$ page 21/36

Trump administration rolls out new US cyber strategy after 15-year gap

The White House unveiled a new national cyber strategy focused on stronger defenses, threat disruption, critical infrastructure, and innovation.

2 min readMar 23

FIRST says 2026 could bring more than 50,000 new CVEs

FIRST forecasts that newly disclosed CVEs could exceed 50,000 in 2026, raising the pressure on already stretched vulnerability teams.

2 min readMar 23

AI may help spot smartphone phishing, but it won’t stop the surge alone

Dark Reading reports Omdia found smartphone phishing is bypassing on-device protections, while AI helps both defenders and attackers.

2 min readMar 23

Gru-linked BlueDelta sharpens credential-harvesting operations across Europe and Eurasia

Recorded Future says GRU-linked BlueDelta is refining phishing and session-theft campaigns targeting government, energy, and research groups.

7 min readMar 23

Tentacles of ‘0ktapus’ threat group victimize 130 firms

The 0ktapus campaign hit 130+ firms by spoofing Okta MFA flows, showing how phishable authentication can enable wide account takeover.

8 min readMar 23

VoidStealer uses debugger trick to steal Chrome’s encryption key

VoidStealer reportedly bypasses Chrome ABE with a debugger trick, exposing cookies, passwords, and session tokens to account hijacking.

2 min readMar 23

Rapid7 says exploit windows are shrinking to days after vulnerability disclosure

Rapid7 says the median time from vulnerability disclosure to CISA KEV inclusion has dropped to five days in 2025.

2 min readMar 22

ClickFix campaigns use fake AI installers to push MacSync infostealer on macOS

Three ClickFix campaigns are using fake AI installers to trick macOS users into running terminal commands that deploy the MacSync infostealer.

2 min readMar 22

Oracle patches critical flaw in Identity Manager that could allow unauthenticated remote code execution

Oracle fixed CVE-2026-21992, a critical 9.8 flaw in Identity Manager and Web Services Manager enabling unauthenticated remote code execution.

2 min readMar 22

Microsoft patches two publicly disclosed zero-days in March security update

Microsoft fixed 79 flaws in March, including two publicly disclosed zero-days affecting Windows SmartScreen and Microsoft Office.

2 min readMar 22

Cloud attackers are shifting from stolen credentials to software exploits, Google Cloud says

Google Cloud says attackers increasingly breach cloud environments through software exploits instead of stolen credentials.

2 min readMar 22

Hackers exploited critical Langflow bug within 20 hours of disclosure

Sysdig says attackers started exploiting Langflow RCE flaw CVE-2025-3248 within 20 hours of disclosure, hitting exposed instances.

2 min readMar 22