Cybersecurity briefing — 2026-03-27
Here's your PlainSec briefing for Friday, March 27th.
Coruna Exploit Kit Recycles Triangulation iOS Zero‑Days
Trivy GitHub Actions Compromise Exposes CI/CD Secrets
Langflow Code-Injection Flaw Actively Exploited After Disclosure
TeamPCP Injects Credential-Stealer into LiteLLM Package
Unauthenticated RCE in Secure Firewall Management Center
China‑Linked Red Menshen Embeds Stealthy Implants in Telecom Cores
All Checkmarx Action Tags Overwritten in TeamPCP Supply-Chain Compromise
Immediate Attacks Target Oracle WebLogic RCE Flaw
Xinbi campaign update
Pay2Key Re-emerges; Bearlyfy Escalates Ransomware Campaign
Nation-States Hijack IP Cameras for Battlefield Intelligence
ChromeOS LTC-144 Rollout Starts for Most Devices
WAGO Switches Vulnerability Allows Full Device Compromise
Magento Stores Hit by WebRTC Payment Skimmer Exploiting PolyShell
China-Linked Hackers Embed Kernel Implants in Telecom Backbone
OpenCode Messaging Flaw Lets Users Access Other Tenants' SMS
Armenian Extradited for Administering RedLine Infostealer
Defender Adds Asset-Aware Protections for High-Value Systems
Southeast Asian Government Targeted by Multiple Espionage Clusters
New Phishing Campaign Targets TikTok for Business Accounts
Iranian Handala Breaches FBI Director's Gmail; Targets Journalists
Open VSX Bug Lets Malicious VS Code Extensions Bypass Pre-Publish Checks
Supply-Chain Malware in LiteLLM Harvests Cloud Credentials
Hackers Release 93GB of Tip Data from P3 Platform
Phishing Campaign Hijacks TikTok Business Accounts
Ajax Breach Exposes Fan Data and Season Tickets
BIND Updates Patch Two High-Severity DNSSEC DoS Flaws
USB-Worm Backdoor and Keylogger Compromise Financial Institution
TP‑Link Patches Archer NX Routers Against Authentication Bypass
Iran-Aligned Actors Ramp Up Phishing and Disruption
Citrix NetScaler Flaws Risk Memory Disclosure and Session Mix‑up
Cybersecurity briefing — 2026-03-27
Here's your PlainSec briefing for Friday, March 27th.
Coruna Exploit Kit Recycles Triangulation iOS Zero‑Days
Trivy GitHub Actions Compromise Exposes CI/CD Secrets
Langflow Code-Injection Flaw Actively Exploited After Disclosure
TeamPCP Injects Credential-Stealer into LiteLLM Package
Unauthenticated RCE in Secure Firewall Management Center
China‑Linked Red Menshen Embeds Stealthy Implants in Telecom Cores
All Checkmarx Action Tags Overwritten in TeamPCP Supply-Chain Compromise
Immediate Attacks Target Oracle WebLogic RCE Flaw
Xinbi campaign update
Pay2Key Re-emerges; Bearlyfy Escalates Ransomware Campaign
Nation-States Hijack IP Cameras for Battlefield Intelligence
ChromeOS LTC-144 Rollout Starts for Most Devices
WAGO Switches Vulnerability Allows Full Device Compromise
Magento Stores Hit by WebRTC Payment Skimmer Exploiting PolyShell
China-Linked Hackers Embed Kernel Implants in Telecom Backbone
OpenCode Messaging Flaw Lets Users Access Other Tenants' SMS
Armenian Extradited for Administering RedLine Infostealer
Defender Adds Asset-Aware Protections for High-Value Systems
Southeast Asian Government Targeted by Multiple Espionage Clusters
New Phishing Campaign Targets TikTok for Business Accounts
Iranian Handala Breaches FBI Director's Gmail; Targets Journalists
Open VSX Bug Lets Malicious VS Code Extensions Bypass Pre-Publish Checks
Supply-Chain Malware in LiteLLM Harvests Cloud Credentials
Hackers Release 93GB of Tip Data from P3 Platform
Phishing Campaign Hijacks TikTok Business Accounts
Ajax Breach Exposes Fan Data and Season Tickets
BIND Updates Patch Two High-Severity DNSSEC DoS Flaws
USB-Worm Backdoor and Keylogger Compromise Financial Institution
TP‑Link Patches Archer NX Routers Against Authentication Bypass
Iran-Aligned Actors Ramp Up Phishing and Disruption
Citrix NetScaler Flaws Risk Memory Disclosure and Session Mix‑up