Week in review: Self-spreading npm malware hits developers, Cisco SD-WAN 0-day exploited since 2023
2026-03-04T21:07:25Z•35fb58a6162648c94f097b85e8c832d178f4834d0bb1fc5adf5b33a7859592ce
Android 17Cisco SD-WANContacts PickerEuropolEyeDropper APIIllumio InsightsIronCurtainLLM agent securityMeta scamsNHIsSophos report','off-hours attacks','NATO','iPhone','iPad','classThe ComWindows 365ad fraudagentless visibilitycloud PCidentity observabilitynon-human identitiesnpm malwareprivacyransomwaresecrets managementself-spreading malwaresupply chainzero-day
What happened
Weekly roundup covering multiple high-impact security developments: a self‑spreading npm malware campaign targeting developers and continued exploitation of a Cisco SD‑WAN zero‑day (active since 2023); IronCurtain, an open‑source safeguard for autonomous LLM agents to prevent unauthorized actions; Meta pursuing scammers via lawsuits and technical takedowns; Europol’s Project Compass actions and arrests against The Com ransomware/extortion network; Android 17 beta privacy additions (Contacts Picker, EyeDropper API); Microsoft expanding Windows 365 Cloud PC hardware partners; Illumio Insights’ (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 35fb58a6162648c94f097b85e8c832d178f4834d0bb1fc5adf5b33a7859592ce
- Enrichment time
- 2026-03-04T21:07:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.