Italian spyware vendor creates Fake WhatsApp app, targeting 200 users

2026-04-02T08:51:46Z7d5ea399187abd6d80c7bbb04c5ffcde1348027be574b4bacd1f9fe505a5d9db
anthropicaxioschromecisaclaude-codecve-2026-5281data-breachdawndutch-ministry-of-financefake-appfree-vpnknown-exploited-vulnerabilitiesliteLLMlloyds-banking-groupmobile-bankingnpmratsentinelonespywaresupply-chainunc1069use-after-freevpn-privacywebgpuwhatsapp

What happened

Multiple high-impact security incidents and vulnerabilities were reported: Google patched an actively exploited Chrome/WebGPU zero-day (CVE-2026-5281, use-after-free, CVSS 8.8) which CISA added to its Known Exploited Vulnerabilities catalog. Several supply-chain compromises were disclosed — the Axios npm account was hijacked to distribute RATs (linked by Google to North Korea–linked UNC1069), a trojaned LiteLLM package was blocked by SentinelOne’s autonomous detection, and Anthropic accidentally leaked Claude Code via npm. Additional incidents include an Italian firm’s fake WhatsApp spyware-lt

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
7d5ea399187abd6d80c7bbb04c5ffcde1348027be574b4bacd1f9fe505a5d9db
Enrichment time
2026-04-02T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.