Black Hat USA

2026-03-31T14:51:43Zd30e3b72de54b34b11b7af9d75b80f48ddf83937e58ec5d7496f114444565407
active-exploitationai-powered-malwarecredential-theftexploitinfostealeriot-camerasransomwarercesupply-chaintelecom-espionagethreat-intelligencevulnerability

What happened

A DarkReading news roundup covering multiple high-risk incidents: an AI-generated, obfuscated infostealer called DeepLoad that steals credentials and evades detection; F5 BIG‑IP flaw reclassified as a remotely exploitable RCE (CVE-2025-53521) and observed in the wild; several active supply‑chain attacks (Trivy, Checkmarx KICS, malicious GitHub repo/packages) delivering info‑stealers and trojans; critical, quickly exploited code‑injection and RCE bugs in Langflow and Oracle Fusion Middleware; a disputed 9.8 CVSS “no‑click” Telegram sticker vulnerability; Chinese APT Red Menshen’s upgraded BPF‑/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
d30e3b72de54b34b11b7af9d75b80f48ddf83937e58ec5d7496f114444565407
Enrichment time
2026-03-31T14:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Black Hat USA · Baitaphish