CrowdStrike patched CVE-2026-40050, a critical path traversal vulnerability in self-hosted LogScale that let remote, unauthenticated attackers read arbitrary files from the server. Organizations should update immediately and review access controls and web exposure for LogScale instances to reduce blast radius.
Source: Security Affairs
‘Pack2TheRoot’: Easily exploitable Linux PackageKit bug leads to root
Researchers detailed a race condition in PackageKit that allows local, unprivileged users to escalate privileges during package installation. The flaw is reportedly easy to exploit, underscoring the need to apply vendor patches quickly and tighten policies around software installation on endpoints and servers.
Source: SecurityWeek
Firefox vulnerability enables Tor user fingerprinting, now patched
Mozilla fixed CVE-2026-6770, a Firefox issue that could allow fingerprinting of Tor Browser users, with patches landing in Firefox 150 and Tor 15.0.10. Privacy-focused users should update immediately to prevent cross-site tracking and potential deanonymization via browser behavior signals.
Source: SecurityWeek
Trigona ransomware switches to custom data theft tool to evade detection
Symantec observed Trigona operators replacing common exfiltration utilities like Rclone and MegaSync with a bespoke command-line tool, accelerating data theft and reducing telemetry defenders rely on. The March 2026 shift gives attackers more control and stealth; defenders should hunt for anomalous outbound flows and unsigned, short-lived binaries.
Source: Security Affairs
UNC6692 uses email bombing and social engineering to deploy ‘Snow’ malware
A threat actor tracked as UNC6692 leveraged email bombing and social engineering to push the Snow malware family (Snowbelt, Snowglaze, Snowbasin) for long-term access. The campaign highlights how operational disruptions and inbox overload can be weaponized; implement resilient email filtering, user training, and behavior-based EDR to spot persistence chains.
Source: SecurityWeek
US targets Southeast Asia cyberscam networks, sanctions Cambodian senator
The U.S. launched a broad crackdown on cyberscam operations across Southeast Asia, pairing criminal actions with Treasury sanctions, including against a Cambodian senator. The effort, led by a Scam Center Strike Force, signals escalating pressure on transnational organized cybercrime and raises compliance stakes for financial and tech intermediaries.
Source: SecurityWeek
Utility giant Itron discloses breach after detecting unauthorized access
Itron reported detecting unauthorized access to part of its IT environment on April 13, 2026, initiating incident response, engaging external experts, and notifying authorities. While impact details are limited, the incident underscores supply chain exposure in critical infrastructure ecosystems and the need for third-party risk visibility.
Source: Security Affairs
You May Also Be Interested In...
GopherWhisper: new China-linked APT targets Mongolia with Go-based malware
Fast16: Pre-Stuxnet malware that targeted precision engineering software
NIST NVD Update: What it Means For Vulnerability Management