Trump wants to take a battle axe to CISA again and slash $707M from budget
2026-04-04T07:24:01Z•9ef9c4c5d6be528f37c848580f1bf29c429733fc87c568f45957c06be76c33ed
AI-supply-chainAPI key leakageChatGPTCitrix NetScalerDNS exfiltrationGhostSocksLiteLLMM365PyPIRATTrivyVidarWhatsApp social engineeringcredential-theftdata breachmalwarenpmpassword sprayingpolicy_CISA_budgetsupply-chainvirtual smartphone fraud
What happened
A batch of late-March/early-April 2026 infosec stories highlighting a surge in high-impact supply-chain and credential-theft activity, prolific malware distribution, and multiple targeted intrusions. Notable items include major supply-chain compromises (npm/Axios backdoor delivering a RAT, PyPI/Telnyx and Trivy/LiteLLM downstream impacts), trojanized Claude source downloads bundling Vidar stealer and GhostSocks, in-the-wild exploitation of a critical Citrix NetScaler flaw, a ChatGPT DNS-based data exfiltration issue that was patched, WhatsApp-delivered MSI installers used for remote compromise
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 9ef9c4c5d6be528f37c848580f1bf29c429733fc87c568f45957c06be76c33ed
- Enrichment time
- 2026-04-04T07:24:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.