Crushing the Axios supply chain threat with Tenable Hexa AI: Use cases for agentic AI
2026-04-10T20:52:33Z•8f3d2d0d4f785ee389968d9a584e34f359b9abf594372675fc3942de87edfc56
IRGCUNC1069WAVESHAPER.V2agentic-aiaxioscisa-aa26-097acredential-theftcve-2021-22681cve-2026-35616cyberav3ngersdeveloper-credential-economyforticlientemsfortineticsincident-responsekeVnpmplain-crypto-jsplcpublic-exploitremediationsupply-chainsupply-chain-compromisetenable-hexa-aizero-day
What happened
Tenable published multiple security advisories and analyses: a confirmed Axios npm supply‑chain compromise attributed to UNC1069 that published malicious Axios versions 1.14.1 and 0.30.4 (injecting a dependency 'plain-crypto-js' to deliver the WAVESHAPER.V2 RAT) — Tenable urges immediate incident response (quarantine, rotate secrets, rebuild) and provides remediation/detection guidance. Fortinet FortiClientEMS suffers a critical improper access control zero‑day (CVE-2026-35616, CVSS 9.1) exploited in the wild with public exploit code; Fortinet has released hotfixes and CISA added the CVE to KE
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- 8f3d2d0d4f785ee389968d9a584e34f359b9abf594372675fc3942de87edfc56
- Enrichment time
- 2026-04-10T20:52:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.