Hybrid work, expanded risk: what needs to change
2026-04-03T19:24:00Z•1a7474acfe9b233e1baef43842a8136f873c55fae15ccf288cd60b0f2122f63c
ai-supply-chainapi-keysaxioschatgptcitrix-netscalercredential-theftdata-leakdns-exfiltrationeuropean-commission-breachghostsockslitellmmanufacturing-cyberattacksmsinpmpassword-sprayingpypiratsocial-engineeringsupply-chaintelnyxtrivytrojanized-sourcevidarwhatsapp
What happened
A broad set of active infosec incidents and trends: high-impact supply-chain attacks continue to hit developer ecosystems (npm axios backdoor dropping a cross‑platform RAT; PyPI Telnyx packages and downstream LiteLLM/Trivy compromise), and attackers are trojanizing leaked source code (Claude Code downloads bundled with Vidar stealer and GhostSocks). Critical infrastructure bugs are being exploited in the wild (Citrix NetScaler), and a ChatGPT flaw that allowed DNS-based data exfiltration was patched. Other notable activity includes social‑engineering campaigns delivering malicious MSI viaWhats
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 1a7474acfe9b233e1baef43842a8136f873c55fae15ccf288cd60b0f2122f63c
- Enrichment time
- 2026-04-03T19:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.