Malicious Axios releases briefly appeared on npm after a maintainer was socially engineered, adding a backdoored dependency whose postinstall fetched payloads from attacker-controlled infrastructure. Cisco Talos details the delivery chain and infrastructure, underscoring how a single compromised maintainer account can cascade through CI/CD and developer environments. Teams should purge the affected versions, rotate tokens/keys, and audit build logs for suspicious postinstall activity.
Source: Cisco Talos
European Commission confirms data breach tied to TeamPCP supply-chain attack
The European Commission says attackers stole more than 300 GB of data from its AWS environment, with links to the Trivy supply-chain compromise attributed to TeamPCP. The incident highlights the systemic risk of third-party and open-source tooling across cloud workloads, with personal data included in the haul. EU entities should review Trivy exposure, rotate credentials, and tighten federation and least-privilege policies.
Source: SecurityWeek
Critical Cisco IMC auth bypass (CVE‑2026‑20093) allows unauthenticated admin access
Cisco patched 10 flaws in its Integrated Management Controller, including CVE‑2026‑20093, which could let a remote, unauthenticated attacker bypass authentication and change user passwords. Because IMC provides out‑of‑band control, exploitation could grant deep, OS‑independent access to servers. Prioritize patching, restrict IMC to dedicated management networks, and monitor for anomalous password changes.
Source: Help Net Security
CISA orders rapid patching of video‑conferencing zero‑day exploited by Chinese hackers
U.S. federal agencies have two weeks to remediate a video‑conferencing vulnerability actively exploited by China‑linked actors. The flaw has been used for reconnaissance, privilege escalation, and follow‑on payload delivery, raising risks of lateral movement via collaboration platforms. Agencies and enterprises should patch immediately, rotate credentials, and hunt for persistence around conferencing integrations.
Source: RecordedFuture
Attackers weaponize Claude Code leak to push malware to developers
After Anthropic inadvertently exposed Claude Code source files, threat actors seeded fake “unlocked” builds that delivered malware, luring developers via GitHub repositories. The incident shows how leaked code can become instant social‑engineering bait, especially for tools used in dev pipelines. Verify digital signatures, prefer official distribution channels, and test suspicious artifacts in isolated sandboxes.
Source: Help Net Security
React2Shell exploited at scale to harvest credentials from 750+ systems
Threat actors automated discovery and exploitation of the React2Shell flaw, using the Nexus Listener framework to compromise over 750 systems across providers. The campaign emphasizes how quickly internet‑facing bugs are operationalized for credential theft. Patch affected components, invalidate exposed secrets, and enforce MFA with conditional access to blunt post‑exploitation.
Source: SecurityWeek
Suspected Chinese breach of FBI system exposed wiretap targets’ phone numbers
An intrusion into an FBI system reportedly revealed the phone numbers of surveillance targets, potentially allowing foreign adversaries to infer U.S. investigations. The exposure poses operational and national‑security risks and highlights the sensitivity of metadata, not just content. Agencies should tighten segmentation around lawful‑intercept tooling, increase monitoring, and reassess partner access controls.
Source: NextGov Cyber
You May Also Be Interested In...
Trump wants to slash $707M from CISA’s budget
Windows adds Secure Boot certificate status indicators ahead of 2026 expiration
Ukraine warns Russian hackers are revisiting past breaches to prep new attacks