US foreign router ban criticized for being ‘industrial policy disguised as cybersecurity’
2026-03-30T07:23:58Z•fc94e2ac761c1bb8a72e65bd53a19f876ea89de2818adba99fb6f7909adb7d25
AFC-AjaxFCCai-supply-chainapi-keys-exposedcloud-infectioncontext-hubcredential-stealing-malwarecredential-theftdata-breachdeepfakeextortion-groupsliteLLMmicrosoftnational-securityout-of-band-updatepatchingpypiransomwarerouter-bansignal-phishingsupply-chaintrivyunderwater-dronesvoice-phishing
What happened
A series of high-impact infosec stories dominated the feed: a Trivy supply-chain compromise has led to credential-stealing malware infecting 1,000+ cloud environments and collaborators with extortion groups, and the Python package LiteLLM was removed from PyPI after CI/CD pollution. Researchers also found nearly 2,000 exposed API credentials across public websites, while a proof-of-concept ‘documentation poisoning’ AI supply-chain attack (Context Hub) highlights non-malware avenues for compromising agentic systems. Additional notable incidents include an AFC Ajax data breach that allowed admin
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- fc94e2ac761c1bb8a72e65bd53a19f876ea89de2818adba99fb6f7909adb7d25
- Enrichment time
- 2026-03-30T07:23:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.