Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (31 March 2026)
Published: Loading…
At a Glance
- The European Commission confirmed attackers breached Europa.eu and stole over 350GB of data, affecting at least one AWS account and Union entities.
- A fail-open bug in Open VSX allowed malicious VS Code-compatible extensions to bypass scanning and be published, fixed on 11 February 2026.
- Researchers disclosed a ChatGPT code execution runtime flaw that exfiltrated sensitive user data via DNS, fixed by OpenAI on 20 February 2026.
- Vietnam-linked actors distributed PXA Stealer through compromised LinkedIn accounts, targeting job seekers in India, Bangladesh, Netherlands, Sweden, and the United States.
- CareCloud reported a temporary breach in one of its six EHR environments, causing an eight-hour disruption while patient data access remains under investigation.
Summary
The European Commission confirmed attackers accessed its Europa.eu web platform and stole over 350GB of data. At least one Amazon Web Services account was affected, and affected Union entities are being notified. The breach did not disrupt public websites or internal Commission systems.
A fail-open flaw in Open VSX allowed malicious VS Code-compatible extensions to bypass pre-publish scanning. The bug treated absent scanners and failed job enqueues identically, enabling attackers to publish extensions. The issue was fixed on 11 February 2026.
Check Point Research revealed a ChatGPT runtime vulnerability that exfiltrated sensitive conversation data through DNS channels. Both messages and uploaded files could be accessed without user consent. OpenAI deployed a fix on 20 February 2026.
Vietnam-linked threat actors leveraged compromised LinkedIn accounts to distribute PXA Stealer to job seekers across India, Bangladesh, the Netherlands, Sweden, and the United States. The payload included DLL sideloading and Python-based in-memory execution. It harvested browser credentials, session cookies, cryptocurrency wallets, and authenticator data.
CareCloud reported unauthorised access to one of its six electronic health record environments. The disruption lasted eight hours, and investigators are determining whether patient data was accessed or exfiltrated. Other company systems were not affected.
Emerging malware campaigns and supply-chain risks intersected with AI exploitation, cloud-targeted attacks, and professional network phishing. Multiple vectors exploited both software vulnerabilities and social engineering to harvest credentials, deploy malicious payloads, and disrupt operations.
Highlights of the Day
European Commission Confirms Data Theft from Europa.eu Hack
The European Commission confirmed that attackers breached its Europa.eu web platform and stole data, while saying the incident did not disrupt public websites or affect internal Commission systems. BleepingComputer reported that at least one Amazon Web Services account was impacted, and the Commission said it is notifying affected Union entities while investigating the full scope. ShinyHunters claimed responsibility for the intrusion, told BleepingComputer it stole more than 350GB of data, and published an archive of over 90GB allegedly taken from the compromised cloud environment.
Open VSX Bug Let Unscanned Extensions Go Live
Koi Security disclosed a fail-open flaw in Open VSX’s pre-publish scanning pipeline that could let malicious VS Code-compatible extensions bypass security checks and be published as “PASSED”. The bug stemmed from a boolean return value that treated both “no scanners configured” and “all scanner job enqueues failed” as the same state during publication. Koi said attackers could trigger the condition by flooding the publish endpoint until database connection exhaustion stopped scanner jobs from queuing, and Open VSX fixed the issue on 11 February.
Check Point Finds ChatGPT Runtime Data Leak Path
Check Point Research disclosed a flaw that allowed data exfiltration from ChatGPT’s code execution runtime by abusing DNS resolution as a covert outbound channel despite blocked direct internet access. The researchers said a single malicious prompt or backdoored custom GPT could leak user messages, uploaded files and model-generated summaries to an attacker-controlled server without approval prompts. Check Point also demonstrated remote shell access inside the Linux runtime through the same channel, and said OpenAI fully deployed a fix on 20 February 2026.
LinkedIn Job Lures Spread PXA Stealer Across Five Countries
Cyble attributed an active infostealer campaign to a Vietnam-linked actor using compromised LinkedIn accounts to send fake Apex Logistics Group recruitment messages to targets in India, Bangladesh, the Netherlands, Sweden and the United States. Victims are redirected through Google Forms, a shortened URL and a Dropbox-hosted ZIP that launches DLL sideloading with a renamed winword.exe and a padded 100MB malicious DLL. The final payload runs in memory via Python, pulls command-and-control details from an encrypted Telegram channel, and steals browser credentials, session cookies, cryptocurrency wallets, authenticator data, email credentials and Ledger Live artefacts.
CareCloud Probes Possible Patient Data Exposure After EHR System Breach
CareCloud disclosed that an unauthorised third party temporarily accessed one of its six electronic health record environments on 16 March, causing an eight-hour disruption in its CareCloud Health division. The company said the affected environment stores patient information and is still investigating whether any patient or other data was accessed or exfiltrated, including the categories and volume involved. CareCloud reported the incident to law enforcement, said the breach was contained the same day, and stated that its other platforms, divisions, systems and environments were not affected.
Daily Coverage