A widely used JavaScript HTTP client, Axios, was hit by a supply chain compromise after an attacker used a maintainer’s stolen npm credentials to publish trojanized versions (1.14.1 and 0.30.4). The releases pulled in a fake dependency (“plain-crypto-js” 4.2.1) to deliver a cross‑platform RAT, putting countless build systems and developer machines at risk. Teams should yank the affected versions, audit build logs for suspicious network activity, rotate tokens, and re-issue clean installs. Package manager trust is under active attack—pin known‑good versions and verify checksums in CI.
Source: The Hacker News
TeamPCP supply chain spree pauses—but pivots to ransomware; Databricks probing alleged compromise
SANS reports that TeamPCP’s rapid series of software supply chain intrusions has slowed, while the threat actors shift to dual ransomware operations for monetization. The update notes Databricks is investigating an alleged compromise, and follows recent incidents poisoning open‑source projects (including Telnyx SDK on PyPI). Even as new compromises pause, defenders should expect follow‑on abuse of stolen secrets and downstream ransomware impacts. Lock down developer credentials, scrub CI artifacts, and monitor for anomalous package pulls.
Source: SANS Internet Storm Center
F5 BIG‑IP APM flaw reclassified to critical RCE and exploited in the wild
A vulnerability initially labeled a DoS in F5 BIG‑IP Access Policy Manager has been upgraded to a critical remote code execution issue—and attackers are already exploiting it. Given APM’s role at the edge, organizations should patch immediately, follow F5’s mitigations where upgrades aren’t possible, and assume potential compromise on exposed appliances. The flaw is now on government KEV radars, raising urgency for rapid remediation and incident review.
Source: SecurityWeek
Citrix NetScaler critical bug under exploitation to steal admin session IDs
Active exploitation has begun for a critical NetScaler vulnerability that leaks application memory, enabling theft of authenticated administrative session tokens. Attacks appeared within days of disclosure, underscoring the speed of exploitation for edge devices. Patch quickly, invalidate all active sessions, and hunt for suspicious configuration changes or new admin accounts.
Source: SecurityWeek
Fortinet FortiClient EMS critical SQLi (CVE‑2026‑21643) actively exploited for RCE
A critical SQL injection flaw in Fortinet FortiClient Endpoint Management Server is being exploited to achieve remote code execution, according to honeypot telemetry. Although not yet listed in some KEV catalogs, exploitation attempts have been observed in the wild. Fortinet customers should upgrade immediately, restrict EMS exposure, review logs for suspicious queries or process spawns, and rotate credentials managed by the platform.
Source: Help Net Security
European Commission confirms data theft from Europa.eu hosting; resilience questions mount
The European Commission disclosed a cyber intrusion impacting cloud infrastructure hosting its Europa.eu web presence, with evidence of data exfiltration but no signs of internal system compromise. This marks the second Commission‑linked breach this year as ShinyHunters claims large‑scale theft, though the institution has downplayed impact. Agencies and suppliers should review any integrations with EC web services and prepare for potential data exposure fallout.
Source: SecurityWeek
ChatGPT data exfiltration via DNS side‑channel patched; enterprises reminded AI isn’t “secure by default”
Researchers uncovered a ChatGPT flaw that allowed silent leakage of conversation content and uploaded files via DNS, bypassing outbound web controls; OpenAI has since patched the issue. The incident highlights how AI assistants can become covert egress channels and why DLP/egress policies must cover DNS, not just HTTP(S). Security leaders should revisit AI usage policies, apply least‑privilege data access, and enforce egress monitoring across all protocols.
Source: Check Point Blog
You May Also Be Interested In...