Hacktivist persona Handala claims responsibility for a destructive attack on Stryker that reportedly wiped more than 200,000 devices, disrupting global operations at the Fortune 500 medical technology firm. The incident underscores rising geopolitical spillover into healthcare, with wiper tactics elevating the risk from downtime to potential data loss and prolonged recovery.
Source: SecurityWeek
Microsoft’s March Patch Tuesday fixes 80+ flaws; six “more likely” to be exploited
Microsoft addressed more than 80 vulnerabilities across Windows, cloud services, and developer components, with two publicly disclosed issues and six tagged as “more likely” to be exploited. Notable items include an SQL Server privilege escalation and a .NET denial‑of‑service; defenders should prioritize patch deployment, tighten change windows, and monitor for post‑patch exploitation attempts.
Source: Help Net Security
CISA adds critical n8n automation bug to KEV amid active exploitation
U.S. CISA added CVE-2025-68613 to its Known Exploited Vulnerabilities catalog, warning that a critical expression‑injection flaw in the n8n workflow platform enables remote code execution. Researchers report tens of thousands of exposed instances; organizations should patch immediately, remove public exposure where unnecessary, rotate stored credentials, and audit workflows for tampering.
Source: The Hacker News
KadNap botnet infects 14,000+ routers using resilient P2P control
A stealthy malware campaign has compromised more than 14,000 routers—mostly ASUS—building a proxy botnet that’s highly resistant to takedowns via a custom Kademlia-based peer‑to‑peer network. The edge‑device focus and decentralized C2 make detection and remediation difficult; owners should disable remote admin, update firmware, and replace end‑of‑life hardware.
Source: Ars Technica
“BlackSanta” malware kills EDR/AV at kernel level before data theft
Researchers detail a new threat that disables endpoint protections at the kernel layer, clearing the way for credential harvesting, reconnaissance, and exfiltration. The tool’s defensive‑evasion focus and staging tactics raise detection bars; security teams should harden kernel‑mode protections, enforce application control, and scrutinize unusual driver loads.
Source: SecurityWeek
Polyfill supply chain attack re-attributed to North Korea
New analysis links the widespread 2024 polyfill.io compromise—impacting over 100,000 sites—to North Korean operators, not China as initially suspected. The case highlights the systemic risk of third‑party JavaScript dependencies; defenders should favor self‑hosting critical libraries, enforce subresource integrity (SRI), and continuously inventory/monitor external scripts.
Source: SecurityWeek
Flashpoint: Agentic attack chains scale intrusions as infostealers flood markets
Flashpoint’s 2026 Global Threat Intelligence Report finds cybercriminals automating full intrusion lifecycles with agentic workflows, tightly coupling stolen identity data, unpatched edge devices, and ransomware operations. With machine‑speed campaigns lowering human involvement, organizations need continuous exposure management, rapid credential hygiene, and automated containment to keep pace.
Source: Help Net Security
You May Also Be Interested In...
Meta rolls out anti-scam tools across WhatsApp, Facebook, and Messenger