Microsoft says two malicious Axios npm releases (1.14.1 and 0.30.4) published on March 31 were used to pull a backdoor via a hidden post-install dependency, with attribution to North Korean actor Sapphire Sleet. Given Axios’ ubiquity, exposure ranges from hundreds of thousands to potentially millions of downstream installs. Defenders should pin to safe versions, audit lockfiles and CI logs for suspicious post-install execution, rotate exposed tokens, and scan developer endpoints for persistence. Microsoft has published IOCs, detection guidance, and remediation steps.
Source: Microsoft Security Blog
Chrome zero-day (CVE-2026-5281) exploited in the wild; patch now across Chromium browsers
Google patched 21 Chrome vulnerabilities, including CVE-2026-5281, a use-after-free in the Dawn WebGPU component with a confirmed in-the-wild exploit. CISA added the flaw to its KEV catalog, signaling active attacker interest and urgency for government and enterprise fleets. Update Chrome and all Chromium-based browsers immediately, and consider enterprise policies to accelerate critical browser rollouts.
Source: Help Net Security
TrueConf zero-day used for cyber-espionage against Southeast Asian governments
Check Point researchers uncovered suspected China-nexus operators exploiting CVE-2026-3502, a zero-day in TrueConf’s client updater, to push malware inside government LANs. Because TrueConf is often deployed on isolated networks, abusing its trusted update path provided covert reach for command-and-control. Organizations running on-prem video platforms should restrict update flows, validate code-signing, and monitor update traffic for anomalies.
Source: Help Net Security
Cisco Talos exposes massive automated credential-harvesting operation
Cisco Talos detailed UAT-10608, a large-scale automated credential harvesting campaign abusing a framework dubbed “NEXUS Listener” to target web applications. The cluster automates login attempts, session hijacking, and identity abuse at scale, blending with normal traffic patterns. Defenders should tighten bot management, enforce MFA and step-up verification, and monitor for impossible travel and high-velocity authentication anomalies.
Source: Cisco Talos
FBI labels suspected Chinese hack of US surveillance system a “major cyber incident”
The FBI designated a suspected PRC-linked intrusion into a US surveillance system as a major cyber incident, indicating potential compromise of sensitive data housed on FBI systems. The escalation underscores growing geopolitical cyber risk and the need for heightened monitoring and segmentation around high-value law enforcement and critical infrastructure platforms.
Source: Politico
LiteLLM supply-chain attack ripples: AI recruiter Mercor confirms breach
Mercor confirmed it’s among the downstream victims of the LiteLLM supply-chain compromise, as threat actors claimed terabytes of stolen source and data. The incident highlights the cascading blast radius when widely embedded developer/AI middleware is tampered with. Teams should inventory where LiteLLM or similar brokers are used, rotate secrets, and implement provenance checks and runtime egress monitoring for AI agent frameworks.
Source: SecurityWeek
“Claude Mythos” leak is a wake-up call: AI is accelerating vuln discovery and exploit dev
Check Point warns that leaked details about Anthropic’s advanced “Claude Mythos/Capybara” capabilities signal a new threshold: frontier models can materially accelerate vulnerability discovery, exploit creation, and multi-step attack planning once reserved for state actors. Security leaders should assume faster attacker OODA loops and invest in secure-by-default architectures, continuous code scanning, and guardrails for AI-assisted development and agent permissions.
Source: Check Point Blog
You May Also Be Interested In...
Apple expands iOS 18.7.7 to more devices to block DarkSword exploitSecuring the open source supply chain across GitHub
Progress ShareFile pre-auth RCE chain (CVE-2026-2699 & CVE-2026-2701)