Axios npm Package Hijacked in North Korea-Linked Supply Chain Attack — RAT Deployed to Millions
Summary The widely used JavaScript HTTP client Axios — with over 100 million weekly npm downloads — was compromised in a supply chain attack on March 30-31, 2026. Threat actors…
Google Patches Fourth Chrome Zero-Day of 2026 — CVE-2026-5281 Actively Exploited in the Wild
Summary Google has released an emergency Chrome update to patch CVE-2026-5281, a high-severity use-after-free vulnerability in Dawn, the open-source WebGPU implementation used in Chromium. The flaw allows remote code execution…
ShinyHunters Strike Again: European Commission Confirms 350GB Data Theft from Europa.eu
Summary The European Commission has confirmed a major cyberattack on its Europa.eu web platform, with the notorious extortion group ShinyHunters claiming responsibility. Detected on March 24, 2026, the breach targeted…
SANS Report: The Real Cybersecurity Crisis Is a Skills Gap, Not a Talent Shortage — and AI Is Rewriting the Rules
Summary The 2026 SANS | GIAC Cybersecurity Workforce Research Report, unveiled at RSAC 2026 on March 31, challenges the prevailing narrative around the cybersecurity talent shortage. Based on a survey…
Anthropic’s Claude Code Source Code Leaked via Misconfigured npm Package
Summary The full TypeScript source code of Anthropic’s proprietary Claude Code CLI tool was inadvertently exposed on March 31, 2026, through a misconfigured npm package. Security researcher Chaofan Shou discovered…
DOJ Dismantles Aisuru and Three Other Massive IoT Botnets Behind Record 30 Tbps DDoS Attacks
Summary The U.S. Department of Justice, working with Canadian and German authorities, announced the successful dismantlement of four major IoT botnets: Aisuru, Kimwolf, JackSkid, and Mossad. The operation targeted command-and-control…
ShinyHunters Breach Hundreds of Companies via Misconfigured Salesforce Experience Cloud
Summary The cybercrime group ShinyHunters has claimed responsibility for a mass data theft campaign targeting Salesforce customers through misconfigured public-facing Experience Cloud sites. The group asserts it compromised approximately 100…
INTERPOL’s Operation Synergia III Dismantles 45,000 Malicious IPs Across 72 Countries, 94 Arrested
Summary INTERPOL has announced the results of Operation Synergia III, a massive global cybercrime crackdown that ran from July 2025 through January 2026 across 72 countries and territories. The operation…
Critical Fortinet FortiClient EMS Flaw CVE-2026-21643 Now Under Active Exploitation
A critical SQL injection vulnerability in Fortinet FortiClient Enterprise Management Server (EMS), tracked as CVE-2026-21643, has moved from theoretical threat to active exploitation. Threat intelligence firm Defused confirmed attackers began…
CareCloud Discloses Cybersecurity Incident Affecting Electronic Health Records
Healthcare IT platform CareCloud has disclosed a material cybersecurity incident that temporarily disrupted one of its electronic health record (EHR) environments. The incident occurred on March 16 and caused approximately…
