Episode 5
Security Brief Daily | 24 Mar 2026
In This Episode
Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks — The Hacker News
Citrix has released security updates to address two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical flaw that could be exploited to leak sensitive data from the application. The vulnerabilities are listed below - CVE-2026-3055 (CVSS score: 9.3) -...Tycoon2FA phishing platform returns after recent police disruption — Bleeping Computer
The Tycoon2FA phishing-as-a-service (PhaaS) platform that Europol and partners disrupted on March 4 has already returned to previously observed activity levels. Microsoft led the technical disruption, which involved seizing 330 domains part of Tycoon2FA’s backbone...3.1 Million Impacted by QualDerm Data Breach — Security Week
Hackers stole personal, medical, and health insurance information from the company’s internal systems. The post 3.1 Million Impacted by QualDerm Data BreachU.S. Sentences Russian Hacker to 6.75 Years for Role in $9M Ransomware Damage — The Hacker News
A 26-year-old Russian citizen has been sentenced in the U.S. to 6.75 years (81 months) in prison for his role in assisting major cybercrime groups, including the Yanluowang ransomware crew, in conducting numerous attacks against U.S. companies and other organizations....‘CanisterWorm’ Springs Wiper Attack Targeting Iran — Krebs on Security
A financially motivated data theft and extortion group is attempting to inject itself into the Iran war, unleashing a worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran’s time zone or have Farsi set as the default...Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials — The Hacker News
Cybersecurity researchers have uncovered a new set of malicious npm packages that are designed to steal cryptocurrency wallets and sensitive data. The activity is being tracked by ReversingLabs as the Ghost campaign. The list of identified packages, all published by a user...Chip Services Firm Trio-Tech Says Subsidiary Hit by Ransomware — Security Week
The semiconductor company says hackers deployed file-encrypting ransomware on the network of a subsidiary in Singapore. The post Chip Services Firm Trio-Tech Says Subsidiary Hit by RansomwareCISA orders feds to patch DarkSword iOS flaws exploited attacks — Bleeping Computer
CISA ordered U.S. government agencies to patch three iOS vulnerabilities targeted in cryptocurrency theft and cyberespionage attacks using the DarkSword exploit kit. [...]Security Brief Daily is an AI-generated cybersecurity news podcast. Always verify critical information with primary sources.