AI-Assisted Supply Chain Attack Targets GitHub
2026-04-07T02:51:46Z•d1c7e3f831524a11661da05203906129479a1991dbf63bbc412498f15a3f7e4e
CVE-2025-53521CVE-2026-35616ai-assisted-attacksai-malwareaxioscloud-compromisecredential-harvestingdarksworddeeploadf5-big-ipfortinetgithub-misconfigurationios-patchmaasnextjsnpmover-privilegercereact2shellsource-code-leaksupply-chainteampcpvenom-stealervertex-aizero-day
What happened
Multiple DarkReading reports highlight an urgent surge in supply-chain and AI-enabled attacks across open source ecosystems, cloud services, and endpoint software. Notable incidents include an AI-assisted GitHub targeting campaign (PRT-scan), a precision compromise of the Axios NPM package, an emergency FortiClient authentication-bypass zero-day (CVE-2026-35616) being patched and exploited in the wild, automated credential-harvesting campaigns exploiting React2Shell on Next.js apps, and the reclassification/active exploitation of F5 BIG-IP (CVE-2025-53521) as an RCE. Coverage also flags AI‑dr‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- d1c7e3f831524a11661da05203906129479a1991dbf63bbc412498f15a3f7e4e
- Enrichment time
- 2026-04-07T02:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.