Cybersecurity briefing — 2026-03-28
Here's your PlainSec briefing for Saturday, March 28th.
TeamPCP Pauses New Supply-Chain Compromises, Monetizes Haul
CISA Adds BIG‑IP APM RCE to Known Exploited Vulnerabilities
Coruna Exploit Kit Recycles Triangulation iOS Zero‑Days
Langflow RCE Added to CISA Known Exploited Catalog
TeamPCP Injects Credential-Stealer into LiteLLM Package
Cloudflare-Themed Lures Install Python Infostealer on macOS
China‑Linked Red Menshen Embeds Stealthy Implants in Telecom Cores
Citrix NetScaler Flaws Risk Memory Disclosure and Session Mix‑up
Nation-States Hijack IP Cameras for Battlefield Intelligence
Xinbi campaign update
Defender Adds Asset-Aware Protections for High-Value Systems
Pay2Key Re-emerges; Bearlyfy Escalates Ransomware Campaign
Open VSX Bug Lets Malicious VS Code Extensions Bypass Pre-Publish Checks
Phishing Campaign Hijacks TikTok Business Accounts
Cybersecurity briefing — 2026-03-28
Here's your PlainSec briefing for Saturday, March 28th.
TeamPCP Pauses New Supply-Chain Compromises, Monetizes Haul
CISA Adds BIG‑IP APM RCE to Known Exploited Vulnerabilities
Coruna Exploit Kit Recycles Triangulation iOS Zero‑Days
Langflow RCE Added to CISA Known Exploited Catalog
TeamPCP Injects Credential-Stealer into LiteLLM Package
Cloudflare-Themed Lures Install Python Infostealer on macOS
China‑Linked Red Menshen Embeds Stealthy Implants in Telecom Cores
Citrix NetScaler Flaws Risk Memory Disclosure and Session Mix‑up
Nation-States Hijack IP Cameras for Battlefield Intelligence
Xinbi campaign update
Defender Adds Asset-Aware Protections for High-Value Systems
Pay2Key Re-emerges; Bearlyfy Escalates Ransomware Campaign
Open VSX Bug Lets Malicious VS Code Extensions Bypass Pre-Publish Checks
Phishing Campaign Hijacks TikTok Business Accounts