TechLogHub Blog — Page 20 of 22
Insights, guides, and product strategy for builders and product teams.

Trivy supply‑chain attack spreads to Docker, GitHub repos
Trivy, a popular vulnerability scanner from Aqua Security, was compromised in a supply‑chain attack that extended to Docker Hub and GitHub. TeamPCP hackers gained access to Aqua’s GitHub organization by exploiting an unsecured service account (Argon‑DevOps‑Mgt) that had long‑lived personal access tokens. They injected malicious code into Trivy, pushed altered Docker images with tags 0.69.5 and 0.69.6, and tampered with dozens of repositories, adding a “TeamPCP Owns Aqua Security” banner. Despite the breach, Aqua confirmed that its commercial version of Trivy was unaffected but warned users to verify integrity of Docker images and GitHub releases. The incident highlights risks in supply‑chain security and the need for stronger access controls, MFA, and immutable tags.

Varonis Atlas: Securing AI and the Data That Powers It
Varonis announces the general availability of Varonis Atlas, an end‑to‑end AI security platform that lets enterprises discover, monitor, protect and govern all AI systems—from hosted services to custom LLMs and embedded AI—within a single solution built on the Varonis Data Security Platform. Atlas continuously inventories AI assets (including shadow AI), assesses posture for vulnerabilities and data exposure, performs live pen‑tests against production endpoints, enforces real‑time guardrails to prevent leaks or malicious behavior, tracks compliance with regulations such as the EU AI Act and NIST AI RMF, manages third‑party AI risk, monitors full end‑to‑end activity, and provides detection & response capabilities that integrate with SIEM/SOAR. The platform unifies data security context with AI operations to give organizations a fast path to safe, trustworthy AI at scale.

How to Fine-Tune Open Models Locally With Unsloth Studio
A practical technical guide to evaluating Unsloth Studio for local model fine-tuning, including environment choices, data preparation, base-model selection, training workflow design, export planning, and deployment caveats.

What Unsloth Offers for Local Model Training and Inference
Unsloth combines a local-first interface, model training workflows, dataset preparation, and export tooling so teams can run and fine-tune open models without defaulting to hosted AI platforms.

FBI Links Signal Phishing Attacks to Russian Intelligence Services
FBI warns that Russian intelligence-linked actors are hijacking accounts on encrypted messaging apps like Signal and WhatsApp through phishing campaigns, compromising thousands of users worldwide—especially high-value targets such as U.S. officials, military personnel, politicians, and journalists. The attacks bypass end‑to‑end encryption by tricking users into linking devices or sharing verification codes, enabling attackers to read messages, impersonate victims, and launch further phishing. Users are urged to be wary of unexpected support requests, QR codes, and device linking.

Oracle pushes emergency fix for critical Identity Manager RCE flaw
Oracle released an out‑of‑band patch for a critical CVE‑2026‑21992 vulnerability in its Identity Manager and Web Services Manager, allowing unauthenticated remote code execution over HTTP with no user interaction. The fix applies to versions 12.2.1.4.0 and 14.1.2.1.0 of both products, carries a severity score of 9.8, and Oracle strongly urges customers to apply the patch immediately.

Police take down 373,000 fake CSAM sites in Operation Alice
Police and Europol have dismantled 373,000 fake child sexual abuse material (CSAM) sites under Operation Alice, shutting down a Chinese‑based scam platform that advertised counterfeit CSAM packages costing between €17–€215 and attracted around 10,000 users who paid about $400,000. The investigation seized 287 servers—105 in Germany—and issued an arrest warrant for the operator, while Europol highlights its broader child‑protection initiatives such as Help4U and “Stop Child Abuse – Trace an Object.”

CISA orders federal agencies to patch Cisco Secure FMC vulnerability by Sunday.
CISA has ordered all federal agencies to patch the high‑severity CVE‑2026‑20131 vulnerability in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22, after the flaw was found to allow remote attackers to execute Java code as root via insecure deserialization. The vulnerability is actively exploited by ransomware groups such as Interlock since January 2026, and CISA has added it to its Known Exploited Vulnerabilities catalog. Federal agencies have only three days to apply the patch or stop using the product; other organizations are urged to act promptly.

How CISOs Can Survive the Era of Geopolitical Cyberattacks
CISOs must shift from pure prevention to resilience against geopolitically motivated “wiper” attacks that aim to disrupt rather than ransom. Iran’s recent destructive campaigns illustrate a pattern: attackers gain access via stolen VPN credentials, then move laterally through administrative tools (RDP, PowerShell, SMB, SSH), escalating privileges and deploying multiple wiping methods simultaneously. Defenders can mitigate this by limiting credential-based network reach, enforcing MFA on administrative services, default‑deny policies for admin ports, restricting privileged accounts to the systems they manage, detecting tunneling or unusual east‑west traffic, and rapidly containing affected hosts with automated isolation and ring‑fencing. The core lesson is that preventing lateral movement and controlling privileged access—combined with visibility into who can access what—reduces blast radius and enables organizations to survive geopolitical cyber conflicts.

Musician admits to $10 M streaming royalty fraud using AI bots
North Carolina musician Michael Smith pleaded guilty to fraudulently collecting over $10 million in streaming royalties by generating thousands of AI‑created songs and using bot accounts to stream them billions of times on Spotify, Apple Music, Amazon Music, and YouTube Music. He used VPNs and automated bots to inflate listening stats between 2017 and 2024, earning an estimated $1.2 million per year from half a cent per stream. Smith will pay roughly $8 million in forfeiture and faces up to five years in prison for conspiracy to commit wire fraud.

FBI Seizes Handala Data‑Leak Sites After Stryker Cyberattack
The FBI has seized the two public domains used by the Handala hacktivist group—handala-redwanted.to and handala-hack.to—after the group carried out a destructive cyberattack on medical technology company Stryker, wiping about 80,000 devices via Intune. The seizure was authorized by a Maryland district court warrant, citing alleged foreign state involvement and malicious activity. Handala, an Iranian-linked pro‑Palestinian group linked to Iran’s MOIS, has acknowledged the seizures and plans to rebuild its online infrastructure while continuing operations. Microsoft and CISA have issued guidance on securing Intune to prevent similar attacks.

Russian hackers exploit Zimbra flaw in Ukrainian govt attacks
Russian state‑backed hackers from APT28 are exploiting a newly patched Zimbra Collaboration Suite vulnerability (CVE‑2025‑66376) to target Ukrainian government entities, notably the State Hydrology Agency. The flaw allows unauthenticated attackers to execute remote code via stored cross‑site scripting in emails, enabling stealthy credential harvesting and data exfiltration over DNS and HTTPS. CISA has added this exploit to its catalog of active vulnerabilities and ordered federal agencies to patch within two weeks. Security researchers report that the attack chain uses a single email with obfuscated JavaScript, no attachments or links, exploiting the XSS flaw to gain access to users’ mailbox contents and backup 2FA codes. This is part of a broader trend of Russian‑state groups targeting Zimbra servers for espionage.

Aura confirms data breach exposing 900,000 marketing contacts
Aura confirms that a voice‑phishing attack exposed nearly 900,000 customer records—names, email addresses, home addresses and phone numbers—from a marketing tool acquired in 2021. The breach involved 20,000 current and 15,000 former customers, with no SSNs or financial data compromised. ShinyHunters claimed to have stolen 12 GB of PII, but Aura has not commented on that claim. The company is conducting an internal review, notifying law enforcement, and will send personalized alerts to affected individuals.

ConnectWise Releases Patch to Fix Cryptographic Signature Vulnerability in ScreenConnect™
ConnectWise alerts that a cryptographic signature verification flaw (CVE‑2026‑3564) in ScreenConnect versions before 26.1 can allow attackers to hijack sessions by extracting ASP.NET machine keys, enabling unauthorized access and privilege escalation. The vendor has patched the issue in version 26.1 with encrypted key storage and improved handling; cloud users are automatically upgraded while on‑premises admins must update immediately. Although researchers have observed attempts to abuse disclosed machine key material in the wild, no confirmed exploitation or indicators of compromise have been reported yet. ConnectWise advises tightening access controls, monitoring logs for unusual authentication activity, protecting backups, and keeping extensions up to date to mitigate risk.

Apple pushes first Background Security Improvements update to fix WebKit flaw
Apple released its first Background Security Improvements update, fixing the WebKit flaw CVE‑2026‑20643 that lets malicious web content bypass Safari’s Same Origin Policy. The patch applies to iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1 and 26.3.2 without a full OS upgrade, demonstrating Apple’s new lightweight out‑of‑band security feature that delivers small fixes between major releases.

GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
GlassWorm, a supply‑chain malware campaign, has infected over 400 open‑source components across GitHub, npm, VSCode and OpenVSX repositories. In March 2026 researchers identified 433 compromised packages—200 Python repos, 151 JS/TS repos, 72 VSCode extensions and 10 npm packages—all injected with invisible Unicode characters to conceal malicious code that harvests cryptocurrency wallet data, developer credentials, SSH keys, and other sensitive information. The attackers use a single Solana blockchain address for command‑and‑control, consistently updating payload URLs every five seconds. Initial compromise occurs via forced pushes on compromised GitHub accounts, after which malicious packages are published on npm and VSCode/OpenVSX with obfuscated code. The malware skips execution on Russian‑locale systems but is likely operated by Russian‑speaking actors. Developers are advised to scan for the marker variable “lzcdrtfxyqiplpd,” check for unexpected Node.js installations, suspicious i.js files, and anomalies in commit histories to detect compromises.

Europe sanctions Chinese and Iranian firms for cyberattacks
EU Council sanctions three Chinese and one Iranian companies, plus two individuals, for cyberattacks targeting EU devices and critical infrastructure, including hacking over 65,000 devices, compromising SMS services, hijacking billboards, and selling personal data of Charlie Hebdo subscribers; the sanctions impose asset freezes, travel bans, and restrictions on EU entities.

Top 5 Things CISOs Need to Do Today to Secure AI Agents
CISOs must secure AI agents by treating them as first‑class digital identities with clear ownership, authentication, defined permissions and activity logging; move from fragile guardrails to tight access control that limits what systems, data, actions and conditions an agent can use; eliminate shadow AI through continuous discovery and visibility of all machine‑and non‑human identities; enforce security based on the agent’s intended purpose rather than static permission inheritance; and maintain full lifecycle governance—monitor ownership, access alignment, credential rotation, review, and decommissioning—to prevent risk accumulation over time. The overarching principle is that identity—and its controlled, intent‑driven management—is the only scalable foundation for securing autonomous AI agents.

Stryker attack wiped tens of thousands of devices, no malware needed
Stryker’s recent cyberattack, allegedly linked to the Handala hacktivist group, caused a remote wipe of tens of thousands of employee devices via Microsoft Intune, without deploying malware or encrypting data. The attack was limited to Stryker’s internal Microsoft environment and did not affect its medical products; however, electronic ordering systems went offline and customers must place orders manually through sales reps while restoration efforts focus on resuming shipping and transactional services.

Microsoft Exchange Online outage blocks access to mailboxes
Microsoft’s Exchange Online is experiencing an outage that blocks users from accessing mailboxes and calendars across all connection methods, including Outlook on the web, desktop, ActiveSync, and IMAP4. The issue was first reported at 06:42 UTC, with telemetry showing a decrease in incidents but customers still report problems. Additionally, Office.com’s web portal is down, displaying an error message, and a separate outage affecting Microsoft Copilot sign‑in pages and chat services is underway. Microsoft is working on configuration changes to resolve these disruptions.
Showing 20 of 423 articles


