Latest Internet & Cybersecurity News

📅April 3, 2026 at 1:00 PM
Major cybersecurity incidents dominate headlines: FBI surveillance hack by China-linked actors, North Korean crypto theft from Drift, Microsoft Japan AI-cyber investment, and rising SMB threats.
1

FBI Labels China-Linked Hack of Surveillance System a Major Cyber Incident

The FBI classified a breach of its DCS-3000 surveillance system as a major incident, with suspected Chinese hackers, possibly Salt Typhoon, accessing wiretap data.Source 2 The intrusion, discovered February 17, compromises pen register and trap-and-trace operations used for monitoring calls and internet activity.Source 2 FBI is investigating with CISA and NSA amid ongoing Chinese cyber threats to U.S. infrastructure.Source 2

2

SonicWall 2026 Cyber Protect Report Reveals Seven Deadly Sins for SMBs

SonicWall's annual report reframes research around SMB protection outcomes, identifying seven deadly sins in cybersecurity practices.Source 1 Released April 3, it highlights risks facing small and medium businesses in the evolving threat landscape.Source 1 The findings aim to guide better protection strategies for SMBs.Source 1

3

Microsoft Announces $10 Billion Investment in Japan for AI and Cybersecurity

Microsoft plans a $10 billion investment over four years in Japan to build AI infrastructure and bolster cybersecurity.Source 3 Partnerships with SoftBank and Sakura Internet will develop domestic AI services via Azure cloud.Source 3 The initiative includes training one million engineers by 2030 and aiding early cyberattack detection.Source 3

4

North Korean Hackers Drain $285 Million from Drift Protocol in 10 Seconds

North Korean actors exploited Drift, a DeFi platform, stealing $285 million by taking over an admin key and draining five vaults using nonce-based transactions.Source 6 The attack occurred rapidly, prompting service suspension.Source 4Source 6 Infrastructure was prepped in advance for the large-scale theft.Source 6

5

Critical strongSwan Vulnerability Allows VPN Crashes via Integer Underflow

CVE-2026-25075 in strongSwan's EAP-TTLS plugin (versions 4.5.0-6.0.4) enables attackers to crash VPNs through memory corruption.Source 4 The 15-year-old flaw poses risks to VPN services worldwide.Source 4 Organizations are urged to patch immediately.Source 4

6

Ransomware Group Claims Hack of Meriden, CT City Systems

The Inc ransomware group claims responsibility for attacking Meriden, CT, causing ongoing service disruptions since February 17.Source 4 City officials confirmed the breach, with data stolen.Source 4 Restoration efforts continue over a month later.Source 4

7

New RoadK1ll WebSocket Implant Enables Network Pivoting

RoadK1ll, a Node.js implant, uses custom WebSocket protocol to pivot in breached networks without inbound listeners.Source 4 It blends with normal traffic for stealthy operations.Source 4 Threat actors deploy it for persistent access.Source 4

8

AI-Powered Phishing Campaign Compromises 344 Organizations

An AI-driven phishing operation exploited Microsoft cloud accounts via OAuth tokens, hitting sectors like healthcare and government.Source 4 Hundreds of organizations affected across construction, law, and more.Source 4 The campaign demonstrates advanced social engineering.Source 4

9

Axonius Adapt 2026 Conference Addresses Cybersecurity Actionability Gap

Axonius Adapt 2026 on April 15 features keynotes from former NASA CIO Renee Wynn and CEO Joe Diamond on cyber resilience and asset intelligence.Source 5 Research shows 56% of teams struggle with prioritization amid data overload.Source 5 The event focuses on intelligence-driven security operations.Source 5

10

Iran Conflict Escalates Cyber Threats to U.S. Energy Infrastructure

Heightened Middle East tensions raise risks from Iranian cyber actors targeting U.S. energy sectors.Source 9 Iran has built capabilities and ties to hacker groups, with warnings of disruptive attacks.Source 9 Energy firms urged to enhance defenses.Source 9

11

Cisco Patches Critical Vulnerabilities Including RCE and Auth Bypass

Cisco addressed critical and high-severity bugs that could lead to remote code execution, info disclosure, and privilege escalation.Source 6 Patches are essential to prevent exploitation.Source 6 Affected products require immediate updates.Source 6

12

Palo Alto Networks Warns of Breaches in 39 Seconds

Attackers can breach defenses in 39 seconds, accelerated by AI, outpacing human responses.Source 8 Resilience requires AI-enhanced defenses.Source 8 Podcast discusses building rapid security postures.Source 8