Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (25 March 2026)
Published: Loading…
At a Glance
- TeamPCP compromised LiteLLM PyPI versions 1.82.7 and 1.82.8, embedding infostealer malware to exfiltrate cloud, crypto, and CI/CD credentials.
- Five malicious npm packages typosquatting Solana and Ethereum libraries steal private keys to a hardcoded Telegram bot, affecting crypto developers' wallets.
- Citrix NetScaler ADC and Gateway suffer CVE-2026-3055 out-of-bounds read vulnerability, leaking memory data from SAML-configured instances without authentication.
- Russian initial access broker Aleksei Volkov was sentenced to 81 months in US prison for enabling Yanluowang ransomware attacks causing millions in losses.
- Redash Python data source flaw allows sandbox escape, enabling arbitrary system command execution and full server compromise across vulnerable instances.
- FCC bans import of consumer routers manufactured outside the U.S., citing national security risks from state-sponsored espionage and compromised devices.
Summary
Malicious activity in open source software supply chains continues to escalate. TeamPCP compromised LiteLLM PyPI versions 1.82.7 and 1.82.8, embedding nested payloads that exfiltrate cloud, Kubernetes, GitHub, Slack, Discord, and cryptocurrency credentials. The attack leveraged a polluted CI/CD pipeline, enabling persistence and further downloads from a command-and-control server.
Simultaneously, five npm packages typosquatting legitimate Solana and Ethereum libraries were discovered stealing private keys to a hardcoded Telegram bot. The campaign affected direct and transitive dependencies, allowing attackers to compromise developer wallets across multiple ecosystems. Obfuscation in the payloads concealed the exfiltration channel, maintaining normal package functionality while harvesting credentials.
Critical vulnerabilities continue to threaten enterprise infrastructure. Citrix NetScaler ADC and Gateway suffer from CVE-2026-3055, an out-of-bounds read allowing unauthenticated memory data leaks on SAML-configured instances. Patching is advised, though default and cloud-managed deployments remain unaffected. The flaw carries a CVSS score of 9.3, highlighting the potential impact on session tokens and sensitive configuration data.
Law enforcement actions mark another notable development. Russian initial access broker Aleksei Volkov was sentenced to 81 months in US federal prison for facilitating Yanluowang ransomware attacks. The co-conspirators attempted extortion totaling approximately $24 million, and restitution of $9.2 million has been ordered. Volkov’s activities exemplify the monetisation of network access for ransomware campaigns.
Other software and cloud platforms face exploitable flaws. Redash’s Python data source enables sandbox escape, allowing any user with query access to execute system commands and achieve full server compromise. The vulnerability remains unpatched, presenting a high risk for organisations relying on Redash for analytics and dashboarding. Attackers exploiting this flaw can access sensitive internal data and lateral movement capabilities.
National security concerns are reflected in hardware controls. The FCC banned all consumer routers manufactured outside the U.S. from future imports, citing espionage risks and previous compromises by state-sponsored actors. Existing devices remain in use, but the prohibition underscores supply chain and device security priorities.
The Silver Fox intrusion set continues operations across South Asia, blending espionage with financially motivated malware. Its campaigns target regional organisations using culturally relevant lures and multiple delivery methods, including Python-based stealers disguised as messaging tools.
Highlights of the Day
Citrix NetScaler Flaw Leaks Sensitive Memory Data via SAML Configurations
Citrix has published a security advisory for CVE-2026-3055, a critical out-of-bounds read vulnerability in NetScaler ADC and NetScaler Gateway carrying a CVSS score of 9.3, allowing unauthenticated remote attackers to leak sensitive data from appliance memory. Only customer-managed instances configured as a SAML Identity Provider are affected, with default configurations and Citrix-managed cloud deployments stated as unaffected. No in-the-wild exploitation or public proof-of-concept has been identified at the time of publication, with Citrix reporting the flaw was discovered internally through a security review.
Russian Initial Access Broker Sentenced to 81 Months for Ransomware Role
Aleksei Volkov, a 26-year-old Russian national from St. Petersburg, has been sentenced to 81 months in a US federal court after pleading guilty to charges including computer fraud, access device fraud, aggravated identity theft, and conspiracy to commit money laundering. Volkov operated as an initial access broker for several major cybercrime groups, including the Yanluowang ransomware operation, with co-conspirators collectively attempting to extort approximately $24 million from victim organisations. Arrested in Rome in 2024 and extradited to the United States in 2025, Volkov has agreed to pay at least $9.2 million in restitution to known victims.
Silver Fox Expands Dual-Focus Campaigns Across South Asia
Since early 2025, China-linked intrusion set Silver Fox has combined advanced espionage with financially motivated operations across South Asia, leveraging modular malware, phishing, and compromised tools. Its campaigns evolved from deploying ValleyRAT via tax-themed PDFs to abusing misconfigured RMM software and, most recently, using a Python-based stealer disguised as WhatsApp, highlighting a versatile, adaptive malware ecosystem. Targeting spans Taiwan, Japan, Malaysia, Indonesia, Singapore, Thailand, the Philippines, and India, using culturally relevant lures while maintaining simultaneous opportunistic and strategic operations.
Redash Python Sandbox Flaw Enables Full Server Compromise
OX Security researchers demonstrated a critical vulnerability in Redash’s Python data source that allows sandbox escape, enabling any user with query access to execute arbitrary system commands. Exploiting this flaw results in full server compromise, exposing sensitive data and permitting lateral movement across internal networks. The issue affects all Redash instances with the Python data source enabled, with no patch currently available, highlighting significant risk for organisations relying on Redash for analytics and dashboarding.
FCC Bans Foreign-Made Routers Over National Security Concerns
The FCC has prohibited the import of all consumer routers manufactured outside the U.S., citing “unacceptable risk” to national security and U.S. persons unless exempted by DHS or the Department of War. Compromised routers have been linked to espionage, botnets, and attacks on critical infrastructure, with state-sponsored groups exploiting vulnerabilities in foreign-made devices to gain network access. The ban affects future imports, while existing devices remain in use, reflecting concerns over supply chain security and the reliance on foreign-manufactured networking equipment.
LiteLLM PyPI Malware Targets Cloud and Crypto Credentials
Malicious versions 1.82.7 and 1.82.8 of the LiteLLM Python library were uploaded to PyPI after a maintainer account was compromised, embedding an infostealer that extracts AWS, GCP, GitHub, Kubernetes, Slack, Discord, and cryptocurrency keys. The malware uses nested base64 payloads to collect sensitive data, encrypt it, and send it to a command-and-control server, with a secondary payload capable of executing further downloads.
Malicious npm Packages Typosquat Crypto Libraries to Steal Keys
Five npm packages typosquatting Solana and Ethereum libraries exfiltrate private keys to a Telegram bot, affecting developers handling sensitive cryptocurrency credentials. The campaign, traced to the account galedonovan, leverages both direct and transitive dependencies, with obfuscated payloads in several packages and live C2 infrastructure confirmed as of March 2026. Developers using these packages risk full compromise of their crypto wallets.
Daily Coverage