Malicious LiteLLM versions 1.82.7–1.82.8 deploy credential theft, Kubernetes lateral movement, and a persistent backdoor.
Linked to the Trivy CI/CD compromise, the payload runs on import or via .pth at Python startup, spreads across nodes, and installs a systemd service.
🔗 Full story → https://thehackernews.com/2026/03/teampcp-backdoors-litellm-versions.html
Signed Gløįrę Shÿålęmbęrwą
Showing the 12 most recent of 20 posts we hold for @glorysky25. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.