EU court adviser says banks must immediately refund phishing victims
2026-03-09T13:23:32Z•7703b6121a00a62e3d9a6ad70cbc7fe2caa77b69a4dacb7c4fa9df3df158ac1f
.arpaUAT-9244aptcastleratchina-linked-aptclickfixdata-breachdonutloaderfbi-breachhealthcareinfostealerinstallfixios-exploits','coruna'ipv6javascript-wormphishing-evasionplugin-exploitransomwaresurveillance-systemstelecom-targetingtermitetrizettovelvet-tempestwikipediawordPress
What happened
This collection of security reports highlights multiple high-risk active campaigns and large breaches. Attackers are abusing .arpa reverse DNS and IPv6 for phishing-evasion, and using novel social-engineering techniques (ClickFix/InstallFix) to push infostealers, DonutLoader, and the CastleRAT backdoor—linked to Termite/Velvet Tempest ransomware activity. Major incidents include a Cognizant TriZetto breach exposing ~3.4M patient records, an FBI investigation into a breach of surveillance/wiretap systems, and widespread exploitation of a critical WordPress membership plugin to create admin back
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 7703b6121a00a62e3d9a6ad70cbc7fe2caa77b69a4dacb7c4fa9df3df158ac1f
- Enrichment time
- 2026-03-09T13:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.