https://t.co/QekiU9BbjE More than 400 packages in the Arch User Repository (AUR) are distributing a Linux rootkit and infostealer malware targeting credentials and access tokens.
https://t.co/BRPyVduifg GPT‑Rosalind is now available in research preview to eligible organizations globally through our trusted-access deployment structure.
https://t.co/RZVOQaanu4 For years, software supply-chain security was often treated as a technical issue for developers, DevOps teams, and security engineers. That framing no longer fits the real risk.
https://t.co/bC5RrCZpyB According to the IMF, the financial sector relies heavily on shared digital infrastructure, which means a single vulnerability could have consequences for multiple institutions simultaneously. #cybersecurity
https://t.co/xVJWEv7M1V A malicious Hugging Face repository managed to take a spot in the platform's trending list by impersonating OpenAI's Privacy Filter open-weight model to deliver a Rust-based information stealer to Windows users. (Kids these days. Yall just dl anything)
https://t.co/glKzMT4tmX The basic goal is still the same: steal credentials from developer machines and CI/CD runners, then use those credentials to reach more packages. #linux#cybersecurity#supplychain
https://t.co/MoSluvvwsw The activity is said to be the work of cybercrime threat actors who appear to have collaborated together to plan what the tech giant described as a "mass vulnerability exploitation operation."
https://t.co/oFmA50hhwf The hacker behind a breach at education technology giant Instructure claims to have stolen 280 million records tied to students and staff from 8,809 colleges, school districts, and online education platforms. #cybersecurity
https://t.co/BzNB5Y5ri8 CISA is warning that a newly disclosed Linux kernel bug dubbed "CopyFail" is already being exploited, just days after researchers dropped a working root-level exploit. #linux#cybersecurity
https://t.co/hS83EF7mmS An apparent data breach may have compromised user information submitted to https://t.co/HZpBJlCEre, a newly launched platform designed to organize opposition to proposed ICE detention facilities across the United States. #ICE#cybersecurity
https://t.co/6L6MpIrx3N WARN - cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. This is big. Check your versions. #cybersecurity
https://t.co/N91Ujtl1OK The actress warned women that their careers are likely to be taken over by AI if they don’t start learning about the tech. That’s prompted a social media outcry. #ai
https://t.co/YurvBTanWS Microsoft has released Windows 11 KB5083769 and KB5082052 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. #windows#cybersecurity
https://t.co/jvnJRbtVpn The malicious versions were available for approximately three hours before PyPI quarantined the package. LiteLLM is downloaded roughly 3.4 million times per day.
#cybersecurity#trivy#litellm#openclaw
https://t.co/dZ6wWvJrb8 The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity vulnerability, CVE-2026-20131, in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22.
https://t.co/lajjMlSFPc A new indictment alleges that three men affiliated with server maker Supermicro conspired to sell $510 million in servers with banned Nvidia chips to China
#cybersecurity
https://t.co/ubd3VJqs4f Apple is urging users who are still running an outdated version of iOS to update their iPhones to secure against web-based attacks carried out via powerful exploit kits like Coruna and DarkSword.
#cybersecurity#apple
https://t.co/U74va1jmJh 'Just 6 months back, Model Context Protocol (MCP) was all that anyone could talk about and it seemed that everyone was in a frenzy to ship MCP-related offerings and tools.'