This week

- Anthropic accidentally leaks Claude Code app source code
- North Korea behind compromise of popular Axios JS library
- Iran is password spraying ME governments and municipalities
- Cisco lost source code in Trivy supply chain breach
- Rowhammer attacks on Nvidia GPUs can lead to system compromise
Interesting stats
78% of British manufacturing businesses say they have suffered a cyber incident in the past year, with 3/4 of those experiencing between 1 and 7 days of downtime as a result, 1/2 of affected organisations report costs exceeding £250,000, while 1/5 the costs exceed £1,000,000, according to ESET
40% efficiency savings at Amazon from using AI tools to pen test its products — saving on both human/salary costs and operating expenses from third parties. (CISO CJ Moses says staff aren’t being laid off, but holding hiring flat and increasing coverage).
Five things
-
Anthropic leak: Not an April Fool’s. Anthropic accidentally published a ‘source map’ file this week that allowed access to the complete source code of its Claude Code command line application. The backend code and models were not affected. Anthropic were quick to point out that no sensitive customer information was compromised and has begun issuing copyright takedown requests to those hosting the 512,00 lines of source code. Still, it’s a big deal. Anthropic says the cause was human error — and accidents happen — though I’m not sure I buy the claim that this is “not a security breach.” Especially as it includes a bunch of unannounced and unreleased features. There’s little impact on companies outside of Anthropic, and it’ll be interesting to see if, or what, financial impact this ‘intellectual property theft’ incident has on the firm.
-
Axios: On Monday, a malicious version of the Axios JavaScript library was published, potentially putting millions of developers and their software projects at risk of compromise. Developers download Axios around 100 million times a week: even an hour’s compromise could impact ~500,000 downloads. The post mortem goes into detail of how the compromise occurred: socially engineering the lead maintainer into joining a Slack workspace mimicking a real company, and then subsequently inviting them to an MS Teams meeting to discuss collaboration: when they joined a convincing ‘update message’ was displayed prompting them to update Teams with what’s thought to be a remote access trojan. Props for the transparency. This technical writeup explains how the malware steals secrets and credentials used during build processes. Google security researchers say the incident is the work of a North Korean threat actor, ‘UNC1069’. North Korea typically conducts software supply chain attacks to obtain cryptocurrency to fund its regime; it’s unclear whether this is the motive in this case. This breach will have a long tail, given the widespread use of Axios. If you or your developers use it, check to see if you’ve been compromised and rotate everything involved if you have.
-
Iran: Researchers say they have seen Iran-linked threat actors conducting password-spraying attacks against ‘hundreds’ of Middle East government and municipal organisations. The attacks, similar to those attributed to the IRGC’s Peach Sandstorm and Grey Sandstorm groups, generally focus on gaining access to Microsoft 365 environments to steal sensitive information. Check Point says that there appears to be some overlap between city administrations and those targeted by Iran with missile attacks, potentially seeking to ascertain the damage and support of kinetic warfare. Meanwhile, Jacob Judah’s article for the FT has a pretty balanced view of Tehran’s cyber operations, their objectives, and constraints. It’s also syndicated on ArsTechnica if you hit a paywall.
-
Cisco believes that threat actors have some of its stolen source code after losing development and build environment credentials and AWS keys in the Trivy supply chain attack. Cisco hasn’t had the most stellar track record of finding and fixing vulnerabilities in its (particularly legacy) products, and so losing source code like this may make it easier for attackers to find vulnerabilities in Cisco products that they can use to compromise customers’ environments.
-
GDDRHammer: Researchers have proven that rowhammer style attacks can be used against Nvidia GPUs to gain root control over the underlying system. Researcher Andrew Kwong told ArsTechnica “an attacker can induce bit flips on the GPU to gain arbitrary read/write access to all of the CPU’s memory, resulting in complete compromise of the machine.” This is a huge deal for providers and consumers of cloud compute, where expensive Nvidia GPUs can be shared among customers for AI workloads.
In brief
-
⚠️ Incidents: Toymaker Hasbro has taken some systems offline as it notifies the SEC that it has detected unauthorised access to its network. Hasbro has implemented “business continuity plans to enable it to continue to take orders, ship product and conduct other key operations,” though expects “these interim measures may continue for several weeks before the situation is fully resolved”. It’s been a while since we’ve had a public S3 bucket, but Canadian fintech Duc left 360,000 files from know-your-customer checks, including government IDs and driver’s licenses, publicly accessible to anyone with a web browser. Cryptocurrency platform Drift has confirmed the theft of $280 million, saying the attack appears to have “involved multi-week preparation and staged execution”. That level of prep should be expected when you’re holding hundreds of millions in assets: a few weeks isn’t long to plan a heist like that for such a large payday. The finger, as with most similar cryptocurrency thefts, is being pointed at North Korea. Healthcare system provider CareCloud says that attackers accessed patient records during a recent cyber security incident; while the full extent of the breach is not known, it relates to one of six environments that host patient data for over 45,000 healthcare providers. Sticking with healthcare… Hims & Hers, which offers weight-loss and sexual health prescriptions, says attackers broke into a third-party customer support platform for three days in February. Styker, the US medtech company hit by an Iranian-linked threat group, says it’s returned to full operations, three weeks after multiple systems were hit with wiper malware. Jaguar Land Rover says production has returned to “normal levels” following the high-profile incident last year.
-
🕵️ Threat Intel: Cybercriminals are proposing a new service to process messy, stolen data into a structured format that’s searchable and may allow compatriots to exert more pressure on their victims to pay ransom demands. Ukraine’s national CERT says Russian threat actors are revisiting previous compromises to check whether systems have been patched and credentials rotated.
-
🪲 Vulnerabilities: NCSC is encouraging organisations to patch F5 BIG-IP Access Policy Manager to prevent an unauthenticated remote code execution vulnerability (CVE-2025-53521; 9.9/10; advisory). Cisco’s patched a critical vulnerability in its Integrated Management Controller (IMC) that allows attacker to bypass authentication and gain root on the out-of-band management module (CVE-2026-20093; 9.8/10; advisory). Progress ShareFile has been patched to fix two vulnerabilities which allow unauthenticated file exfiltration (CVE-2026-2699 & CVE-2026-2701; 9.8 & 9.1 /10; writeup). OpenClaw devs have fixed a critical privilege escalation issue (CVE-2026-33579; 9.4/10; advisory).
-
🧑💻 End user and consumer: Apple has introduced ClickFix warnings to MacOS: when a user copies commands from Safari to paste into Terminal, the process is halted and a warning message is displayed to the user. ClickFix attacks, in which threat actors try to socially engineer victims into running a malicious command on their devices, have become increasingly popular.
-
🛠️ Security engineering: OpenAI has fixed a side-channel data exfiltration vulnerability after CheckPoint found that, while ChatGPT is blocked from making outbound web requests, the LLM could make DNS lookups that could contain information from the user’s prompts. Google Drive will now pause syncing and notify users and admins of paid accounts if it detects a ransomware attack.
-
🏭 Operational technology: A North Dakota water treatment plant suffered a ransomware attack in March, supplies to the city of Minot’s 50,000 residents were unaffected.
-
🧿 Privacy: The Italian Data Protection Authority has fined Sanpalolo, one of Italy’s largest banks, €31.8 million ($36M) for “serious shortcomings in personal data security, due to the inadequacy of the technical and organizational measures adopted.” The regulatory investigation began after the bank reported that its internal controls had failed to detect an employee accessing the information of 3,573 customers over a two-year period from February 2022 to April 2024. OkCupid has settled an FTC investigation for sharing 3 million photos and user metadata with an AI company building facial recognition software. The dating site, owned by giant Match, breached its own privacy policy by not notifying or allowing users to opt-out of the data sharing, however under the deal with the FTC, will not have to pay any penalty or admit wrong-doing. OkPenalty? Perhaps not! The acting head of Immigration and Customs Enforcement (ICE) says the agency has purchased spyware from Israeli firm Paragon Solutions to counter “foreign terrorist organizations’ thriving exploitation of encrypted communication platforms”.
-
📜 Policy & Regulation: Trump’s proposed fiscal 2027 budget may slash the US’ Cybersecurity and Infrastructure Security Agency’s budget by $707 million.
-
👮 Law Enforcement: Cambodia has extradited Li Xiong to China in a reported crackdown on scam centres. Xiong headed up the Huione Group, a conglomerate described as “Amazon for criminals,” while China asserts that it is linked to Chen Zhi, the former head of Prince Group, and says Xiong is a “a key member of the Chen Zhi criminal syndicate.”
-
🗞️ Industry news: Dunkin’ on Delve: LiteLLM, who fell victim to a credential-stealing malware attack last week, has publicly ditched embattled compliance platform Delve.
And finally
- Astronauts aboard the Artemis II mission to the moon have complained that they have two copies of Microsoft Outlook, and neither was working. I’m just surprised they’re not using Thunderbird 3. I’ll get my coat. And h/t Paul for this gem:

- Also, don’t use ‘encrypted’ chat app TeleGuard, whose encryption is about as useful as, well, a chocolate fireguard. It’s comically bad from an implementation and architecture perspective.
