March 25th : Your Security Tools, Your Router, Your Tax Search
There’s a particular kind of dark irony in watching a security scanner become the weapon. That’s what happened with Trivy, and it sets the…
March 25th : Your Security Tools, Your Router, Your Tax Search

There’s a particular kind of dark irony in watching a security scanner become the weapon. That’s what happened with Trivy, and it sets the tone for everything else that landed on March 25.
It was a day where the tools people trusted, the policies people expected, and the seasons people live through all got weaponized at once. Supply chain compromises. A sweeping government ban on nearly every router you can buy. A court verdict that platforms have been dreading for years. And a tax-season malware campaign designed to blind your defenses before you ever know you’re infected. Plus Lapsus$, showing up in two separate headlines like the headline acts couldn’t get enough.
Not every news day has a connective thread. This one did.
The Security Scanner That Became the Weapon
The Trivy supply chain attack, first spotted around March 19, stopped being a contained incident sometime this week. By March 25, confirmed victim counts had passed 1,000 enterprise cloud and SaaS environments, with researchers from The Register projecting the real number could climb to 10,000 or more.
Trivy is an open-source vulnerability scanner from Aqua Security. It’s the kind of tool security teams run specifically because they don’t trust other software. That’s what makes this particular attack sting.
The initial vector was a compromised trivy-action GitHub Action, which is how Trivy plugs into CI/CD pipelines. From there, the attack spread to KICS and LiteLLM, an AI routing library. Specifically, LiteLLM versions 1.82.7 and 1.82.8 were backdoored with a payload that included a credential harvester, a persistent backdoor, and a Kubernetes lateral movement toolkit designed to jump from developer environments into production cloud clusters.
That last piece matters. This wasn’t just credential theft. The K8s component was built specifically to move up the stack, from the dev pipeline into live infrastructure. Palo Alto Networks called it “the most sophisticated supply chain attack on a security tool to date,” describing the combined package of tag poisoning, binary tampering, persistent backdoors, and a self-propagating worm. CrowdStrike traced the initial spread through Falcon platform telemetry. Microsoft published detection and response guidance.
And then Lapsus$ showed up.
The extortion group, which was reportedly disrupted after a wave of arrests in 2022 and 2023, is now reportedly collaborating with the original attackers to squeeze victims. Whether this is the original crew, successors using the brand, or something more complicated is genuinely unclear. What’s not unclear is that 1,000-plus organizations are now potentially looking at extortion contact, if they haven’t received it already.
If you run Trivy in CI/CD, or installed LiteLLM 1.82.7 or 1.82.8, treat this as a live incident. Rotate credentials. Check for signs of Kubernetes lateral movement. Microsoft and CrowdStrike have both published specific detection guidance.
Lapsus$ Had a Very Busy Tuesday
The Trivy story would’ve been enough. But separately, Lapsus$ is claiming to have breached AstraZeneca.
The claim, reported by CyberNews, SecurityWeek, and Hackread, alleges the group stole Java Spring Boot source code, Angular and Python packages, AWS and Azure cloud credentials, Terraform configuration files, and employee databases. The sample descriptions are specific enough to look credible. But AstraZeneca has not confirmed, denied, or commented, and no independent party has verified the data.
So: write this down as an unconfirmed claim with a credible-enough claimant. Lapsus$ has a track record. The specificity of the alleged data is notable. The silence from AstraZeneca, at least as of March 25, is also notable.
If the AWS and Azure credentials are real and haven’t been rotated, that’s potentially ongoing access. Which would be worth taking seriously regardless of how the confirmation question ultimately resolves.
What’s worth watching: Lapsus$ is claiming two of today’s three biggest security stories simultaneously. Either the group is experiencing a genuine resurgence, or someone is successfully borrowing a reliable brand name. The net effect for victims is the same.
Every Router in Your House Is Now a National Security Problem
The FCC updated its Covered List on March 25 to include all consumer-grade routers manufactured outside the United States. New models can no longer be imported or sold in the US market. Existing routers already authorized by the FCC are not affected. But if you were planning to buy a new one, your options are about to get much more complicated.
The scope is broader than most coverage initially suggested. This isn’t a TP-Link ban. TP-Link accounts for roughly 35% of the US consumer router market, and it’s certainly on the list. But so is Asus, which is Taiwanese. Netgear, which has US headquarters but manufactures abroad. Eero, which is owned by Amazon. Ubiquiti. CNET put it plainly: with the exception of newer Starlink routers, nearly every router you can currently buy in this country is at least partially made outside the US.
No manufacturer has received exemption approval. An exemption process exists, but the criteria aren’t exactly transparent, and no one has cleared it yet.
This has been building for a while. Volt Typhoon and Flax Typhoon, Chinese state-linked groups, used SOHO routers as pivot points in their network campaigns. The TP-Link investigation accelerated congressional pressure. This FCC action is the structural response to that pressure: stop the supply at the source rather than investigate individual devices.
What it doesn’t answer is what comes next. Domestic router manufacturing doesn’t exist at consumer scale in the US. Building it takes years. The exemption path is opaque. And new models are banned effective now, not after some transition runway.
For people who already have a router, nothing changes today. But when it’s time to replace it, the market they’re shopping in is going to look very different.
Your Antivirus Gets Killed Before the Malware Starts
Tax season creates urgency. Urgency makes people click without thinking. Someone is exploiting that very deliberately.
Researchers at Huntress have been tracking a malvertising campaign that’s been running since January. Attackers buy Google Ads targeting US users searching for tax forms, W-2s, W-9s, the standard season stuff. The ads serve up what looks like a ScreenConnect installer (ConnectWise’s remote support tool). It’s fake.
What makes this campaign technically different from the average tax-season phishing run is what happens after the download. Before the actual payload runs, HwAudKiller executes a Bring Your Own Vulnerable Driver attack using a legitimate but vulnerable signed Huawei audio driver. It loads that driver into kernel mode, uses it to kill endpoint detection and response software, and blinds antivirus before the primary compromise begins.
BYOVD attacks work because Windows will load a signed driver without complaint, even if that driver has known vulnerabilities. The attack happens in kernel space. Your standard security tools often can’t see what’s happening until it’s done.
The April 15 tax deadline is relevant context here. The campaign has been running for months, but the urgency window is getting tighter, which means click rates are probably going up.
The mitigation is tedious but simple: don’t download software from Google Ads. Go directly to vendor sites. ConnectWise has a website. ScreenConnect installers should only ever come from there.
Stryker Finally Says “Malware”
Two weeks after Iranian hackers from the Handala group allegedly wiped more than 200,000 Stryker devices, the medical device company has officially confirmed that malware was involved.
The confirmation came through a customer letter and was reported by The Record. Stryker says production lines are coming back online. Patient-connected products and services were not affected, which has been consistent across the company’s messaging since the incident began.
What’s new: the malware question, which had been somewhat ambiguous, is now resolved from Stryker’s side. The company acknowledges malware as the attack mechanism. The FBI had previously seized Handala’s web infrastructure, describing the group as a psychological operation of Iran’s Ministry of Intelligence and Security.
This is a recovery update rather than a new development. But for anyone tracking the story, the operational picture is improving.
$375 Million. First Jury Verdict.
A New Mexico jury ordered Meta to pay $375 million in damages after a six-week trial brought by Attorney General Raúl Torrez. The verdict, confirmed by Reuters, CNBC, The Guardian, and NPR, is the first time a US state has successfully taken Meta to trial over harm to children on its platforms.
The key distinction: this is not a settlement. It’s a jury verdict, on both liability and damages, following contested trial proceedings. The jury found Meta knowingly harmed children’s mental health and concealed what it knew about child sexual exploitation occurring on its platforms.
Torrez called it “a historic victory for every child and family who has paid the price for Meta’s choice to put profits over kids’ safety.”
Meta is expected to appeal. The $375 million is not existential for a company of Meta’s size. But the precedent is.
Federal child safety legislation, including KOSA and COPPA reform, has stalled in Congress repeatedly. New Mexico used state consumer protection law instead and won. That template is now sitting on the desk of every other state attorney general in the country. TechCrunch noted the rest of the country is watching.
OpenAI Killed Sora
Not a security story, but relevant to the larger picture of how the AI industry is maturing, or not.
OpenAI announced it’s shutting down Sora, its video generation platform, roughly 15 months after launch. The stated reason is narrowing focus and reallocating human and compute resources. The timing is jarring because OpenAI signed a three-year deal with Disney just three months ago, covering licensed characters from Marvel, Pixar, and Star Wars. That deal is now cancelled.
What it signals: AI companies are still figuring out what they’re actually building, and billion-dollar partnerships can evaporate when internal resource priorities shift. It’s worth watching where those compute resources are going instead.
What to Take Away
The through-line today is trust infrastructure. The tools you use to verify your software. The hardware you use to connect to the internet. The platforms you use to file your taxes or let your kids browse. All of it was stressed or questioned or actively exploited on March 25.
Lapsus$ appearing in two separate stories in a single news cycle, after years of relative quiet, is worth watching. Whether that’s resurgence, rebranding, or imitation, it’s a signal that the extortion market around supply chain attacks is heating up.
If there’s one concrete thing worth doing this week: if you run Trivy in CI/CD, or installed LiteLLM 1.82.7 or 1.82.8, start there. The Kubernetes lateral movement angle makes this more than a credential rotation exercise.
And if you’re doing your taxes and see a Google Ad for a form download, close it.
메타데이터
- post_id
- 8052fae7a07f
- slug
- march-25th-your-security-tools-your-router-your-tax-search-8052fae7a07f
- url
- https://medium.com/@gNerd/march-25th-your-security-tools-your-router-your-tax-search-8052fae7a07f
- canonical_url
- https://medium.com/@gNerd/march-25th-your-security-tools-your-router-your-tax-search-8052fae7a07f
- author_url
- https://medium.com/@gNerd
- status
- ok
- fetched_at
- 2026-06-09 15:37:30