Ongoing supply-chain attack 'explicitly targeting' security, dev tools

2026-04-28T07:24:06Zb0ab05370ecc538901fc36a30816f50077e221d354badf4ba497a1442ae13273
AI-securityCISAChina-linked-actorsFAST16FirestarterIoT-compromiseLapsus$RDPShinyHuntersWindows-Updatebackdoorcode-scanningdata-breachextortionrepo-exposurerouter-exploitationsecurity-toolssocial-engineeringsupply-chain

What happened

A cluster of high-impact incidents and trends: an apparent supply‑chain campaign explicitly targeting security and developer tooling (Checkmarx repo exposure; Lapsus$ claims), multiple corporate breaches and data-leaks (Itron, Medtronic, ADT, Carnival, Biobank), and active extortion groups (ShinyHunters, Lapsus$). Government and vendor alarms include CISA/UK removal of the Firestarter backdoor from a federal network (Cisco-related compromise reported), a joint advisory on China-linked actors abusing compromised routers/IoT as proxy infrastructures, and research on FAST16 — a possible early-era

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
b0ab05370ecc538901fc36a30816f50077e221d354badf4ba497a1442ae13273
Enrichment time
2026-04-28T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.