HomeCybersecurity NewsCybersecurity news roundup, March 2, 2026
March 2, 2026

Cybersecurity news roundup, March 2, 2026

San Mateo, CA, March 2, 2026 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.

Phishing hits record highs as identity theft overtakes exploits

Darktrace says it detected more than 32 million high-confidence phishing emails in 2025, with attackers leaning on automation and speed. Over 8.2 million targeted VIPs, while 1.6 million came from newly created domains and 1.2 million used malicious QR codes. Many messages looked legitimate enough to clear controls, with 70% passing DMARC authentication, 41% tagged as spear-phishing, and 38% using novel social engineering. Darktrace also reports that identity compromise overtook vulnerability exploitation as the dominant initial access vector, with SaaS and Microsoft 365 account takeovers accounting for nearly 70% of incidents across the Americas. Shane Barney of Keeper Security said, “Identity has become the attacker’s skeleton key,” and warned that fragmented or overly permissive identity controls let adversaries move laterally “under the cover of legitimacy.” Read more.

Claude Code bugs turn poisoned repos into device backdoors

Cisco is warning that a maximum-severity flaw in its networking products has been exploited over the internet for at least three years, with evidence dating back to 2023. Successful attackers can remotely gain the highest-level permissions on affected devices, establish persistent hidden access inside enterprise networks, and spy on or steal data over time. Cisco said some victims appear to be critical infrastructure, while a joint advisory from Australia, Canada, New Zealand, the U.K., the U.S., and others says targeting is global. CISA said it is aware of ongoing exploitation and ordered U.S. civilian federal agencies to patch by the end of the day Friday, citing imminent risk, even as it operates under a partial shutdown. No threat group has been named. Read more.

Flaws in Claude Code create risk for developers’ devices

Check Point Research found three critical flaws in Anthropic’s Claude Code that could allow attackers to run arbitrary commands, steal credentials, and take over a developer machine simply by opening a poisoned repository. Two issues, tracked together as CVE-2025-59536, abused repository-controlled configuration for Hooks and Model Context Protocol servers to execute commands before meaningful consent, creating a supply-chain path via a single malicious commit. A third bug, CVE-2026-21852, in versions before 2.0.65 enabled silent API key interception by rerouting Claude-to-Anthropic traffic to an attacker server. Researchers Aviv Donenfeld and Oded Vanunu warned that “configuration files that were once passive data now control active execution paths.” Read more.

Fewer victims pay ransoms even as demands skyrocket

Ransomware payment rates hit a new low in 2025, even as attack claims rose. Chainalysis says only 28% of victims paid last year, down from 62.8% in 2024 and 78.9% in 2022, while overall on-chain payments reached $820 million and may “approach or exceed $900 million” as attribution improves. Despite roughly 50% year-over-year growth in claimed attacks, total payment counts stayed relatively stable, and the median ransom jumped 368%, from $12,738 to $59,556. Analysts tracked 85 active extortion groups, with the U.S. the top target, followed by Canada, Germany, and the U.K. Initial access brokers earned $14 million, and access prices fell to $439 in Q1 2026. Chainalysis predicts that ransomware is experiencing a phase of adaptation to extract more money from fewer victims. Read more.

Ex-defense exec jailed for selling zero-days to Russia

Former L3Harris executive Peter Williams was sentenced to more than seven years in prison after admitting he stole and sold at least eight zero-day exploits linked to a specialized L3Harris cybersecurity unit, Trenchant. Prosecutors said the exploits were intended for restricted use by the U.S. government and allied partners, but Williams sold them over a three-year period to a Russian broker identified in court as “Company 3.” Authorities said he was paid in cryptocurrency, earned about $1.3 million, and used proceeds on luxury goods. A restitution hearing is scheduled for May. Neither L3Harris nor Trenchant has been accused of any wrongdoing. Read more.

CarGurus breach exposes 12.5 million user records

Automotive marketplace CarGurus is facing a major data breach after millions of customer records were stolen and later reported by Have I Been Pwned. The breach allegedly exposed 12.5 million accounts, including names, email addresses, phone numbers, and physical addresses, along with user account ID mappings, finance prequalification application data, and dealer account and subscription information. Have I Been Pwned attributed the incident to ShinyHunters, a group widely known for social engineering attacks, including help desk impersonation to trigger password resets and gain access. The group has also been linked to breaches affecting universities and Salesforce customers, including Google and Workday. Read more.

$10K challenge aims to break Ring’s cloud lock-in

The Fulu Foundation is offering a $10,000 bounty, plus matched community donations of up to another $10,000, for the first eligible submission that enables Ring camera owners to run their devices locally and prevent data from reaching Amazon servers. The nonprofit wants a workable path to redirect footage to an owner-controlled computer or server. Fulu tied the bounty to Ring’s privacy history, including a $5.6 million FTC settlement and criticism of the company’s subscription-driven model. A Super Bowl ad that alarmed viewers by advertising Ring’s surveillance features also added fuel to the fire, with one online user saying, “They want to sell me hardware, sell me a subscription to run the hardware, sell me a subscription to monitor my system, and then sell all of my information to nefarious actors. They’re basically sacrificing my community’s privacy and security, and charging me for the experience.” Fulu also says the effort highlights broader limits on tech ownership under DMCA Section 1201, which restricts users’ ability to circumvent platform controls. Read more.

Steganography hides malware inside innocent PNG files

Veracode researchers uncovered a malicious NPM package, buildrunner-dev, that used steganography to hide .NET malware inside PNG images and deliver the Pulsar RAT to Windows systems, marking an evolution in software supply chain tradecraft. The typosquatted package impersonated abandoned buildrunner projects and triggered a postinstall init.js script that downloaded packageloader.bat from Codeberg, then established persistence in the Startup folder. Analysts found seven obfuscation layers and mostly junk content inside the batch file. The malware elevated privileges with the fodhelper.exe UAC bypass, launched hidden PowerShell via conhost.exe, checked installed antivirus, and decoded payloads from ImgBB-hosted images, including an AMSI bypass and .NET loader. A third PNG served as a live steganographic C2 channel for the final encrypted payload. Read more.

ATM jackpotting spree drains $20M from U.S. banks

The FBI says ATM jackpotting surged in 2025, with more than 700 U.S. attacks causing over $20 million in losses and accounting for nearly two-fifths of incidents recorded since 2020. Attackers typically use Ploutus malware to abuse the XFS API, bypass bank authorization, and force ATMs to dispense cash. “Ploutus attacks the ATM itself rather than customer accounts, enabling fast cash-out operations that can occur in minutes and are often difficult to detect until after the money is withdrawn,” the report said. The bureau also warned that crews often use generic keys to open machines, then install malware on the existing hard drive or swap in a preloaded device, exploiting Windows across multiple ATM brands. Recommended defenses include stronger physical locks and sensors, hardware controls, centralized logging, auditing, IP and software whitelisting, endpoint detection, threat intelligence sharing, and updated staff training. Read more.

AI-boosted hacker cracks 600 firewalls in global sweep

Amazon warns that a Russian-speaking threat actor breached more than 600 FortiGate firewalls in 55 countries from January 11 to February 18, 2026. They did so by targeting internet-exposed management interfaces and weak credentials without MFA, rather than by using exploits. The attacker used generative AI services to build and document Python, Go, and PowerShell tooling for reconnaissance, lateral movement planning, and credential theft. Amazon found signs of AI-generated code quality issues that caused failures in hardened environments. After extracting FortiGate configurations, the actor mapped networks, scanned hosts, and targeted the Veeam backup infrastructure, a common pre-ransomware step. Amazon assessed the actor as low-to-medium skill, but amplified by AI. The company is urging admins to disable exposed management access, enable MFA, separate passwords, and harden backups across opportunistic global campaigns. Read more.

More cybersecurity news

About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles