Daily Recap, a roundup of recent cybersecurity activity highlights macOS ClickFix delivering Infiniti Stealer via a Nuitka loader, iOS exploitation by TA446 using DarkSword to deploy GHOSTBLADE and MAYBEROBOT, and backdoored Telnyx PyPI packages pushed by TeamPCP that use WAV steganography to exfiltrate SSH keys and tokens. The report also covers critical advisories (CVE-2026-3055, CVE-2025-53521), the Open VSX Open Sesame fix, major breaches including the European Commission cloud incident and Handalaâs alleged exfiltration of FBI director materials, plus governance moves such as the CSAM ruling, UK donation limits, the Chip Security Act, and OpenAIâs Bug Bounty program. #InfinitiStealer #DarkSword #GHOSTBLADE #MAYBEROBOT #TeamPCP #Telnyx #NetScaler #CVE2026-3055 #CVE2025-53521 #EuropeanCommission #AnimePlay #Handala #OpenAI #Bugcrowd #OpenVSX #CSAMRuling #ChipSecurityAct
Malware & Phishing
- A macOS ClickFix campaign tricks users into pasting a Cloudflareâthemed Terminal command that deploys a Nuitka loader and the Python-based Infiniti Stealer to harvest browsers, Keychain, crypto wallets, developer secrets and screenshots and exfiltrate via HTTP/Telegram â Infiniti Stealer
- Russiaâlinked TA446 used the leaked DarkSword iOS exploit kit in targeted spearâphishing to deliver GHOSTBLADE and MAYBEROBOT, prompting Apple lockâscreen exploit alerts â DarkSword iOS, Apple Alerts
- Attackers posted fake Visual Studio Code security alerts in GitHub Discussions impersonating maintainers to lure developers into reconnaissance and secondâstage malware delivery â Fake VSCode
- Threat actor TeamPCP pushed backdoored telnyx PyPI versions (4.87.1/4.87.2) that use WAV steganography to install credentialâstealers and exfiltrate SSH keys, cloud tokens and wallets â rollback to 4.87.0 and rotate secrets immediately â Telnyx PyPI, Telnyx PyPI
Vulnerabilities & Advisories
- Attackers are actively probing Citrix NetScaler ADC/Gatewayâs /cgi/GetAuthMethods to exploit a critical inputâvalidation flaw CVE-2026-3055 (CVSS 9.3) that can leak sensitive information â patch or mitigate immediately â NetScaler Recon
- CISA added the critical F5 BIGâIP APM flaw CVE-2025-53521 (CVSS 9.3) to its KEV list after confirmed exploitation; F5 published IOCs/TTPs and FCEB must remediate by March 30, 2026 â F5 KEV
- Open VSX fixed an âOpen Sesameâ bug where preâpublish scanner failures were misinterpreted as âno scanners configured,â allowing malicious VS Code extensions to bypass vetting â patched in 0.32.0 â Open VSX
Breaches & Takedowns
- The European Commission is investigating a breach after a threat actor accessed at least one Amazon cloud account and claims to have stolen over 350 GB of data including employee information and email servers; incident response is ongoing â EC Cloud Breach
- The Alliance for Creativity and Entertainment seized the illegal AnimePlay appâhosted > 60 TB of content and > 5 million registered usersâconfiscating domains, servers and source repos â AnimePlay Takedown
- ProâIranian group Handala claimed responsibility for exfiltrating FBI Director Kash Patelâs personal emails and photos; FBI/DOJ say the material is historical/nonâgovernmental while seizures and rewards continue â Handala Leak, Handala Leak
Policy & Governance
- The European Parliament voted against extending temporary CSAM scanning rules, removing platformsâ exemption and prompting lawâenforcement warnings and privacy concerns about mass surveillance and false positives â CSAM Ruling
- UK reports warn of evolving foreign interference and the government is proposing tighter politicalâdonation rules including a temporary ban on cryptocurrency donations and a ÂŁ100,000 cap for overseas voters â UK Donation Limits
- Congress is advancing a Chip Security Act requiring continuous location verification on exported advanced AI chips to prevent smuggling and diversion after cases like DeepSeek using restricted accelerators â Chip Tracker
AI, Research & Programs
- OpenAI launched a public safety bugâbounty (run via Bugcrowd) focused on AI abuse vectorsâprompt injection, data exfiltration, connector flawsâwith discretionary rewards up to $7,500 â OpenAI Bounty
- Weekly roundup: notable items include transit disruptions, highâprofile account hijacks, outages, ETH Zurichâs antiâdeepfake chip and Googleâs 2029 quantumâsafe deadline among other developments â Other News
- Analysis: âAgentic GRCâ warns that while teams have agentic tech, the missing piece is a governance mindset shift to manage risks posed by agentic systems â Agentic GRC