📰 DAILY THREAT BRIEFING
Saturday, March 21, 2026
12 News Items
THN · BleepingComputer · Krebs · Dark Reading · SANS

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of March 21, 2026.

  1. FBI links Signal phishing attacks to Russian intelligence services
    — Bleeping Computer

    The FBI has issued a public service announcement warning that Russian intelligence-linked threat actors are actively targeting users of encr…
  2. Patch Now: Oracle's Fusion Middleware Has Critical RCE Flaw
    — Dark Reading

    Attackers can execute arbitrary code without authentication if Oracle's Identity or Web Services Managers are exposed to the Web.
  3. Oracle pushes emergency fix for critical Identity Manager RCE flaw
    — Bleeping Computer

    Oracle has released an out-of-band security update to fix a critical unauthenticated remote code execution vulnerability in Identity Manager…
  4. Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets
    — The Hacker News

    Trivy, a popular open-source vulnerability scanner maintained by Aqua Security, was compromised a second time within the span of a month to …
  5. Police take down 373,000 fake CSAM sites in Operation Alice
    — Bleeping Computer

    An international law enforcement action called Operation Alice has shut down over 373,000 dark web sites that offered fake CSAM packages. [.…
  6. Cyber OpSec Fail: Beast Gang Exposes Ransomware Server
    — Dark Reading

    Files on a central cloud server used by the ransomware group highlight a systematic, aggressive attack on network backups as a key TTP.
  7. Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
    — The Hacker News

    A critical security flaw impacting Langflow has come under active exploitation within 20 hours of public disclosure, highlighting the speed …
  8. CISA orders feds to patch max-severity Cisco flaw by Sunday
    — Bleeping Computer

    The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity vulnerability, CVE-2026…
  9. Interlock Ransomware Targets Cisco Enterprise Firewalls
    — Dark Reading

    The ransomware gang, known for double-extortion attacks, had access to a critical Cisco firewall vulnerability weeks before it was publicly …
  10. Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams
    — The Hacker News

    Google on Thursday announced a new "advanced flow" for Android sideloading that requires a mandatory 24-hour wait period to install apps fro…
  11. The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks
    — The Hacker News

    Artificial Intelligence (AI) is changing how individuals and organizations conduct many activities, including how cybercriminals carry out p…
  12. GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th)
    — SANS ISC

    Yesterday, I discovered a malicious Bash script that installs a GSocket backdoor on the victim&#x27s computer. I don&#x27t know the source o…

Generated by HiveNet.ai Threat Intelligence Platform · March 21, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC