03/26

Project Zero: Blasting Past Webp

https://googleprojectzero.blogspot.com/2025/03/blasting-past-webp.html
Project Zero: Blasting Past Webp

Google Patches Chrome Sandbox Escape Zero-Day Caught by Kaspersky - SecurityWeek

https://www.securityweek.com/google-patches-chrome-sandbox-escape-zero-day-caught-by-kaspersky/
Google Patches Chrome Sandbox Escape Zero-Day Caught by Kaspersky - SecurityWeek

Google fixes Chrome zero-day exploited in espionage campaign

https://www.bleepingcomputer.com/news/security/google-fixes-chrome-zero-day-exploited-in-espionage-campaign/
Google fixes Chrome zero-day exploited in espionage campaign

New Windows zero-day leaks NTLM hashes, gets unofficial patch

https://www.bleepingcomputer.com/news/security/new-windows-zero-day-leaks-ntlm-hashes-gets-unofficial-patch/
New Windows zero-day leaks NTLM hashes, gets unofficial patch

StreamElements discloses third-party data breach after hacker leaks data

https://www.bleepingcomputer.com/news/security/streamelements-discloses-third-party-data-breach-after-hacker-leaks-data/
StreamElements discloses third-party data breach after hacker leaks data

Broadcom warns of authentication bypass in VMware Windows Tools

https://www.bleepingcomputer.com/news/security/broadcom-warns-of-authentication-bypass-in-vmware-windows-tools/
Broadcom warns of authentication bypass in VMware Windows Tools

IngressNightmare-POCs/CVE-2025-1974 at main · sandumjacob/IngressNightmare-POCs · GitHub

https://github.com/sandumjacob/IngressNightmare-POCs/tree/main/CVE-2025-1974
IngressNightmare-POCs/CVE-2025-1974 at main · sandumjacob/IngressNightmare-POCs · GitHub

New npm attack poisons local packages with backdoors

https://www.bleepingcomputer.com/news/security/new-npm-attack-poisons-local-packages-with-backdoors/
New npm attack poisons local packages with backdoors

Russian Ransomware Gang Exploited Windows Zero-Day Before Patch - SecurityWeek

https://www.securityweek.com/russian-ransomware-gang-exploited-windows-zero-day-before-patch/
Russian Ransomware Gang Exploited Windows Zero-Day Before Patch - SecurityWeek

Exclusive: DOGE staffer 'Big Balls' provided tech support to cybercrime ring, records show | Reuters

https://www.reuters.com/world/us/doge-staffer-big-balls-provided-tech-support-cybercrime-ring-records-show-2025-03-26/
Exclusive: DOGE staffer 'Big Balls' provided tech support to cybercrime ring, records show | Reuters

New Atlantis AIO platform automates credential stuffing on 140 services

https://www.bleepingcomputer.com/news/security/new-atlantis-aio-automates-credential-stuffing-on-140-services/
New Atlantis AIO platform automates credential stuffing on 140 services

Teen Warned Not To Accept Group Chat Invites From National Security Advisors She Doesn’t Know - The Onion

https://theonion.com/teen-warned-not-to-accept-group-chat-invites-from-national-security-advisors-she-doesnt-know/
Teen Warned Not To Accept Group Chat Invites From National Security Advisors She Doesn’t Know - The Onion

RedCurl cyberspies create ransomware to encrypt Hyper-V servers

https://www.bleepingcomputer.com/news/security/redcurl-cyberspies-create-ransomware-to-encrypt-hyper-v-servers/
RedCurl cyberspies create ransomware to encrypt Hyper-V servers

Windows 11 update breaks Veeam recovery, causes connection errors

https://www.bleepingcomputer.com/news/microsoft/windows-11-update-breaks-veeam-recovery-causes-connection-errors/
Windows 11 update breaks Veeam recovery, causes connection errors