Ongoing supply-chain attack 'explicitly targeting' security, dev tools
2026-04-28T07:24:06Z•b0ab05370ecc538901fc36a30816f50077e221d354badf4ba497a1442ae13273
AI-securityCISAChina-linked-actorsFAST16FirestarterIoT-compromiseLapsus$RDPShinyHuntersWindows-Updatebackdoorcode-scanningdata-breachextortionrepo-exposurerouter-exploitationsecurity-toolssocial-engineeringsupply-chain
What happened
A cluster of high-impact incidents and trends: an apparent supply‑chain campaign explicitly targeting security and developer tooling (Checkmarx repo exposure; Lapsus$ claims), multiple corporate breaches and data-leaks (Itron, Medtronic, ADT, Carnival, Biobank), and active extortion groups (ShinyHunters, Lapsus$). Government and vendor alarms include CISA/UK removal of the Firestarter backdoor from a federal network (Cisco-related compromise reported), a joint advisory on China-linked actors abusing compromised routers/IoT as proxy infrastructures, and research on FAST16 — a possible early-era
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- b0ab05370ecc538901fc36a30816f50077e221d354badf4ba497a1442ae13273
- Enrichment time
- 2026-04-28T07:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.