Only Trump can decide when cyberwar turns into real war
2026-03-25T19:24:06Z•74feb36e824bde6e3447d535c410bb6c4a6fb64c258bc9805959594624e46597
credential‑stealerdark-webddosextortiongoogle-geminiincident-responseiot-botnetiranlapsuslitellmmalwaremicrosoft-intunenation-statepatchingpypirapid-exploitationsharepointsocial-engineeringstrykersupply-chaintrivyvoice-phishingzero-day
What happened
A cluster of active, high-impact incidents and trends dominated The Register’s security feed: a Trivy supply‑chain compromise has led to credential‑stealing malware infecting 1,000+ cloud environments and collaborating with extortion groups; two LiteLLM PyPI releases were removed after malicious code was introduced via polluted CI/CD; unknown actors are actively exploiting a critical Microsoft SharePoint vulnerability; and Iran-linked attackers abused Microsoft Intune in the Stryker incident. Additional coverage highlights rising voice‑phishing and social‑engineering attacks (including actors
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 74feb36e824bde6e3447d535c410bb6c4a6fb64c258bc9805959594624e46597
- Enrichment time
- 2026-03-25T19:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.