CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (28 March 2026)

Published: Loading…

At a Glance

  • TeamPCP compromised the Telnyx Python SDK on PyPI, embedding credential-stealing malware using WAV steganography on Unix and persistent binaries on Windows.
  • LangChain and LangGraph frameworks contain three critical vulnerabilities exposing filesystem data, environment secrets, and full conversation histories across enterprise AI applications.
  • TikTok for Business accounts are being targeted by AiTM phishing campaigns using cloned TikTok and Google-themed pages hosted on Cloudflare domains.
  • Researchers identified Railway PaaS abuse to capture Microsoft 365 OAuth device codes, enabling token theft and bypassing multi-factor authentication controls.
  • Apple confirms that devices with Lockdown Mode enabled have not been compromised by mercenary spyware, including NSO Group's Pegasus and similar exploits.

Summary

The Telnyx Python SDK on PyPI was compromised by TeamPCP, embedding credential-stealing malware. Unix systems received a WAV-steganography payload, while Windows systems installed a persistent Startup binary. The campaign followed patterns observed in prior LiteLLM attacks.

LangChain and LangGraph frameworks contain multiple vulnerabilities, including path traversal, SQL injection, and insecure serialization. Exploitation allows access to filesystem data, environment secrets, and conversation histories across AI applications. Over 847 million downloads indicate broad exposure in enterprise environments.

TikTok for Business accounts are under attack from account-in-the-middle phishing campaigns. Adversaries deploy cloned TikTok and Google-themed login pages using Cloudflare hosting and bot-detection evasion, harvesting credentials and leveraging single sign-on connections for further access.

Microsoft 365 OAuth device codes are being targeted through Railway PaaS abuse. Victims provide authentication codes that attackers convert into access and refresh tokens, maintaining persistent access and bypassing multi-factor authentication protections across multiple organisations.

Apple reports that Lockdown Mode has successfully prevented spyware attacks on all protected devices. Attempts by mercenary spyware, including NSO Group's Pegasus, have been blocked, effectively reducing attack surface and stopping exploitation of common system vectors.

Highlights of the Day

TeamPCP Backdoors Telnyx PyPI SDK Days After LiteLLM Compromise

Two PyPI releases of the Telnyx Python SDK were found to contain malicious code executing on import, delivering platform-specific malware on Windows and Linux/macOS. The payload uses WAV steganography on Unix systems to fetch a credential harvester, exfiltrating SSH keys, cloud secrets, and Kubernetes credentials, while Windows systems receive a persistent Startup binary. The attack is linked to TeamPCP through an identical RSA-4096 key used in the earlier LiteLLM compromise and follows the same AES-256-CBC and RSA OAEP exfiltration pattern.

LangChain Vulnerabilities Expose Files, Secrets, and Conversations

Researchers identified three critical vulnerabilities in LangChain and LangGraph affecting enterprises using AI frameworks. Path traversal allows arbitrary file access, serialization flaws expose environment secrets, and SQL injection retrieves full conversation histories, all through standard framework functions. The issues highlight risks in AI middleware where sensitive data flows invisibly through widely deployed code, with over 847 million Python package downloads, impacting a vast ecosystem of dependent applications and integrations.

TikTok Business Accounts Targeted by AITM Phishing Campaigns

Researchers identified a surge of account-in-the-middle phishing pages targeting TikTok for Business accounts. Attackers use cloned TikTok and Google-themed pages to harvest login credentials, exploiting single sign-on connections to access linked apps. The campaign leverages Cloudflare-hosted domains, bot-detection evasion, and rapid domain registration to bypass security controls and distribute infostealers or ad fraud infrastructure across multiple platforms.

Apple Confirms Lockdown Mode Prevents Spyware Attacks

Apple reports that no devices using Lockdown Mode have been compromised by mercenary spyware since its 2022 launch. The feature disables common attack vectors exploited by government-grade spyware, reducing remotely reachable attack surfaces. Independent security researchers and digital rights organisations have observed Lockdown Mode blocking attempts from NSO Group’s Pegasus and other spyware, highlighting its effectiveness in protecting at-risk users without documented bypasses to date.

Source: TechCrunch

Threat Actors Exploit Railway PaaS to Compromise Microsoft 365 Tokens

Arctic Wolf has observed threat actors leveraging Railway PaaS infrastructure to host phishing attacks targeting Microsoft 365’s OAuth device code flow. Victims are tricked into submitting authentication codes, allowing attackers to capture valid access and refresh tokens, bypass multi-factor authentication, and maintain persistent access. The campaign, linked to the EvilTokens phishing-as-a-service platform, has impacted hundreds of organisations across multiple regions and remains active, highlighting the ongoing abuse of trusted cloud platforms to evade detection.

Daily Coverage

Developments
Telnyx Sdk CompromiseLangchain FlawsTiktok Aitm PhishingRailway Paas Attacks
Vulnerabilities
CVE-2025-53521Big-Ip 17.5.0 (Critical)CVE-2026-3055Adc 14.1 (Critical)
Threat Groups
TA446Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.