EPIC FAILS in Application Development Security practice processes, training, implementation, and incident response
A hacker has allegedly breached one of China’s supercomputers and is attempting to sell a trove of stolen data
The dataset, which allegedly contains more than 10 petabytes of sensitive information, is believed by experts to have been obtained from the National Supercomputing Center (NSCC) in Tianjin. The alleged sample data appeared to include documents marked “secret” in Chinese, along with technical files, animated simulations and renderings of defense equipment including bombs and missiles.
The attacker is offering a limited preview of the alleged dataset, for thousands of dollars, with full access priced at hundreds of thousands of dollars. Payment was requested in cryptocurrency.
The attacker claimed to have gained access to the Tianjin supercomputer through a compromised VPN domain. Once inside, the attacker deployed a “botnet”, a network of automated programs, that were able enter the NSCC’s system and then extract, download and store the data. The extraction of 10 petabytes of data took around six months.
The approach was less about technical sophistication and more about architecture.
By distributing the extraction across many systems simultaneously, the attacker reduced the risk of triggering an alert. Somebody on the defensive side is less likely to notice small amounts of data leaving the system compared to large amounts of data going to one location.

 

Hims & Hers Health Breach Exposes the Most Sensitive Kinds of PHI
Hackers maintained access from Feb. 4 to Feb. 7. Hims reported having first become aware of suspicious activity targeting its customer service platform on Feb. 5. It took a month for the company to determine that those support tickets contained names and unspecified medical information belonging to "a limited set" of affected customers.
Hims has built its brand around the kinds of medical issues that people fear talking about the most: erectile dysfunction, balding, obesity, and mental health.
If attackers obtained anything beyond basic personally identifying information (PII) from Hims, and even with that alone, potentially, it could empower them to blackmail individuals to a level beyond what leaks of general PHI typically allow.
"This is a design problem. Customer service is now one of the richest sources of personal data in the business, but it’s still managed across a patchwork of disconnected systems; recordings here, transcripts there, workflows somewhere else. That fragmentation is what creates risk."
As the old story goes, Hims is now offering impacted customers a year of free credit monitoring, and a few paragraphs worth of guidance about identity protection.

 

CBP facility codes sure seem to have leaked via online flashcards
A user on Quizlet, an online learning platform, created a public flashcard set in February that appears to have exposed highly confidential information about security procedures in US Customs and Border Protection facilities.
The Quizlet set, titled “USBP Review,” was available to the public until March 20, when it was made private less than half an hour after WIRED messaged a phone number potentially linked to the Quizlet user.
The public Quizlet set contained information about alleged codes for specific facility entrances. “Checkpoint doors code?” asked one card, with a specific four-digit combination listed in response.

 

Bluesky users are mastering the fine art of blaming everything on “vibe coding”
Social network Bluesky saw some intermittent service disruptions on Monday. On its own, this fact isn’t that noteworthy; Bluesky has seen similar service disruptions in the past, and this one coincided with widespread service problems being reported with other popular sites (Bluesky officially blamed the temporary problems on an “upstream service provider”).
What made this outage notable for many Bluesky users, though, was the instant assumption that it was the result of sloppy, AI-assisted “vibe coding” by the Bluesky development team. Before the outage, many on the Bluesky development team faced social media backlash for admitting they used AI tools in their work.
The lesson from this downtime isn’t that it was caused by vibe coding. It’s that if you use AI you will no longer get the benefit of the doubt and everyone will mock you for laziness regardless of the cause.

 

Months-old Adobe Reader zero-day uses PDFs to size up targets
The campaign uses a malicious PDF that runs as soon as it's opened, working against even up-to-date Reader installations with no clicks required beyond viewing the file.
The exploit leans on heavily obfuscated JavaScript that runs as soon as it's opened. Instead of blowing up straight away, it starts pulling information from the machine using built-in Acrobat APIs, including local files and system details, and sends it back to servers under the attacker's control. If the box looks useful, it pulls a second-stage payload and runs it inside Reader.
Such a mechanism allows the threat actor to collect user information, steal local data, perform advanced 'fingerprinting', and launch future attacks. If the target meets the attacker's conditions, the attacker may deliver additional exploit to achieve RCE or SBX.
There's still no CVE, no patch, and Adobe hasn't said anything publicly.

 

What’s Weak This Week:

  • CVE-2026-1340 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability:
    Could allow attackers to achieve unauthenticated remote code execution. Related CWE: CWE-94

  • CVE-2026-35616 Fortinet FortiClient EMS Improper Access Control Vulnerability:
    May allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Related CWE: CWE-284 

 

HACKING
US cybercrime losses pass $20B for first time as AI boosts online fraud
The total number of cybercrime complaints submitted to the agency topped one million for the first time, increasing 17% compared to 2024.
Phishing led the pack with 191,561 reports, followed by extortion and investment scams. As for where the big money went, investment scams led the pack with $8.6 billion in reported losses, followed by business email compromise (BEC) and tech support scams.
Cyber-enabled fraud was involved in 45% of 2025's complaints, but 85% of financial losses.
2025 also marked the first year in the IC3 report's history that a special section on artificial intelligence has been included: AI has been hailed as a profitable innovation for the online criminal underground multiple times over the past year. Interpol even reported last month that financial fraud schemes aided by AI tend to be 4.5 times more profitable than those perpetuated without the help of a bot.

 

Iran-linked hackers disrupt operations at US critical infrastructure sites
The FBI, Cybersecurity and Infrastructure Security Agency, National Security Agency, Environmental Protection Agency, Department of Energy, and US Cyber Command “urgently” warned that the APT, or advanced persistent threat group, is targeting PLCs, short for programmable logic controllers.
The current campaign involves direct access to internet-exposed PLCs using legitimate vendor software (Rockwell Studio 5000 Logix Designer), enabling actors to interact with project files and manipulate HMI/SCADA display data without requiring zero-day exploitation. Confirmed targeted device families include CompactLogix and Micro850.
Protocols, such as Modbus/502 and S7/102, are also being probed.

 

Hundreds of orgs compromised daily in Microsoft device code phishing attacks bypass MFA
Since March 15, 2026, we have observed 10 to 15 distinct campaigns launching every 24 hours.
EvilTokens is a new Microsoft device-code phishing kit that has been sold as a service since mid-February, allowing buyers to bypass multi-factor authentication (MFA) and silently authenticate as the victim to the organization's Microsoft 365 applications. Its operators have promised to soon extend support to Gmail and Okta phishing pages.
Miscreants query GetCredentialType, a Microsoft API endpoint used to determine the authentication method of a user, which allows the attackers to confirm whether a targeted email address exists and is active within the tenant.
The attackers then used AI to create hyper-personalized phishing emails aligned to the target's role, with themes such as requests for proposals, invoices, and manufacturing workflows. These emails include a malicious attachment or a direct URL - but the phisher folk doesn't link to the final phishing website in their initial emails. 
Instead, they automated a series of redirects using compromised legitimate domains on trusted serverless platforms including Railway, Cloudflare Workers, DigitalOcean, and AWS Lambda. This helps the phishing emails avoid detection by automated URL scanners and sandboxes and blend in with legitimate enterprise cloud traffic.
The final phishing page looks like a legitimate browser window within a web page. It prompts users to verify their identity via a button, which redirects to "Microsoft[.]com/devicelogin" and shows the device code.
Microsoft recommends blocking device code flow wherever possible, or only allowing where absolutely necessary.

 

How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers
The most active piece of enterprise infrastructure in the company is the developer workstation. That laptop is where credentials are created, tested, cached, copied, and reused across services, bots, build tools, and now local AI agents.
In March 2026, the TeamPCP threat actor proved just how valuable developer machines are. Their supply chain attack on LiteLLM, a popular AI development library downloaded millions of times daily, turned developer endpoints into systematic credential harvesting operations. The malware only needed access to the plaintext secrets already sitting on disk.
TeamPCP compromised LiteLLM packages versions 1.82.7 and 1.82.8 on PyPI, injecting infostealer malware that activated when developers installed or updated the package. The malware systematically harvested SSH keys, cloud credentials for AWS, Azure, and GCP, Docker configurations, and other sensitive data from developer machines.
The solution is treating secrets as managed identities with defined ownership, lifecycle policies, and automated remediation paths. Move credentials into a centralized vault infrastructure where security teams can enforce rotation schedules, access policies, and usage monitoring. Integrate incident management with your existing ticketing systems so remediation happens in context rather than requiring constant tool-switching.

 

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
All identified npm packages follow the same naming convention, starting with "strapi-plugin-" and then phrases like "cron," "database," or "server" to fool unsuspecting developers into downloading them. It's worth noting that the official Strapi plugins are scoped under "@strapi/."

 

How the FBI Extracted Deleted Signal Messages From a Defendant's iPhone
While they weren't able to retrieve the defendant's outgoing messages, they were able to scrape incoming messages from the iPhone's push notification database.
Any app that has permission to show previews and alerts on the Lock Screen will save those previews to the internal memory of the user's iPhone. As such, the FBI was able to obtain messages the defendant had received, even though those messages were set to disappear in the app, and the app had been cleared from the device.
This is not a security hole exclusive to Signal: Any app that displays an alert on your Lock Screen has this vulnerability.

 

Russia Hacked Routers to Steal Microsoft Office Tokens
More than 200 organizations and 5,000 consumer devices that were caught up in a stealthy but remarkably simple spying network.
The routers attacked by Forest Blizzard were reconfigured to use DNS servers that pointed to a handful of virtual private servers controlled by the attackers. Importantly, the attackers could then propagate their malicious DNS settings to all users on the local network, and from that point forward intercept any OAuth authentication tokens transmitted by those users.
Because those tokens are typically transmitted only after the user has successfully logged in and gone through multi-factor authentication, the attackers could gain direct access to victim accounts without ever having to phish each user’s credentials and/or one-time codes.

 

Security researchers tricked Apple Intelligence into cursing at users. It could have been a lot worse
Apple Intelligence, the personal AI system integrated into newer Macs, iPhones, and other iThings, can be hijacked using prompt injection, forcing the model into producing attacker-controlled results. Researchers used two techniques and succeeded 76% of the time. Essentially, they encoded the malicious/offensive English-language output text by writing it backwards and using our Unicode hack to force the LLM to render it correctly.

  

APPSEC, DEVSECOPS, DEV
The Hidden Cost of Recurring Credential Incidents
IBM’s 2025 Cost of a Data Breach Report puts the average cost of a breach at $4.4 million.
Account lockouts and compromised credentials don’t make the news. They show up as repeated helpdesk tickets, interrupted workflows, and time pulled away from higher-value work. Individually, each incident seems minor, but collectively they place a constant burden on IT teams and the wider business. The real cost doesn’t just sit in the breach you might prevent, but in the day-to-day disruption you’re already dealing with.
Forrester estimates that password resets account for up to 30% of all helpdesk tickets, with each one costing around $70 when you factor in staff time and lost productivity.
When users are required to change passwords every 60 or 90 days, behavior becomes predictable. People make small, incremental changes to existing passwords or choose something easy to remember under time pressure. The result isn’t stronger credentials, but more vulnerable ones.

 

Internet Bug Bounty program hits pause on payouts
HackerOne, which administers the program, has said that it is “pausing submissions” while it contemplates ways in which open source security can be handled more effectively.
Up to now, 80% of its payouts have been for discoveries of new flaws, and 20% to support remediation efforts. But as artificial intelligence makes it easier to find bugs, that balance needs to change. “AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed. The balance between findings and remediation capacity in open source has substantively shifted.”
[rG This isn’t surprising. It has long been understood, “Cost-Speed-Quality: Pick two.”
The CI/CD rapid development fad has resulted in the abandonment of deliberate design and thorough quality/security testing. This situation will persist until product sponsors return to six-sigma principles and emphasizing continuous improvement practices to reduce security defects and rework, operational disruption risks, and rework.
That expertise has been stamped out of organizations and will require sea change refocus and years to rebuild those capabilities.
The AI hype-cycle has accelerated this chaos and is now beginning to bring the consequences into focus.]

 

Ex-Microsoft engineer believes Azure problems stem from talent exodus
Recent enthusiasm for AI has convinced many companies that they can make do with fewer people, Microsoft among them. Yet AI adoption has only underscored the consequences of running code without enough people paying attention.
Microsoft's rushed launch of Azure, the "post-launch talent exodus," the lack of software quality and testing discipline, the lack of architectural vision, and persistently poor execution have left the cloud service fighting fires ever since.
Their most significant challenge was knowledge dilution caused by high attrition.
One can reasonably infer that Microsoft struggled to meet OpenAI's demanding requirements on time and at scale," and the layoff of around 15,000 people Microsoft carried out during the May-July 2025 period.
Microsoft executives should focus on bringing back senior technical leaders to improve dev training at all levels.

 

Why Your Automated Pentesting Tool Just Hit a Wall
By design, automated pentesting solutions deliver their best results in the first run. Within a few cycles, exploitable paths within their scope are exhausted. But that doesn’t mean your environment is secure. It just means the tool has reached its limits, while deeper issues remain untested. This is the structural ceiling of a tool operating against a deterministic surface. It’s an architectural limitation, not an operational one.
Breach and Attack Simulation (BAS) asks: "Are my firewalls, EDRs, WAFs, and SIEMs actually doing their jobs across the entire MITRE ATT&CK framework?" It focuses on the effectiveness of your defensive controls.
Automated Pentesting asks: "Can an attacker get from Point A to Point B using known exploits?" It focuses on the success of specific attack paths.

 

 

Find Evil! SANS AI Hackathon Registration
An AI-powered adversary can go from initial access to full domain control in under 8 minutes. CrowdStrike's fastest observed breakout time: 7 minutes. Horizon3's autonomous agent: 60 seconds to full privilege escalation. MIT's 2024 research: AI-driven attack workflows running 47 times faster than human operators.
Your job: teach an AI agent to think like a senior analyst --- how to sequence its approach, recognize when something doesn't add up, and self-correct when it gets it wrong.
You'll build autonomous AI agents on the SANS SIFT Workstation. Protocol SIFT, the proof-of-concept framework that connects AI agents to those tools through Model Context Protocol (MCP) hallucinates more than we'd like. Unlike offensive teams that operate with three or four people in secret, we're putting the entire practitioner community on this problem simultaneously.
[rG: Thx Peter]

 

When attackers already have the keys, MFA is just another door to open
Modern adversary tooling executes what security researchers call a real-time phishing relay, sometimes referred to as an adversary-in-the-middle (AiTM) attack. Push notification MFA, SMS one-time codes, and TOTP authenticator apps are all vulnerable to this relay.
Phishing-resistant authentication that closes the relay attack vector requires three properties simultaneously:

  • Cryptographic origin binding: the authentication credential is mathematically tied to the exact origin domain. A spoofed site cannot produce a valid signature because the domain does not match. The attack fails before any credential is transmitted.

  • Hardware-bound private keys that never leave secure hardware: the signing key cannot be exported, copied, or exfiltrated. Compromise of the endpoint does not compromise the credential.

  • Live biometric verification of the authorized individual: not a stored biometric template that can be replayed, but a real-time match that confirms the authorized person is physically present at the moment of authentication.

 

How Should We Prepare for the Looming Quantum Encryption Apocalypse?
Hardcoded TLS ciphers need to be swapped to their PQC counterpart (X25519MLKEM768), SSH versions need to be updated, configurations for access token signatures need to be changed from ECDSA to MLDSA, and more.

 

VENDORS & PLATFORMS
Anthropic Unveils ‘Claude Mythos’ – A Cybersecurity Breakthrough That Could Also Supercharge Attack
In the last few weeks, Mythos Preview has identified thousands of zero-day vulnerabilities with many classified as critical. Several are ten or 20 years old – the oldest found so far is a 27-years old bug in OpenBSD. Elsewhere, a 16-years old vulnerability found in video software has survived five million hits from other automated testing tools without ever being discovered. And it autonomously found and chained together several in the Linux kernel allowing an attacker to escalate from ordinary user access to complete control of the machine.
The firm does not plan to make Mythos Preview generally available.
Glasswing brings together Amazon, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, the Linux Foundation, Microsoft, and Palo Alto Networks in an effort to secure the world’s most critical software. “The work of defending the world’s cyber infrastructure might take years; frontier AI capabilities are likely to advance substantially over just the next few months. For cyber defenders to come out ahead, we need to act now.”
Anthropic is also extending access, outside of Project Glasswing, to more than 40 other organizations that build or maintain critical software, “so they can use the model to scan and secure both first-party and open-source systems.”

 

Cloudflare fast-tracks post-quantum rollout as new research puts encryption on notice
Cloudflare Inc. today announced that it’s accelerating its post-quantum security roadmap and is now aiming to make its entire platform fully post-quantum-secure by 2029.
The decision comes after Google and Oratomic demonstrated significant advances in algorithms and hardware capable of breaking widely used encryption methods such as RSA-2048 and elliptic curve cryptography.

 

CryptoNext Security First in EU With Full NIST Quantum-Safe Certification
The certification validates CryptoNext Security’s implementation of all three standardized post-quantum cryptographic algorithms, ensuring a new level of security for data protection. This achievement centers on the company’s integration of these algorithms into ProvenRun’s ProvenHSM hardware security module.

 

Little Snitch comes to Linux to expose what your software is really doing
The Linux version uses eBPF to hook into network activity at the kernel level.
Using Ubuntu as a baseline, the system ended up with just nine processes making internet connections over the course of a week. On macOS, that number was reportedly over one hundred. Of course, Linux isn’t magically silent. Ubuntu still phones home for updates and metrics unless you turn that off. And once you start installing apps, things look familiar again.

 

I'm convinced my phone listens to me, so I paired its ears with this AI recorder
The Comulytic Note Pro is a 3mm-thin AI note-taking tool built for calls, conferences, video meetings, and in-person conversations. It's integrated with GPT-5, Whisper, and Gemini models. It's as small as a stack of three bank cards. The top section houses dual MEMS microphones, supported by a voice processing unit, allowing it to pick up and clean speech from five meters indoors.
It's worth noting that the tool supports 113 languages, including multiple variations of English across Canada, India, Ireland, Singapore, and South Africa.
[rG: Personal mobile AI note taking apps – a new sensitive information management security nightmare. It’s not just about mobile phones and smart glasses. Maybe your organization trusts Google, Apple, and Microsoft within range of confidential conversations, but what about other personal electronic wearables and devices vendors?]

 

 

Wikipedia:Signs of AI writing
[rG: More than em dash usage.]

 

Google’s AI Overviews tell millions of lies per hour
1 in 10 AI answers is wrong.
When asked for the date on which Bob Marley’s former home became a museum, AI Overviews cited three pages, two of which didn’t discuss the date at all. The final one, Wikipedia, listed two contradictory years, and AI Overviews confidently chose the wrong one.

“Cognitive surrender” leads AI users to abandon logical thinking, research finds
Those who scored highly on separate measures of so-called fluid IQ were less likely to rely on the AI for help and were more likely to overrule a faulty AI when it was consulted. Those predisposed to see AI as authoritative in a survey, on the other hand, were much more likely to be led astray by faulty AI-provided answers. Letting an AI do your reasoning means your reasoning is only ever going to be as good as that AI system. As always, let the prompter beware.