Start Learning →
Back to Blogs

Cyber Pulse Monthly - March Edition

Tech Skill School
Tech Skill School
Cyber Pulse Monthly - March Edition

Cyber Warfare Escalates: Iran-Linked Attacks Blend Digital and Physical Conflict

Iran-linked cyber operations surged in March 2026, with thousands of attacks targeting critical infrastructure, healthcare, and civilians. Campaigns combined spyware, disruption tactics, and misinformation, highlighting how modern warfare increasingly integrates cyber capabilities alongside traditional military strategies.


Malicious LNK Files Deliver Russian CTRL Toolkit, Hijacking RDP Access

A new campaign distributes the Russian-linked CTRL toolkit via malicious LNK files, enabling attackers to hijack Remote Desktop Protocol sessions using FRP tunnels. The technique allows stealthy persistence and remote access, bypassing traditional detection and security controls.


Iran-Linked Hackers Breach FBI Director's Email, Disrupt Stryker in Cyber Offensive

Iran-linked hackers breached the FBI director's personal email, exposing sensitive communications, while also launching a disruptive wiper attack on Stryker's systems. The coordinated incidents demonstrate a shift toward aggressive, multi-target operations affecting both individuals and critical healthcare infrastructure.


Apple Warns Users: Outdated iPhones Targeted by Active Web Exploits

Apple issued lock screen alerts to users of older iPhones after detecting active web-based exploitation campaigns. The attacks target unpatched vulnerabilities in outdated devices, reinforcing the risks of delayed updates and increasing exposure to mobile-focused threat actors.


FortiGate Vulnerabilities Exploited in Large-Scale Enterprise Breaches

Threat actors actively exploited FortiGate firewall vulnerabilities to gain initial access into enterprise networks. Attackers leveraged compromised devices to harvest credentials and move laterally, emphasizing the ongoing risks of perimeter security misconfigurations and delayed patching.


A sophisticated supply chain attack compromised widely used JavaScript packages, injecting malicious code into software dependencies. The campaign affected thousands of applications globally, demonstrating how attackers exploit trusted ecosystems to achieve large-scale distribution and persistence.


Ransomware Groups Shift to Data Extortion Without Encryption

Cybercriminal groups increasingly adopt data exfiltration-only attacks, skipping encryption and focusing on extortion. This approach reduces detection risk while maximizing pressure on victims, signaling an evolution in ransomware tactics toward faster and more covert operations.


Hacktivist DDoS Campaign Hits Over 100 Organizations Globally

A coordinated wave of hacktivist-driven DDoS attacks targeted more than 100 organizations across multiple countries. The campaign disrupted government and private services, reflecting rising geopolitical tensions and the growing role of cyber activism in conflicts.


New Android Banking Trojan Targets Financial Apps Worldwide

A newly discovered Android banking trojan is targeting users of major financial applications by stealing credentials and bypassing multi-factor authentication. The malware spreads through phishing and malicious apps, highlighting persistent threats in the mobile ecosystem.


Zero-Day Exploit for Windows RDP Circulates in Underground Forums

A high-value zero-day exploit affecting Windows Remote Desktop Protocol is being traded on cybercrime forums. The vulnerability enables privilege escalation and remote access, raising concerns about potential widespread exploitation before official patches are released.


Cloud Misconfigurations Lead to Massive Data Exposure Incident

A major data exposure incident was traced back to misconfigured cloud storage, leaving sensitive information publicly accessible. The breach underscores ongoing challenges in cloud security management and the importance of proper access controls and monitoring.


AI-Powered Phishing Attacks Increase in Sophistication

Threat actors are leveraging artificial intelligence to craft highly convincing phishing emails and messages. These campaigns improve targeting accuracy and bypass traditional filters, making social engineering attacks more effective and difficult to detect.


Healthcare Sector Faces Surge in Targeted Cyber Attacks

Hospitals and healthcare providers experienced a rise in targeted cyberattacks, including ransomware and data breaches. Attackers exploit critical service dependencies, increasing operational disruption risks and putting sensitive patient data at significant risk.


Stealer Malware Campaign Harvests Credentials at Scale

A large-scale infostealer campaign is collecting login credentials, browser data, and session tokens from infected systems. The stolen data is sold on underground markets, fueling further attacks such as account takeovers and corporate breaches.


IoT Devices Targeted in Botnet Expansion Campaign

Cybercriminals are exploiting vulnerable IoT devices to expand botnets used for DDoS attacks and crypto-mining. Weak security configurations and outdated firmware make these devices easy targets, contributing to the rapid growth of distributed attack infrastructure.

Tags & Keywords
TechSkillSchool Ecosystem

Ready to apply these skills hands-on?

Join our structured courses, launch cloud cyber labs, or enroll in real-world internships.

Recommended Next Reads

View all 25 articles →
Back to all articles Start Learning with TSS →