Google’s Threat Intelligence Group says a North Korea–nexus actor (UNC1069) hijacked a maintainer account and slipped a malicious dependency (“plain-crypto-js”) into axios 1.14.1 and 0.30.4, triggering a postinstall dropper that deploys the WAVESHAPER.V2 backdoor on Windows, macOS, and Linux. Axios sees ~100M weekly downloads, amplifying blast radius; defenders should pin to safe versions (1.14.0 / 0.30.3 or earlier), audit lockfiles for “plain-crypto-js,” block C2 (sfrclak.com; 142.11.206.73), clear caches, and rotate credentials on impacted hosts.
Source: Google Threat Intelligence
CISA orders urgent patching of actively exploited Citrix NetScaler flaw
US federal agencies have been told to patch a Citrix NetScaler bug (CVE-2026-3055, severity 9.3) by April 2 after reports of exploitation that could disclose sensitive data via crafted requests. Given the broad footprint of NetScaler ADC/Gateway in enterprise networks, private-sector defenders should prioritize patching, hunt for anomalous requests, and enforce strict access on management interfaces.
Source: Recorded Future News
Exploitation underway for critical Fortinet FortiClient EMS SQLi (CVE-2026-21643)
A critical SQL injection flaw in FortiClient EMS allows unauthenticated remote code execution via crafted HTTP requests, and attacks have been observed in the wild since March 24. Patch immediately, restrict EMS exposure, review web server logs for suspicious POSTs, and monitor for persistence on affected Windows hosts.
Source: SecurityWeek
F5 BIG‑IP APM bug reclassified as unauthenticated RCE and is being exploited
CVE-2025-53521 in F5 BIG‑IP APM has been re-rated to critical (CVSS 9.8) after new findings showed unauthenticated remote code execution; active exploitation is reported. Organizations should patch without delay, isolate/lock down management and APM virtual servers, and hunt for indicators of compromise before and after maintenance windows.
Source: SOCRadar
Trusted updates abused: TrueConf zero‑day pushes malware to Southeast Asian governments
A zero‑day in TrueConf’s client update mechanism (CVE-2026-3502, CVSS 7.8) enabled tampered updates in a campaign dubbed “TrueChaos,” delivering malware without phishing. Researchers observed Havoc used as a post-exploitation framework and assess likely Chinese-nexus involvement, underscoring the risk of supply-chain and updater abuse.
Source: The Hacker News
Iran‑nexus actor hits Microsoft 365 tenants with password‑spray waves
Check Point tracked three waves (Mar 3, 13, 23) of password-spraying attacks against Microsoft 365, primarily targeting Israel (300+ orgs) and the UAE (>25), with spillover to the US, UK, EU, and Saudi Arabia. Enforce conditional access, block legacy auth, rate‑limit and monitor failed logins, and adopt stronger MFA to blunt spray‑and‑pray tactics.
Source: Check Point Research
Google research lowers the bar for quantum attacks on blockchain cryptography
New Google findings suggest significantly fewer qubits may be needed to break elliptic curve cryptography securing Bitcoin, Ethereum, and most modern wallets, shrinking timelines for quantum risk. Crypto and fintech ecosystems should accelerate post‑quantum migration planning, including key agility, quantum‑safe algorithms, and rapid rotation capabilities.
Source: SecurityWeek
You May Also Be Interested In...
Apple counters ClickFix attacks with macOS Terminal warning
Google addresses Vertex AI security issues after researchers weaponize AI agents