THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
TeamPCP’s supply chain attack poisons popular AI package LiteLLM

A cybercriminal group known as TeamPCP is expanding its supply chain campaign against open source tools, most recently by uploading two compromised LiteLLM releases (1.82.7 and 1.82.8) to PyPI on March 24. The trojanized packages included a credential stealer, underscoring how a single upstream dependency can expose thousands of downstream applications that integrate LLMs. Organizations should verify package integrity, pin trusted versions, and rotate exposed secrets.

Source: Help Net Security


Google accelerates post-quantum encryption timeline to 2029

Google has moved up its target for deploying post-quantum cryptography to 2029, signaling heightened urgency to replace vulnerable public-key algorithms before large-scale quantum computers arrive. The shift raises the bar for enterprises to inventory cryptography, plan migrations, and prioritize quantum-safe algorithms across products, devices, and data flows sooner than expected.

Source: CyberScoop


CISA’s acting chief warns shutdown is raising cyber risk and driving resignations

With capacity constrained during the shutdown, CISA is largely limited to imminent threat response, critical information sharing, and sustaining its 24/7 operations center. Acting Director Kiersten Todt Andersen warned that the reduced posture is increasing national cyber risk and fueling staff resignations, potentially degrading long-term readiness.

Source: The Record by Recorded Future


New LLM backdoor method succeeds with only a handful of poisoned samples

Researchers detailed “ProAttack,” a prompt-based backdoor that reaches near-100% attack success on multiple text classification benchmarks without changing labels or inserting obvious trigger words. Because the backdoor is learned during prompt-driven fine-tuning, it is extremely hard to detect; the authors outline a LoRA-based fine-tuning defense paradigm to mitigate such stealthy model compromises.

Source: Help Net Security


Citrix NetScaler ADC/Gateway vulnerabilities: UK NCSC urges immediate action

The UK’s NCSC is urging organizations to rapidly mitigate two newly disclosed flaws affecting Citrix NetScaler ADC and NetScaler Gateway. Given NetScaler’s prevalence in remote access and application delivery, timely patching and configuration reviews are essential to reduce exploitation risk.

Source: NCSC UK


Who owns AI agent access? Survey finds fragmented identity control in enterprises

A Cloud Security Alliance survey highlights that most organizations already run AI agents in production systems, yet ownership of how those agents authenticate and what they can access is unclear. Fragmented controls across SaaS, APIs, and non-human identities are creating a fast-growing attack surface that many teams can’t adequately supervise.

Source: Help Net Security


Microsoft Entra ID adds general availability support for external MFA

Microsoft has made external MFA in Entra ID generally available, enabling organizations to use third-party MFA providers to meet regulatory, M&A, or standardization needs. Built on extensible identity integrations, the feature helps unify MFA policy while maintaining compliance and flexibility across complex environments.

Source: Help Net Security


You May Also Be Interested In...

Ransomware attack disrupts operations at Spain’s Port of Vigo

Google adds Gemini-powered dark web intelligence to Threat Intelligence

HackerOne employee data exposed via third-party provider breach

Cybersecurity — March 26, 2026 | Briefing24