North Korean Hackers Leverage VS Code for StoatWaffle Malware Distribution

North Korean Hackers Leverage VS Code for StoatWaffle Malware Distribution Introduction The emergence of sophisticated cyber threats from state-sponsored actors has raised alarms within the cybersecurity community. Among these threats, North Korean hackers have been increasingly motivated by financial gain and strategic objectives. The latest report attributes the deployment of StoatWaffle malware to these actors…

Critical Vulnerability in Quest KACE Systems Management Appliance Under Attack

Critical Vulnerability in Quest KACE Systems Management Appliance Under Attack Overview of the Vulnerability Threat actors are reportedly exploiting a critical security flaw, identified as CVE-2025-32975, which has been assigned a maximum CVSS score of 10.0. This vulnerability affects the Quest KACE Systems Management Appliance (SMA), leading to concerns regarding its potential impact on organizations…

Security Compromise of Trivy Vulnerability Scanner: Implications and Risks

Security Compromise of Trivy Vulnerability Scanner: Implications and Risks Introduction to the Incident On March 21, 2026, reports emerged of a significant breach affecting the Trivy vulnerability scanner, a widely used tool in the development community for identifying security vulnerabilities in software dependencies. This incident involved a supply-chain attack orchestrated by a group known as…

Trivy Security Scanner Incident: Implications of the GitHub Actions Breach

Trivy Security Scanner Incident: Implications of the GitHub Actions Breach Background and Context Trivy, an open-source vulnerability scanner developed by Aqua Security, is widely utilized in DevOps environments to identify security vulnerabilities within container images. With the growing prevalence of containerization and continuous integration/continuous deployment (CI/CD) processes, tools like Trivy have become integral to maintaining…

U.S. DoJ Disrupts Major IoT Botnets Behind Record DDoS Attacks

U.S. DoJ Disrupts Major IoT Botnets Behind Record DDoS Attacks Introduction On March 20, 2026, the U.S. Department of Justice (DoJ) announced a significant operation that disrupted the command-and-control (C2) infrastructure of multiple Internet of Things (IoT) botnets, including AISURU, Kimwolf, JackSkid, and Mossad. This coordinated effort, which involved collaboration with Canadian and German authorities,…

Aura Data Breach Exposes Nearly 900,000 Customer Records

Aura Data Breach Exposes Nearly 900,000 Customer Records Background & Context The recent confirmation by identity protection company Aura regarding a data breach has raised significant concerns across the cybersecurity landscape. Unauthorized access to almost 900,000 customer records, including names and email addresses, highlights the vulnerabilities that continue to plague organizations, particularly those that handle…

Critical Vulnerability in GNU InetUtils Telnet Daemon Poses Significant Security Risk

Critical Vulnerability in GNU InetUtils Telnet Daemon Poses Significant Security Risk Introduction to the Flaw On March 18, 2026, cybersecurity researchers disclosed a critical vulnerability in the GNU InetUtils telnet daemon, known as telnetd. Identified as CVE-2026-32746, this flaw enables unauthenticated remote attackers to execute arbitrary code with elevated privileges via Port 23. With a…

Stryker Cyberattack: A Wipe Without Malware

Stryker Cyberattack: A Wipe Without Malware Background and Context The cyberattack on Stryker, one of the leading manufacturers of medical technology, has raised alarm bells across the healthcare sector. This incident, which occurred in March 2026, resulted in the remote wiping of tens of thousands of employee devices within the company’s internal Microsoft environment. Such…

Critical Vulnerabilities in OpenClaw AI Agent: Risks of Prompt Injection and Data Exfiltration

Critical Vulnerabilities in OpenClaw AI Agent: Risks of Prompt Injection and Data Exfiltration Background and Context OpenClaw, previously known as Clawdbot and Moltbot, is an open-source autonomous artificial intelligence agent designed for a variety of applications, from automation to machine learning tasks. Its availability as a self-hosted solution has attracted a diverse user base ranging…

Chinese Hackers Target Southeast Asian Militaries with Cyber Espionage Campaign

Chinese Hackers Target Southeast Asian Militaries with Cyber Espionage Campaign Background and Context The rise of state-sponsored cyber attacks is an increasingly pressing concern in today’s interconnected world. Reports have emerged that a Chinese cyber espionage operation, designated CL-STA-1087 by Palo Alto Networks’ Unit 42, has been actively targeting military organizations in Southeast Asia. This…