📰 DAILY THREAT BRIEFING
Tuesday, March 31, 2026
12 News Items
THN · BleepingComputer · Krebs · Dark Reading · SANS

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of March 31, 2026.

  1. Healthcare tech firm CareCloud says hackers stole patient data
    — Bleeping Computer

    Healthcare IT firm CareCloud has disclosed a data breach incident that exposed sensitive data and caused a network disruption lasting approx…
  2. AI-Powered 'DeepLoad' Malware Steals Credentials, Evades Detection
    — Dark Reading

    The massive amount of junk code that hides the malware's logic from security scans was almost certainly generated by AI, researchers say.
  3. New RoadK1ll WebSocket implant used to pivot on breached networks
    — Bleeping Computer

    A newly identified malicious implant named RoadK1ll is enabling threat actors to quietly move from a compromised host to other systems on th…
  4. DShield (Cowrie) Honeypot Stats and When Sessions Disconnect, (Mon, Mar 30th)
    — SANS ISC

    A lot of the information seen on DShield honeypots [1] is repeated bot traffic, especially when looking at the Cowrie [2] telnet and SSH ses…
  5. Critical Citrix NetScaler memory flaw actively exploited in attacks
    — Bleeping Computer

    Hackers are exploiting a critical severity vulnerability, tracked as CVE-2026-3055, in Citrix  NetScaler ADC and NetScaler Gateway applia…
  6. F5 BIG-IP Vulnerability Reclassified as RCE, Under Exploitation
    — Dark Reading

    CVE-2025-53521 was initially disclosed in October as a high-severity denial-of-service (DoS) flaw, but new information has revealed the bug …
  7. OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability
    — The Hacker News

    A previously unknown vulnerability in OpenAI ChatGPT allowed sensitive conversation data to be exfiltrated without user knowledge or consent…
  8. Manufacturing and Healthcare Share Struggles with Passwords
    — Dark Reading

    The two key economic sectors struggle with security for a reason: Many insiders view access management as a roadblock, while attackers see i…
  9. DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
    — The Hacker News

    A new campaign has leveraged the ClickFix social engineering tactic as a way to distribute a previously undocumented malware loader referred…
  10. Storm Brews Over Critical, No-Click Telegram Flaw
    — Dark Reading

    The vulnerability, which is allegedly triggered by a corrupted sticker in the messaging app, received a 9.8 CVSS score, but Telegram denies …
  11. TeamPCP Supply Chain Campaign: Update 004 – Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, (Mon, Mar 30th)
    — SANS ISC

    This is the fourth update to the TeamPCP supply chain campaign threat intelligence report, "When th…
  12. Apple adds macOS Terminal warning to block ClickFix attacks
    — Bleeping Computer

    Apple has introduced a security feature in macOS Tahoe 26.4 that blocks pasting and executing potentially harmful commands in Terminal and a…

Generated by HiveNet.ai Threat Intelligence Platform · March 31, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC