Week in review: Self-spreading npm malware hits developers, Cisco SD-WAN 0-day exploited since 2023

2026-03-04T21:07:25Z35fb58a6162648c94f097b85e8c832d178f4834d0bb1fc5adf5b33a7859592ce
Android 17Cisco SD-WANContacts PickerEuropolEyeDropper APIIllumio InsightsIronCurtainLLM agent securityMeta scamsNHIsSophos report','off-hours attacks','NATO','iPhone','iPad','classThe ComWindows 365ad fraudagentless visibilitycloud PCidentity observabilitynon-human identitiesnpm malwareprivacyransomwaresecrets managementself-spreading malwaresupply chainzero-day

What happened

Weekly roundup covering multiple high-impact security developments: a self‑spreading npm malware campaign targeting developers and continued exploitation of a Cisco SD‑WAN zero‑day (active since 2023); IronCurtain, an open‑source safeguard for autonomous LLM agents to prevent unauthorized actions; Meta pursuing scammers via lawsuits and technical takedowns; Europol’s Project Compass actions and arrests against The Com ransomware/extortion network; Android 17 beta privacy additions (Contacts Picker, EyeDropper API); Microsoft expanding Windows 365 Cloud PC hardware partners; Illumio Insights’ (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
35fb58a6162648c94f097b85e8c832d178f4834d0bb1fc5adf5b33a7859592ce
Enrichment time
2026-03-04T21:07:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.