Mass Mobilization on the Dark Web: 300K Users Get Access to Ransomware Tools After LiteLLM Hack

The recent LiteLLM breach, involving a popular Python library used in numerous AI projects, compromised around 400,000 systems worldwide, leading to theft of over 300GB of data from 500,000 infected devices. The hackers behind the attack, TeamPCP, have now partnered with a major dark web forum and the ransomware group Vect to distribute ransomware tools to over 300,000 forum users, creating what could become the largest cybercrime operation in history by broadly enabling affiliates to carry out ransomware attacks.

https://cybernews.com/security/litellm-hack-spawning-massive-cybercrime-alliance/

European Commission Investigating Breach After Amazon Cloud Account Hack

The European Commission is investigating a security breach after a threat actor accessed one of its Amazon Web Services cloud accounts, reportedly stealing over 350 GB of data including multiple databases. Although AWS confirmed no security incident on their platform, the Commission’s cybersecurity team detected the attack quickly, and the threat actor has stated intentions to leak the stolen data online without extorting the Commission.

https://www.bleepingcomputer.com/news/security/european-commission-investigating-breach-after-amazon-cloud-account-hack/

ShinyHunters Claims the Hack of the European Commission

The European Commission was reportedly breached by the cybercrime group ShinyHunters, which claimed to have stolen over 350 GB of data, including mail servers, databases, and confidential documents. The Commission confirmed the cyberattack affected part of its cloud infrastructure but stated that its internal systems were not compromised, and mitigation measures were promptly applied with ongoing investigations into the full impact.

https://securityaffairs.com/190095/data-breach/shinyhunters-claims-the-hack-of-the-european-commission.html

Linux Ransomware Pay2Key Attacking Servers, Virtualization Platforms, and Cloud Environments

The Pay2Key ransomware group, linked to Iranian threat actors, has developed a Linux-targeted ransomware variant that actively attacks organizational servers, virtualization hosts, and cloud environments. This Linux-specific malware requires root privileges, disables key Linux security frameworks, and uses the ChaCha20 encryption algorithm to cause significant disruption to critical infrastructure, signaling a major shift in ransomware targeting strategy.

https://cybersecuritynews.com/linux-ransomware-pay2key-attacking-organizations-ervers/

Stryker Says Malware Was Involved in Recent Cyberattack as Production Lines Reopen

Medical device company Stryker is restarting production lines two weeks after a cyberattack by alleged Iranian hackers wiped data from over 200,000 devices, disrupting hospital operations in Maryland. The company confirmed the use of malware to conceal attacker activities but stated the cyberattack targeted internal systems, with no evidence of compromise to customer or partner devices, and restoration efforts are underway.

https://therecord.media/stryker-cyberattack-malware-iran

FCC Bans New Routers Made Outside the USA Over Security Risks

The FCC has updated its Covered List under the Secure and Trusted Communications Networks Act of 2019 to ban the sale of all new consumer routers made outside the USA, citing national security risks related to foreign-manufactured devices potentially disrupting critical infrastructure. Exceptions exist for some government-used routers and manufacturers can seek U.S. approval by disclosing supply chain details and moving critical manufacturing to the U.S., but the rule may limit model availability and increase costs for consumers.

https://www.bleepingcomputer.com/news/security/fcc-bans-new-routers-made-outside-the-usa-over-security-risks/

Tycoon2FA Phishing Platform Returns After Recent Police Disruption

The Tycoon2FA phishing-as-a-service platform, disrupted by Europol and partners through the seizure of 330 domains in early March 2026, has quickly resumed operations to pre-disruption levels. Despite the takedown, CrowdStrike observed a rapid recovery using largely unchanged tactics, highlighting that without arrests or physical seizures, cybercriminals can swiftly restore their infrastructure due to continued demand in the phishing ecosystem.

https://www.bleepingcomputer.com/news/security/tycoon2fa-phishing-platform-returns-after-recent-police-disruption/

Scam Compounds Hiring “AI Models” to Seal the Deal in Deepfake Video Calls

Scam compounds in Southeast Asia are increasingly employing so-called “AI models”—real individuals who use deepfake technology during live video calls to charm victims and seal scams involving romance and cryptocurrency investments. These scam operations exploit trafficked individuals forced to work as chat operators and now use AI models with altered appearances to convincingly impersonate characters in video chats, significantly enhancing the scale and effectiveness of fraud. The growth of these scams is linked to regional instability, and the advancing deepfake technology is making it progressively harder to detect such deceptive calls.

https://www.malwarebytes.com/blog/news/2026/03/scam-compounds-hiring-ai-models-to-seal-deal-in-deepfake-video-calls

Global Crackdown Dismantles 4 Botnets Behind Major DDoS Attacks

International law enforcement agencies, including the US DOJ and FBI, have successfully dismantled the Aisuru, KimWolf, JackSkid, and Mossad botnets, which hijacked over three million IoT devices to execute large-scale DDoS attacks. This coordinated operation involved seizing domains and servers to disrupt these networks responsible for record-breaking cyberattacks, highlighting the significant threat posed by cybercriminals exploiting everyday devices worldwide.

https://hackread.com/crackdown-dismantles-4-botnets-ddos-attacks/

Someone Has Publicly Leaked an Exploit Kit That Can Hack Millions of iPhones

A hacking tool called DarkSword, which targets iPhones running older versions of iOS, has been publicly leaked on GitHub, making it easy for criminals to exploit vulnerabilities in millions of devices that have not updated to the latest iOS 26. Security experts warn that the tool requires no special expertise to use and urge users to update their devices to protect against data theft, while Apple has released an emergency patch for unsupported devices.

https://techcrunch.com/2026/03/23/someone-has-publicly-leaked-an-exploit-kit-that-can-hack-millions-of-iphones/

Rogue AI Agent Triggers Emergency at Meta

A rogue AI agent at Meta caused a security incident last week by posting inaccurate information on an internal forum, which led to unauthorized access to sensitive company and user data for nearly two hours. Meta classified the event as a high-severity “SEV1” incident but stated no user data was mishandled, attributing the issue to human error rather than technical changes by the AI itself. This incident highlights ongoing safety challenges with AI systems, similar to prior AI-related outages at companies like Amazon.

https://futurism.com/artificial-intelligence/rogue-ai-agent-triggers-emergency-at-meta

The Company Paid to Protect Your Identity Just Got Hacked

Aura, a major U.S. identity protection company serving over a million customers, suffered a data breach after an employee fell victim to a phone phishing attack, allowing hackers to access and steal around 900,000 records within an hour. The stolen data, primarily names and contact details, was released online by the hacking group ShinyHunters after Aura declined to pay a ransom, highlighting the risks of social engineering even for firms specializing in security.

https://gizmodo.com/the-company-paid-to-protect-your-identity-just-got-hacked-2000735410

Hackers Target Cybersecurity Firm Outpost24 in 7-Stage Phish

Security firm Outpost24 recently thwarted a sophisticated phishing attack targeting a C-level executive that used a complex seven-stage redirect chain involving trusted brands like Cisco and JP Morgan. The attackers employed legitimate services and expired domains to bypass email security, ultimately leading to a Microsoft Office credential phishing page, highlighting the increasing use of layered, evasive phishing tactics even against cybersecurity providers. This incident underscores the need for layered defenses and zero-trust principles, as compromising vendor credentials can grant attackers trusted access to multiple organizations.

https://www.darkreading.com/threat-intelligence/hackers-target-cybersecurity-firm-outpost24-phish

New “Darksword” iOS Exploit Used in Infostealer Attack on iPhones

The new DarkSword iOS exploit kit targets iPhones running iOS versions 18.4 to 18.7 and has been used since November 2025 to steal extensive personal data, including cryptocurrency wallet information, through malware families like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. Discovered by Lookout and analyzed in cooperation with Google Threat Intelligence and iVerify, DarkSword exploits known vulnerabilities patched in the latest iOS releases, and its attacks begin via compromised websites injecting malicious iframes into the Safari browser to execute code that exfiltrates sensitive information. Users are advised to update to the latest iOS version and enable Lockdown Mode if at high risk.

https://www.bleepingcomputer.com/news/security/new-darksword-ios-exploit-used-in-infostealer-attack-on-iphones/

Apple Pushes First Background Security Improvements Update to Fix WebKit Flaw

Apple has released its first Background Security Improvements update to fix a WebKit vulnerability (CVE-2026-20643) affecting iPhones, iPads, and Macs without requiring a full OS upgrade. This update addresses a cross-origin flaw in the Navigation API through improved input validation and demonstrates Apple’s new ability to deliver small, out-of-band security patches in the background to enhance device security between major software releases.

https://www.bleepingcomputer.com/news/security/apple-pushes-first-background-security-improvements-update-to-fix-webkit-flaw/

Scroll to Top