[Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real Attacks

2026-03-26T13:24:12Z3a0ae538f3f6e4ac6a7101caa370a0c9221149637f836d06b9ea1bc238a997b8
BYOVDCI/CD-compromiseEDR-bypassbackdoorbrowser-extensioncredential-theftcryptostealingcsp-bypassdevice-code-phishinggithub-actionsios-exploitkernel-exploitmalvertisingmobile-exploit-kitnpm-malwareoauth-abuse','citrix','netscalerpayment-skimmerprompt-injectionsolana-dead-dropssupply-chainvulnerable-driverweb-exploitationwebrtcxsszero-click

What happened

This collection highlights a wave of high-impact attacks and vulnerabilities across supply chains, web/browser extensions, mobile/iOS, and cloud/CI systems. Notable items: a Claude Chrome extension zero-click XSS/prompt-injection enabling silent malicious prompts; Citrix NetScaler critical vulnerabilities (CVE-2026-3055, CVE-2026-4368) allowing data leaks and race-condition exploitation; supply-chain compromises by TeamPCP (backdoored litellm packages and abused GitHub Actions/CI workflows); a WebRTC-based payment skimmer that bypasses CSP to exfiltrate payment data; the Coruna iOS exploit kit

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
3a0ae538f3f6e4ac6a7101caa370a0c9221149637f836d06b9ea1bc238a997b8
Enrichment time
2026-03-26T13:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · [Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real Attacks · Baitaphish