❌

Reading view

Axios npm Package Compromised in Supply Chain Attack

On March 31, 2026, two versions of the Axios library were compromised and found to contain a Remote Access Trojan. The malicious packages were published through a hijacked maintainer account. The Axios team is investigating how the breach occurred and has deprecated the affected versions. Security experts emphasize the need for better dependency management.

By Daniel Curtis
  •  

Convicted spyware chief hints that Greece’s government was behind dozens of phone hacks

The spyware founder's comments are the most direct suggestion yet from anyone inside Intellexa that the Mitsotakis government authorized the hacking of dozens of phones belonging to senior Greek government ministers, opposition leaders, military officials, and journalists.
  •  

DOGE employee stole Social Security data and put it on a thumb drive, report says

A whistleblower is accusing a former DOGE member of stealing a large number of Americans’ personal data while he was working at the Social Security Administration, with the plan of using it at his new job.
  •  

US military contractor likely built iPhone hacking tools used by Russian spies in Ukraine

Google found a series of hacking tools they said were used by a Russian espionage group and a cybercriminal group in China. Sources from a U.S. government defense contractor said some of those hacking tools were theirs.
  •  
❌