Cyber Briefing: 2026.03.26
Coruna iOS kit evolves, state-backed phishing targets users, WebRTC skimmer evades defenses, major breaches surface, and global cybercrime crackdowns intensify.
👉 What's going on in the cyber world today?
Welcome to Cyber Briefing, the newsletter that informs you about the latest cybersecurity advisories, alerts, incidents and news every weekday.
First time seeing this? Please Subscribe
🚨 Cyber Alerts
1. Coruna IOS Kit Reuses 2023 Exploit Code
The Coruna iOS exploit kit has been identified by researchers as an evolved version of the sophisticated Operation Triangulation framework used in 2023. While originally designed for precision espionage, the toolkit has been updated to support modern M3 chips and is now being deployed in broader, more indiscriminate attacks.
2. FBI Warns Of Russia, Iran Cyber Activity
The FBI and CISA have issued a warning regarding Russian and Iranian cyber operations that target high-profile individuals through popular messaging platforms like Signal. These campaigns use sophisticated phishing techniques to gain unauthorized access to thousands of accounts, allowing actors to bypass encryption by compromising the users themselves rather than the software.
3. WebRTC Skimmer Bypasses CSP Defenses
Researchers have identified a sophisticated payment skimmer that utilizes WebRTC data channels to deliver malicious payloads and exfiltrate sensitive information. By leveraging this peer-to-peer protocol, the malware successfully evades traditional security measures like Content Security Policies that are designed to block unauthorized HTTP traffic.
For more alerts click here!
💥 Cyber Incidents
4. New Horizons Breach Exposes Sensitive Data
New Horizons Behavioral Health in Columbus, Georgia, recently reported a data breach involving unauthorized access to its computer network in January 2026. The organization is currently identifying individuals whose personal and medical information was exposed and plans to provide credit monitoring services to those affected.
5. Ajax Breach Exposes 300K Fans’ Data
Ajax Amsterdam has confirmed a significant data breach resulting from a system vulnerability that allowed unauthorized access to sensitive information. While the club initially reported limited exposure, subsequent reports indicate that the personal data of approximately 300,000 fans may have been compromised.
6. Navia Breach Impacts HackerOne Data
A breach at third-party provider Navia Benefit Solutions has compromised the personal information of approximately 300 HackerOne employees. The incident underscores the persistent vulnerability cybersecurity firms face when their external partners fall victim to data theft.
For more incidents click here!
📢 Cyber News
7. State Dept Counters Iran Cyber, AI Threats
The State Department has established the Bureau of Emerging Threats to counter the weaponization of advanced technologies like artificial intelligence by adversaries such as Iran and China. This new entity is designed to protect national security by addressing modern dangers involving cyberattacks, outer space, and critical infrastructure.
8. Russia Arrests Alleged LeakBase Admin
Russian authorities have apprehended a resident of Taganrog suspected of managing LeakBase, a prominent marketplace for illicitly obtained personal information. The individual is accused of overseeing the platform’s operations since 2021, facilitating the exchange of stolen data among a massive global user base.
9. RedLine Malware Admin Extradited To US
Hambardzum Minasyan, an Armenian citizen, has been extradited to the United States to face charges for his alleged role in managing the infrastructure of the notorious RedLine infostealer. According to federal authorities, Minasyan was responsible for maintaining servers, processing cryptocurrency payments, and providing technical support for the malware-as-a-service operation.
For more news click here!
📈Cyber Stocks
Cybersecurity stocks were mixed to weaker on Thursday, 26 March 2026, even as the broader U.S. market and tech benchmarks moved higher.
CrowdStrike closed at 385.86 dollars and declined, with high-multiple endpoint security stocks continuing to see selling even as the Nasdaq advanced.
Okta closed at 78.12 dollars and was higher, as identity security names saw selective buying after Tuesday’s pullback.
Zscaler closed at 139.44 dollars and was essentially flat to slightly higher, suggesting cloud security valuations stabilized after the sharp decline in the prior session.
Fortinet closed at 78.89 dollars and declined, as network security names continued to reflect cautious sentiment around enterprise software multiples.
Check Point Software Technologies closed at 142.41 dollars and declined, with its more defensive profile holding up better than some higher-growth peers but still finishing lower.
💡 Cyber Tip
🔐 FBI Warns of Russia & Iran Messaging Attacks
The FBI and CISA warn that Russian and Iranian hackers are targeting users on apps like Signal through phishing scams. These attacks trick people into sharing verification codes or linking devices, allowing attackers to access messages and impersonate victims.
🛠️ What You Should Do
Never share verification codes or login details with anyone
Avoid clicking links or responding to unexpected “support” messages
Regularly review and remove unknown linked devices from your accounts
Enable additional security features like PINs or app-level locks
⚠️ Why This Matters
These attacks bypass encryption by targeting users directly instead of the app itself. Once access is gained, attackers can read private messages and use trusted accounts to spread further attacks.
📚 Cyber Book
Gambling on AI by James Whittaker Screech
Copyright © 2026 CyberMaterial. All Rights Reserved.
Follow CyberMaterial on:
Substack, LinkedIn, Twitter, Reddit, Instagram, Facebook, YouTube, and Medium










