📰 DAILY THREAT BRIEFING
Wednesday, March 25, 2026
12 News Items
THN · BleepingComputer · Krebs · Dark Reading · SANS

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of March 25, 2026.

  1. PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug
    — Bleeping Computer

    PTC Inc. is warning of a critical vulnerability in Windchill and FlexPLM, widely used product lifecycle management (PLM) solutions, that cou…
  2. Popular LiteLLM PyPI package backdoored to steal credentials, auth tokens
    — Bleeping Computer

    The TeamPCP hacking group continues its supply-chain rampage, now compromising the massively popular "LiteLLM" Python package on PyPI and cl…
  3. Checkmarx KICS Code Scanner Targeted in Widening Supply Chain Hit
    — Dark Reading

    TeamPCP is the likely cyber threat actor behind attacks on Trivy, Checkmarx's KICS and VS Code plug-ins, and the LiteLLM AI library — and …
  4. How AI Coding Tools Crushed the Endpoint Security Fortress
    — Dark Reading

    Security vendors have spent years building up defenses around the endpoint, but one researcher says AI coding tools have brought the walls d…
  5. FCC bans new routers made outside the USA over security risks
    — Bleeping Computer

    The Federal Communications Commission has updated its Covered List to include all consumer routers made in foreign countries, banning the sa…
  6. TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 Likely via Trivy CI/CD Compromise
    — The Hacker News

    TeamPCP, the threat actor behind the recent compromises of Trivy and KICS, has now compromised a popular Python package named litellm, pushi…
  7. Firefox now has a free built-in VPN with 50GB monthly data limit
    — Bleeping Computer

    Mozilla released Firefox 149 with added privacy protection through a built-in VPN tool offering up to 50GB of monthly traffic. […]
  8. Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR
    — The Hacker News

    A large-scale malvertising campaign active since January 2026 has been observed targeting U.S.-based individuals searching for tax-related d…
  9. 5 Learnings from the First-Ever Gartner Market Guide for Guardian Agents
    — The Hacker News

    On February 25, 2026, Gartner published its inaugural Market Guide for Guardian Agents, marking an important milestone for this emerging cat…
  10. Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner
    — The Hacker News

    An ongoing phishing campaign is targeting French-speaking corporate environments with fake resumes that lead to the deployment of cryptocurr…
  11. GitHub 'OpenClaw Deployer' Repo Delivers Trojan Instead
    — Dark Reading

    An AI-assisted campaign is spreading more than 300 poisoned packages for diverse assets ranging from developer tools to game cheats.
  12. Detecting IP KVMs, (Tue, Mar 24th)
    — SANS ISC

    I have written about how to use IP KVMs securely, and recently, researchers at Eclypsium published …

Generated by HiveNet.ai Threat Intelligence Platform · March 25, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC