Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise
2026-04-11T19:23:58Z•4c3cb4877a0527ac3f01a87f768c537bc0b21632e57d9d596625c36af4c4e37e
AI-generated vulnerabilitiesAdobe Acrobat ReaderAnthropicCUPSFancy BearFortiClient EMSFortinetProject GlasswingRCESBOMcredential theftdev account lockoutdevice-code phishingdownload hijackextortioninfrastructure disruptionmalwareopen sourcephishingransomwaresoftware supply-chainstate‑actorssupply chaintool poisoningzero-day
What happened
A batch of high-impact security incidents and trends reported by The Register: two March supply-chain/tool-poisoning attacks infected popular open-source utilities and were used to exfiltrate secrets at scale; a CPUID download-server hijack briefly delivered credential‑stealing malware; a critical FortiClient EMS vulnerability was confirmed exploited in the wild and added to CISA KEV; months‑old Adobe Acrobat/Reader zero‑day PDFs have been used for target profiling; AI tools (Anthropic/Mythos/Glasswing) are being used to find or weaponize vulnerabilities; dozens of high‑value corporations were
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 4c3cb4877a0527ac3f01a87f768c537bc0b21632e57d9d596625c36af4c4e37e
- Enrichment time
- 2026-04-11T19:23:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.