Robin’s Newsletter #407

5 April 2026. Volume 9, Issue 14
Anthropic's source code leak. North Korea compromises popular JS library. What does Rowhammer mean for Nvidia GPUs in AI workloads?
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 5th April 2026

  • Anthropic accidentally leaks Claude Code app source code
  • North Korea behind compromise of popular Axios JS library
  • Iran is password spraying ME governments and municipalities
  • Cisco lost source code in Trivy supply chain breach
  • Rowhammer attacks on Nvidia GPUs can lead to system compromise

Interesting stats

78% of British manufacturing businesses say they have suffered a cyber incident in the past year, with  3/4 of those experiencing between 1 and 7 days of downtime as a result,  1/2 of affected organisations report costs exceeding £250,000, while  1/5 the costs exceed £1,000,000, according to ESET

40% efficiency savings at Amazon from using AI tools to pen test its products — saving on both human/salary costs and operating expenses from third parties. (CISO CJ Moses says staff aren’t being laid off, but holding hiring flat and increasing coverage).

Five things

  1. Anthropic leak: Not an April Fool’s. Anthropic accidentally published a ‘source map’ file this week that allowed access to the complete source code of its Claude Code command line application. The backend code and models were not affected. Anthropic were quick to point out that no sensitive customer information was compromised and has begun issuing copyright takedown requests to those hosting the 512,00 lines of source code. Still, it’s a big deal. Anthropic says the cause was human error — and accidents happen — though I’m not sure I buy the claim that this is “not a security breach.” Especially as it includes a bunch of unannounced and unreleased features. There’s little impact on companies outside of Anthropic, and it’ll be interesting to see if, or what, financial impact this ‘intellectual property theft’ incident has on the firm.

  2. Axios: On Monday, a malicious version of the Axios JavaScript library was published, potentially putting millions of developers and their software projects at risk of compromise. Developers download Axios around 100 million times a week: even an hour’s compromise could impact ~500,000 downloads. The post mortem goes into detail of how the compromise occurred: socially engineering the lead maintainer into joining a Slack workspace mimicking a real company, and then subsequently inviting them to an MS Teams meeting to discuss collaboration: when they joined a convincing ‘update message’ was displayed prompting them to update Teams with what’s thought to be a remote access trojan. Props for the transparency. This technical writeup explains how the malware steals secrets and credentials used during build processes.  Google security researchers say the incident is the work of a North Korean threat actor, ‘UNC1069’. North Korea typically conducts software supply chain attacks to obtain cryptocurrency to fund its regime; it’s unclear whether this is the motive in this case. This breach will have a long tail, given the widespread use of Axios. If you or your developers use it, check to see if you’ve been compromised and rotate everything involved if you have.

  3. Iran: Researchers say they have seen Iran-linked threat actors conducting password-spraying attacks against ‘hundreds’ of Middle East government and municipal organisations. The attacks, similar to those attributed to the IRGC’s Peach Sandstorm and Grey Sandstorm groups, generally focus on gaining access to Microsoft 365 environments to steal sensitive information. Check Point says that there appears to be some overlap between city administrations and those targeted by Iran with missile attacks, potentially seeking to ascertain the damage and support of kinetic warfare. Meanwhile, Jacob Judah’s article for the FT has a pretty balanced view of Tehran’s cyber operations, their objectives, and constraints. It’s also syndicated on ArsTechnica if you hit a paywall.

  4. Cisco believes that threat actors have some of its stolen source code after losing development and build environment credentials and AWS keys in the Trivy supply chain attack. Cisco hasn’t had the most stellar track record of finding and fixing vulnerabilities in its (particularly legacy) products, and so losing source code like this may make it easier for attackers to find vulnerabilities in Cisco products that they can use to compromise customers’ environments.

  5. GDDRHammer: Researchers have proven that rowhammer style attacks can be used against Nvidia GPUs to gain root control over the underlying system. Researcher Andrew Kwong told ArsTechnica “an attacker can induce bit flips on the GPU to gain arbitrary read/write access to all of the CPU’s memory, resulting in complete compromise of the machine.” This is a huge deal for providers and consumers of cloud compute, where expensive Nvidia GPUs can be shared among customers for AI workloads. 

In brief

And finally

  • Astronauts aboard the Artemis II mission to the moon have complained that they have two copies of Microsoft Outlook, and neither was working. I’m just surprised they’re not using Thunderbird 3. I’ll get my coat. And h/t Paul for this gem:

It’s Monday morning and Outlook is giving you stick, just like a real life astronaut!

TeleGuard’s implementation of encryption makes it essentially pointless and the app is not architected to protect user communications (source: Trail of Bits)

Robin
  Anthropic Claude Intellectual Property North Korea Axios Supply Chain Iran Cisco Trivy Rowhammer GDDRHammer Artificial Intelligence (AI) Cloud