Software supply chain hacks trigger wave of intrusions, data theft

2026-04-02T20:51:52Z8f15584790c2d1a9d9634a902b2486e05b1374190cf78c241a157f2325881889
5GTeamPCPapplecompatibility-breakcve-2026-3502cyber-espionagedarksworddata-breachdrone-detectionexchange-onlineextended-life-cyclehasbrohigh-volume-emailiosnorth-koreanpmopensshred-hatrekeyingrhelsoftware-supply-chain-attacksstolen-secretssupply-chaintrueconfzero-day

What happened

Multiple security developments: Google links recent supply‑chain compromises (Axios npm and packages tied to TeamPCP) and Trivy/KICS/LiteLLM/Telnyx incidents to widespread theft of secrets that could enable further supply‑chain attacks, SaaS compromises, ransomware, and crypto theft. OpenSSH 10.3 fixes five vulnerabilities and removes legacy rekeying compatibility; Apple has backported fixes for the DarkSword exploit to protect iOS 18 devices. A TrueConf zero‑day (CVE‑2026‑3502) was exploited to deliver malware into Southeast Asian government networks via the update mechanism. Additional items

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
8f15584790c2d1a9d9634a902b2486e05b1374190cf78c241a157f2325881889
Enrichment time
2026-04-02T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Software supply chain hacks trigger wave of intrusions, data theft · Baitaphish