❌

Normal view

Europe’s cyber agency blames hacking gangs for massive data breach and leak

3 April 2026 at 23:50
CERT-EU blamed the cybercrime group TeamPCP for the recent hack on the European Commission, and said the notorious ShinyHunters gang was responsible for leaking the stolen data online.

Open Source Security Tool Trivy Hit by Supply Chain Attack, Prompting Urgent Industry Response

3 April 2026 at 20:00

A major security incident affecting the widely used open source vulnerability scanner Trivy has exposed critical weaknesses in software supply chain security, after maintainers confirmed that a malicious release was briefly distributed to users.

By Craig Risi
  • βœ‡InfoQ
  • Axios npm Package Compromised in Supply Chain Attack Daniel Curtis
    On March 31, 2026, two versions of the Axios library were compromised and found to contain a Remote Access Trojan. The malicious packages were published through a hijacked maintainer account. The Axios team is investigating how the breach occurred and has deprecated the affected versions. Security experts emphasize the need for better dependency management. By Daniel Curtis
     

Axios npm Package Compromised in Supply Chain Attack

2 April 2026 at 21:53

On March 31, 2026, two versions of the Axios library were compromised and found to contain a Remote Access Trojan. The malicious packages were published through a hijacked maintainer account. The Axios team is investigating how the breach occurred and has deprecated the affected versions. Security experts emphasize the need for better dependency management.

By Daniel Curtis
❌