threats

LeakNet Ransomware Uses ClickFix Via Hacked Sites, Deploys Deno In-Memory Loader

LeakNet ransomware uses the ClickFix social engineering tactic to trick users into running malicious commands via compromised websites as an initial access method. This approach allows LeakNet to bypass traditional methods and reduce costs. The ransomware also employs a Deno-based loader to execute payloads in memory, minimizing detection.

https://thehackernews.com/2026/03/leaknet-ransomware-uses-clickfix-via.html

ClickFix Campaigns Spread MacSync macOS Infostealer Via Fake AI Tool Installers

Multiple ClickFix campaigns have been identified spreading the MacSync macOS information stealer through fake AI tool installers that trick users into running malicious Terminal commands. These campaigns leverage malvertising and social engineering, often using trusted platforms and search ads to lure victims, with recent variants employing advanced evasion techniques to harvest sensitive data like credentials and cryptocurrency wallet seed phrases. Security experts warn that these evolving tactics exploit developers’ trust in command-line installs and have been adopted by multiple threat actors targeting both macOS and Windows environments.

https://thehackernews.com/2026/03/clickfix-campaigns-spread-macsync-macos.html

Face Value: What It Takes to Fool Facial Recognition

ESET Global Cybersecurity Advisor Jake Moore demonstrated how widely-used facial recognition systems can be fooled using modified smart glasses for real-time identification, AI-generated fake faces to bypass bank identity verification, and face swap technology to evade police watchlists. His experiments reveal significant vulnerabilities in facial recognition technology that is increasingly trusted for security, highlighting the need for these systems to be rigorously tested against such attacks. Moore will present these findings live at RSAC 2026 to raise awareness about the risks of relying solely on facial biometrics for identity verification.

https://www.welivesecurity.com/en/privacy/face-value-what-takes-fool-facial-recognition/

Top Dark Web Telegram Groups & Channels (2026)

Telegram has become a significant platform for cybercriminal activity, with its features attracting threat actors. Key categories of dark Telegram channels include credential dumps, financial fraud, hacktivism, and ransomware announcements. Effective monitoring requires automated tools and context-aware analysis, avoiding manual approaches for scalability. Legal considerations vary, but organizations can generally monitor these channels without engaging in illicit activities. The landscape has shifted due to AI moderation on Telegram, prompting criminals to migrate to other platforms, making comprehensive monitoring essential.

https://www.dexpose.io/dark-web-telegram-groups-channels/

One Click on This Fake Google Meet Update Can Give Attackers Control of Your PC

Fake Google Meet update pages can give attackers control of your Windows PC with one click. This phishing attack uses a legitimate Windows feature for device enrollment, allowing control without malware or stolen credentials, bypassing typical security checks. Victims should check their device settings for unauthorized enrollments and disconnect if necessary.

https://www.malwarebytes.com/blog/threat-intel/2026/03/one-click-on-this-fake-google-meet-update-can-give-attackers-control-of-your-pc

Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer

Microsoft revealed a new phishing campaign, ClickFix, using Windows Terminal to deploy Lumma Stealer malware. The campaign tricks users into executing commands via a trusted app, bypassing detection methods aimed at the Run dialog. It executes a multi-stage attack: downloading and extracting malicious scripts, collecting credentials from browsers, and establishing persistence. The malware targets sensitive data, emphasizing the risks of social engineering tactics in cybersecurity.

https://thehackernews.com/2026/03/microsoft-reveals-clickfix-campaign.html

Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit

Google's Threat Intelligence Group identified a new iOS exploit kit, “Coruna,” targeting iPhone models from iOS 13.0 to 17.2.1. Coruna comprises five exploit chains and uses advanced techniques to bypass mitigations. It was initially discovered with links to commercial surveillance, later leveraged by Russian espionage and Chinese financial criminals. Users are urged to update their devices to the latest iOS version or enable Lockdown Mode for security. The kit features sophisticated mechanisms for targeting and data theft, indicating a growing market for reused zero-day exploits.

https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit

APT36: a Nightmare of Vibeware

APT36, known as Transparent Tribe, shifts from conventional malware to “vibeware,” an AI-generated model producing numerous low-quality implants using niche languages like Nim, Zig, and Crystal. This evolution aims to evade detection and employs trusted cloud services for command and control. Despite technical flaws leading to ineffective malware, this model's production volume overwhelms defenses, indicating a trend towards automated, high-volume cyberattacks. Their targeted attacks focus on the Indian government, utilizing sophisticated social engineering tactics and established frameworks alongside new, poorly coded variants. Overall, APT36 embraces a strategy of integrating AI into malware design, resulting in mass-produced threats lacking true innovation but full of operational risk.

https://businessinsights.bitdefender.com/apt36-nightmare-vibeware

LLMs Can Unmask Pseudonymous Users at Scale With Surprising Accuracy

Large language models (LLMs) can accurately unmask pseudonymous users on social media platforms, thereby undermining the privacy afforded by pseudonymity. Researchers found that LLMs can achieve high recall and precision rates in identifying users based on their online activity, posing risks of doxxing, stalking, and targeted advertising. The study highlights the need for stronger privacy protections and suggests mitigations, such as rate limits on data access and monitoring for LLM misuse.

https://arstechnica.com/security/2026/03/llms-can-unmask-pseudonymous-users-at-scale-with-surprising-accuracy/

New Gmail Account Attack Warning—Hackers Abuse Critical Security Check

Hackers are targeting Gmail users with a malicious fake Google Account Security Checkup tool that grants attackers access to sensitive information, including push notifications, contacts, GPS location, and clipboard contents. This attack uses deception to trick users into following prompts that compromise their account security. To protect themselves, users should only use the official Google Account Security Checkup tool through official channels, such as typing the URL directly into their browser.

https://www.forbes.com/sites/daveywinder/2026/03/01/check-your-gmail-account-security-now-ongoing-attacks-reported/

US‑Israel‑Iran Conflict May Trigger Unprecedented Cyberattacks

US-Israel-Iran tensions may lead to extensive cyberattacks disrupting critical infrastructure and financial systems. Cyberwarfare is increasingly integrated into military strategies, as past incidents demonstrate its potential for widespread damage without physical destruction. Experts warn that the ongoing conflict could escalate into coordinated attacks on various sectors, stressing the need for robust cybersecurity measures like zero-trust architecture.

https://www.khaleejtimes.com/world/asia/usisraeliran-trigger-unprecedented-cyberattacks?amp=1

Iran Cyberattack Blackout and War Risks

Iran faced a near-total internet blackout amid a cyberattack during military strikes, disrupting critical infrastructure and communication. Internet traffic dropped to 4% of normal levels as Iranian news outlets went offline and security systems failed, highlighting the integration of cyber warfare with traditional military actions. Analysts view cyberattacks as a tool for Iran to retaliate without escalating to full-scale war, presenting several potential response strategies, including cyberattacks, maritime threats, and support for militias. The incident underscores the rising importance of cybersecurity in global conflicts and advises individuals to enhance personal digital security measures during such tensions.

https://cyberguy.com/news/iran-cyberattack-blackout-war-risks/

Software Vulnerabilities Are Being Weaponized Faster Than Ever

VulnCheck reports that software vulnerabilities are being weaponized rapidly, with a 16.5% increase in exploits linked to 10,500 CVEs in 2025, partly due to AI-generated proof-of-concept code. Less than 1% of vulnerabilities were exploited, complicating threat assessment for security teams. Notably, over 50% of ransomware CVEs were zero-days. Major vulnerabilities include React2Shell (236 exploits) and a Microsoft Sharepoint flaw (36 exploits).

https://www.cybersecuritydive.com/news/software-vulnerabilities-are-being-weaponized-faster-than-ever/813096/

Scroll to Top