No-frills tech news

Mercor says it was hit by cyberattack tied to compromise of open source LiteLLM project

Mercor, a popular AI recruiting startup, has confirmed a security incident linked to a supply chain attack involving the open source project LiteLLM. The AI startup told TechCrunch on Tuesday that it was “one of thousands of companies” affected by a recent compromise of LiteLLM’s project, which was linked to a hacking group called TeamPCP. Confirmation of the incident comes as extortion hacking group Lapsus$ claimed it had targeted Mercor and gained access to its data. It’s not immediately clear how the Lapsus$ gang obtained the stolen data from Mercor as part of TeamPCP’s cyberattack. Founded in 2023, Mercor works with companies, including OpenAI and Anthropic, to train AI models by contracting specialized domain experts such as scientists, doctors, and lawyers from markets, including India. The startup says it facilitates more than $2 million in daily payouts and was valued at $10 billion following a $350 million Series C round led by Felicis Ventures in October 2025. Mercor spokesperson Heidi Hagberg confirmed to TechCrunch that the company had “moved promptly” to contain and remediate the security incident. “We are conducting a thorough investigation supported by leading third-party forensics experts,” said Hagberg. “We will continue to communicate with our customers and contractors directly as appropriate and devote the resources necessary to resolving the matter as soon as possible.” Earlier, Lapsus$ claimed responsibility for the apparent data breach on its leak site and shared a sample of data allegedly taken from Mercor, which TechCrunch reviewed. The sample included material referencing Slack data and what appeared to be ticketing data, as well as two videos purportedly showing conversations between Mercor’s AI systems and contractors on its platform. Disrupt 2026: The tech ecosystem, all in one room Your next round. Your next hire. Your next breakout opportunity. Find it at TechCrunch Disrupt 2026, where

Alain Dephonse '25: Dual Degree Program + Internships Pave Way to <b>Cybersecurity</b> Job

Alain Dephonse ’25: Dual Degree Program + Internships Pave Way to Cybersecurity Job Current Role: Associate Cybersecurity Analyst, New York Power Authority Dual Degree: B.S. in Computer Science and Information Security (May 2025); M.S. in Digital Forensics & Cybersecurity (December 2025) Advanced Certificate: Applied Digital Forensics Internships: New York City Department of Citywide Administrative Services, Intern; New York Power Authority, Cybersecurity Intern Hometown: Queens, NY Career Aspiration: Computer Science Professional What was life like before John Jay? I grew up in Queens, New York, in a Haitian American household, living with my mom, dad, and sister. My parents are from Haiti, and I grew up visiting the country. I learned a bit of Haitian Creole as a kid, though I’m a little rusty now, but I have immense appreciation and love for my culture. I went to school in Queens for most of my life. What sparked your passion for computer science? It was through my father’s love of music that my passion for computers and technology was born. It was interesting to me to see how quickly technology evolved and how, with each evolution, the access to music was better, the devices were smaller, and the quality of the sound was improved. My dad always had the latest gear to play his music: record players, stereo systems, CD burners to make mixed albums, and the newest devices and laptops. I also grew up with friends who were always doing something tech-related. We’d have conversations about emerging technology and share information on the latest products. So, technology has always been a big focus in my life. My passion for computer science continued to grow in high school. I went to the Thomas Edison Career & Technical Education High School, where I learned about computer programming and computer repair. My knowledge

AuthMind Recognized with <b>Cybersecurity</b> Excellence Award for AI Agent Identity Security Innovations

BETHESDA, MD, UNITED STATES, April 1, 2026 /EINPresswire.com/ — AuthMind, the leader in identity observability-driven threat protection, today announced that its AuthMind Identity Observability & Protection Platform recently received two gold Cybersecurity Excellence Awards as well as a silver-level win. Taking home the program’s silver honors in the AI Agent Identity Security category in this year’s Cybersecurity Excellence Awards, AuthMind also received gold accolades in the Identity Security Posture Management (ISPM) and Identity Threat Detection and Response (ITDR) categories. “Selected by an independent jury of cybersecurity practitioners, analysts, and CISOs, this recognition highlights the role of innovative security solutions in strengthening cybersecurity across organizations worldwide,” said Holger Schulze, founder of Cybersecurity Insiders and organizer of the Cybersecurity Excellence Awards. “We congratulate AuthMind on earning gold and silver award recognitions in the 2026 Cybersecurity Excellence Awards.” As enterprises deploy more AI-Agents for human assistance or autonomous operations, identity security challenges are becoming more complex and dynamic. AuthMind addresses this challenge by delivering network-driven identity observability that maps real access paths across cloud, SaaS, hybrid, and on-premises environments, detecting and protecting all AI Agents access activity. This enables organizations to detect misuse, uncover hidden risks, and eliminate identity blind spots tied to AI Agents as well as the NHIs they use and their associated potential users. A full list of this year’s award winners is available at: https://cybersecurity-excellence-awards.com/ About AuthMind AuthMind empowers organizations to secure agentic AI, non-human (NHI), and human identities by continuously observing every access and understanding every activity across every environment. Unlike traditional identity tools, AuthMind’s patented observability provides real-time visibility into identity behavior, eliminating blind spots and shadow IT while transforming identity security from a static policy-based approach to dynamic AI-based solution. Founded in 2020, the Maryland-based company also has R&D operations in Pune, India. Visit www.authmind.com. Selena

HOPPR™ AI Foundry Achieves HITRUST e1 Certification, Demonstrating Commitment to ...

Certification validates that HOPPR's platform is meeting rigorous cybersecurity and data protection standards through independent assessment and assurance, building on the company's recent SOC 2 Type II attestation. CHICAGO, April 1, 2026 /PRNewswire/ -- HOPPR, a company focused on transforming how AI is developed for medical imaging, today announced its platform HOPPR™ AI Foundry has earned e1 certified status from HITRUST for cybersecurity and information protection. HITRUST e1 Certification demonstrates that HOPPR™ AI Foundry has met requirements defined by leading cybersecurity and regulatory frameworks, confirming that strong controls are in place to protect sensitive data and manage risk effectively. Built on the HITRUST Assurance Program, this achievement reflects independent third-party testing, centralized quality assurance, and certification backed by HITRUST's Cyber Threat-Adaptive engine. These elements ensure continuous alignment with the latest threat intelligence and evolving standards across NIST, ISO, and OWASP. "As our HOPPR AI Foundry platform grows, so does our responsibility to maintain rigorous security controls," said Trever Falconi, Director, IT Security and Operations at HOPPR. "Achieving HITRUST Certification reflects the discipline we've built into our operations and our ongoing commitment to protecting sensitive data and maintaining trust for those we serve." "Earning HITRUST Certification demonstrates HOPPR's commitment to managing information risk and protecting sensitive data through a rigorous, proven assurance process," said Gregory Webb, CEO of HITRUST. "This achievement reflects the organization's proactive approach to cybersecurity and trust." The company also announced it has achieved SOC 2 Type II attestation, an independent validation that the company's security controls are appropriately designed and operating effectively over time. The attestation provides third-party assurance that HOPPR maintains structured safeguards to protect customer environments and sensitive data. To learn more about the HOPPR™ AI Foundry, click here. About HOPPR Founded in 2019, HOPPR brings together experts in clinical radiology, AI development, and healthcare

Hacker Tries to Spread Malware to Millions by Hitting 'Axios NPM' Software | PCMag

A hacker has compromised a little-known, but popular 2.4MB software package that's downloaded over 100 million times per week and is widely used across apps. The IT security community is sounding the alarm about the attack on Axios, an “npm package” that functions as pre-built software that a developer can easily incorporate into a JavaScript project, and basically lets an app talk to the internet and fetch data. However, a hacker hijacked the account of Axios' lead developer and quietly introduced two malicious software versions on Monday night, according to cybersecurity vendor StepSecurity. To evade detection, the hacker-created versions don't contain any malicious code. Instead, they use an instruction to pull from another software project, called “plain-crypto-js,” which can install malware on the computer. The threat is designed to deliver a macOS, Windows, or Linux-based remote access Trojan, depending on the computer’s operating system, allowing the hacker to rifle through a PC, hijack functions, and potentially steal data. This Tweet is currently unavailable. It might be loading or has been removed. The malware versions are also designed to delete themselves after execution. The good news is that the attack only circulated for about three hours before the malicious plain-crypto-js component was taken down, according to Endor Labs. Still, the attack may have affected numerous software developers considering Axios’s reach. “If you installed either compromised version, treat the system as fully compromised,” Endor Labs says. The security community is calling the incident a “supply chain attack” because any software project that incorporated Axios could have ended up running the attack if it had been configured to run the latest version of the npm package. Cybersecurity vendor Wiz noted the attack was observed in about 3% of the affected environments, including cloud and coding platforms. Another provider called Huntress also observed its

Senators Rosen, Blackburn, Rep. Lee, Fitzpatrick Introduce Bipartisan and Bicameral ...

WASHINGTON, DC – U.S. Senators Jacky Rosen (D-NV), Marsha Blackburn (R-TN), Representatives Susie Lee (D-NV-03), and Brian Fitzpatrick (R-PA-01) introduced bipartisan and bicameral legislation to support and expand cybersecurity apprenticeships. The Cyber Ready Workforce Act directs the Department of Labor to establish a grant program to support the creation, implementation, and expansion of registered apprenticeship programs in cybersecurity. “As cyberattacks become more common and complex, we need to ensure we have the workers with the training and skills necessary to protect our cyber infrastructure and Americans’ personal data,” said Senator Rosen. “This bipartisan legislation will help fill gaps in our cybersecurity workforce and will open the door to more good-paying, cutting edge jobs for Nevadans, regardless of whether or not they have a college degree. I’ll keep working across party lines to ensure our workers have the skills needed to fill the jobs of the future.” “With a growing number of cybersecurity job openings nationwide, America’s severe talent shortage poses a serious threat to our national security and economic growth,” said Senator Blackburn. “The bipartisan Cyber Ready Workforce Act would establish a grant program to expand registered apprenticeships, train Tennessee workers for these high-paying jobs, and build a stronger cybersecurity workforce through targeted support for our businesses, colleges, and nonprofits.” “Whether you know it or not, cybersecurity impacts all of us, from our small businesses, to utility grids, to our national security. But we don’t have enough talent to fill these jobs — Nevada alone is facing a shortage of nearly 4,000 cybersecurity professionals,” said Congresswoman Susie Lee. “That’s why I’m reintroducing bipartisan, bicameral legislation to address this shortage by creating cybersecurity apprenticeships to recruit and train a new generation of our cybersecurity workforce. This bill will help ensure that we don’t fall behind when it comes to cybersecurity, while

Will AI replace <b>cybersecurity</b> jobs?

If you’re considering a career in cybersecurity, you may be wondering how artificial intelligence (AI) could impact your future. AI has already made a noticeable impact across the tech industry, with increased automation contributing to workforce shifts and fewer entry-level opportunities. Headlines about layoffs and rapid technological change have raised valid concerns — especially for those just starting out. So, what does that mean for cybersecurity? Will AI replace these roles as well? The short answer is no. Cybersecurity is a specialized branch of information technology focused on risk management, threat defense and data compliance. AI can provide some assistance by improving efficiencies or completing repetitive tasks, but it can’t fully replicate the strategic decision-making and knowledge of human cybersecurity experts. In fact, according to the U.S. Bureau of Labor Statistics, cybersecurity jobs are rising. Information security analysts have a faster-than-average projected job outlook of 29% through 2034. How is AI used in cybersecurity? While AI can’t fully replace the cybersecurity workforce, it will remain a reality in the field. AI has been part of cybersecurity for more than 40 years, primarily used for basic threat detection and automatic system updates. As AI continues to evolve, threat detection is becoming automated through generative security processes that protect user data by identifying system risks and vulnerabilities faster than ever before. That said, the human factor is arguably more important because large language models (LLMs) are limited and can be exposed to sensitive data, “hallucinate” false information or become vulnerable to new, unpredictable attacks. This presents an opportunity for cybersecurity experts to use and train AI tools to detect threats more quickly and efficiently. Rather than replacing workers, AI is transforming efficiencies and changing the scope of day-to-day operations. In some instances, AI is even creating new jobs in the field. The

Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts

Cybersecurity researchers have disclosed a security "blind spot" in Google Cloud's Vertex AI platform that could allow artificial intelligence (AI) agents to be weaponized by an attacker to gain unauthorized access to sensitive data and compromise an organization's cloud environment. According to Palo Alto Networks Unit 42, the issue relates to how the Vertex AI permission model can be misused by taking advantage of the service agent's excessive permission scoping by default. "A misconfigured or compromised agent can become a 'double agent' that appears to serve its intended purpose, while secretly exfiltrating sensitive data, compromising infrastructure, and creating backdoors into an organization's most critical systems," Unit 42 researcher Ofir Shaty said in a report shared with The Hacker News. Specifically, the cybersecurity company found that the Per-Project, Per-Product Service Agent (P4SA) associated with a deployed AI agent built using Vertex AI's Agent Development Kit (ADK) had excessive permissions granted by default. This opened the door to a scenario where the P4SA's default permissions could be used to extract the credentials of a service agent and conduct actions on its behalf. After deploying the Vertex agent via Agent Engine, any call to the agent invokes Google's metadata service and exposes the credentials of the service agent, along with the Google Cloud Platform (GCP) project that hosts the AI agent, the identity of the AI agent, and the scopes of the machine that hosts the AI agent. Unit 42 said it was able to use the stolen credentials to jump from the AI agent's execution context into the customer project, effectively undermining isolation guarantees and permitting unrestricted read access to all Google Cloud Storage buckets' data within that project. "This level of access constitutes a significant security risk, transforming the AI agent from a helpful tool into a potential insider threat," it

Finra Launches Threat-Sharing Center to Tackle <b>Cybersecurity</b>, Fraud Risks | ACAMS

This content is exclusively available to: Want access? Learn more about Moneylaundering.com and Enterprise Membership here. From foundational training to advanced certifications – build the skills that move your career, and the fight against financial crime, forward. Stay informed from every angle. Perspectives, by ACAMS Today, dives deep with expert voices and industry-shaping perspectives, while News, by moneylaundering.com, brings you real-time coverage of global headlines. Stay connected. From local Chapter meetups to The Assembly in your region, ACAMS events bring together the AFC community to share insights and shape what’s next. All of ACAMS content is available by topic, industry, or by country and jurisdiction. Explore our news, analysis, insights, and trainings for each. Enterprise members and MLDC subscribers can also track regulations, legislation, and enforcement action by jurisdiction. Whether you’re looking to improve your own training, or searching for solutions for your team, we can help. Talk to our team about solutions for first, second, or third line of defense. Want access? Learn more about Moneylaundering.com and Enterprise Membership here.

UM spinoff <b>cybersecurity</b> firm lands $70M new financing round for AI push

March 31, 2026 02:50 PM EDT Featured Stories Pay Detroiters a living wage, Sheffield urges employers in her first State of the City address In her first State of the City speech, Detroit Mayor Mary Sheffield stuck to kitchen table issues and called on employers to raise worker pay

Fairleigh Dickinson University Appoints <b>Cybersecurity</b> Leader Miguel A. Crespo to Board of Trustees

Fairleigh Dickinson University Appoints Cybersecurity Leader Miguel A. Crespo to Board of Trustees Appointment reflects longstanding relationship between FDU and Becton, Dickinson and Company April 2026 — Fairleigh Dickinson University (FDU) has appointed cybersecurity and digital risk executive Miguel A. Crespo to its Board of Trustees for a three-year term. Mr. Crespo serves as chief information security officer and vice president for cybersecurity and digital risk at Becton, Dickinson and Company (BD), the global medical technology company headquartered in Franklin Lakes, N.J. In this role, he leads enterprise-wide cybersecurity and digital risk oversight across BD’s global operations and chairs the company’s Responsible AI Committee, guiding ethical technology adoption and risk governance. Mr. Crespo’s appointment reflects the longstanding relationship between FDU and BD. The University is named for Fairleigh S. Dickinson, co-founder of BD and an early benefactor whose philanthropy helped establish the institution. BD’s legacy of innovation in healthcare and technology has remained closely connected to FDU’s mission of preparing students for leadership in a rapidly evolving global economy. “Miguel A. Crespo brings exceptional expertise at the intersection of cybersecurity, risk management and responsible technology,” said Michael Avaltroni, president of Fairleigh Dickinson University. “His leadership and global perspective, along with the historic relationship between FDU and BD, will provide valuable insight as the University continues preparing students for the challenges and opportunities of a digital world.” Mr. Crespo brings more than 23 years of leadership experience across healthcare, pharmaceutical, life sciences and public sector organizations. Prior to joining BD in 2024, he served as vice president and digital & IT risk officer at Bristol Myers Squibb, where he led global initiatives focused on cybersecurity, data privacy, intellectual property protection and manufacturing security. Earlier in his career, Mr. Crespo held senior roles at Booz Allen Hamilton, Mandiant and EY. He also

FINRA Launches Financial Intelligence Fusion Center To Combat <b>Cybersecurity</b> And Fraud Threats

FINRA announced today the launch of the Financial Intelligence Fusion Center (FIFC), a secure portal for FINRA and its member firms to share timely intelligence about cybersecurity and fraud threats and coordinate responses. Building on FINRA's continued commitment to help member firms combat cyber and financial crime threats, the FIFC will collect, analyze and disseminate threat intelligence to bolster member firms’ awareness and ability to quickly respond to these threats. The FIFC will also leverage FINRA's existing partnerships, enabling input from other government and private sector partners. The platform was developed as part of FINRA Forward, a series of initiatives to further improve FINRA’s effectiveness and efficiency in achieving its mission of protecting investors and safeguarding market integrity. As a self-regulatory organization, FINRA is uniquely positioned to work with its member firms to better protect investors and mitigate risk to the securities industry. FINRA began piloting the FIFC last year with a diverse group of member firms, whose participation and feedback have helped strengthen the portal’s functionality and effectiveness for member firms of all sizes. Through the pilot program, member firms have accessed FINRA’s threat intelligence products and actively shared cybersecurity and fraud threat intelligence via the FIFC, enabling timely threat mitigation. FINRA encourages member firms to opt into the FIFC to gain access to this centralized portal for intelligence sharing among firms and FINRA. The FIFC expands on the range of resources FINRA provides its members, including guidance for establishing cybersecurity programs, addressing vulnerabilities, combating cyber-enabled fraud and identifying emerging scams, among others. “The Financial Intelligence Fusion Center will be a powerhouse that facilitates timely intelligence sharing to benefit member firms, their customers and the securities industry. As cybersecurity and fraud threats evolve, this type of innovation and coordination with our member firms—which is made possible because of our

Depthfirst: $80 Million Raised For AI-Native <b>Cybersecurity</b> Platform Expansion

depthfirst, an applied AI lab focused on securing software systems, announced it has raised $80 million in a Series B funding round, bringing its total capital raised to $120 million. The round was led by Meritech Capital, with participation from Forerunner Ventures and The House Fund, alongside existing investors including Accel, Box Group, Liquid 2 Ventures, Alt Capital, and Mantis VC. The funding comes less than 90 days after the company emerged from stealth with a $40 million Series A round, signaling strong investor confidence in its approach to AI-driven cybersecurity. As part of the announcement, depthfirst introduced its first in-house security model, dfs-mini1, designed initially to secure cryptocurrency smart contracts. The model was built on an open-source foundation and further trained using reinforcement learning in security-specific environments. It was evaluated on OpenAI’s EVMBench, a benchmark for identifying vulnerabilities in smart contracts. According to the company, dfs-mini1 outperformed frontier models while operating at 10x to 30x lower cost. Early internal testing also suggests the model can generalize beyond smart contracts to broader security tasks, indicating potential scalability across multiple domains. depthfirst’s broader strategy centers on developing domain-specific AI models tailored to high-stakes applications like cybersecurity. Its AI-native platform analyzes entire software systems, identifies vulnerabilities, and provides developers with ready-to-merge fixes directly within their workflows. The company says its platform is already being used by a mix of Fortune 500 companies and high-growth technology firms, including ClickUp, Supabase, incident.io, Moveworks, and Lovable. It reports that approximately 80 percent of its recommended fixes are accepted and merged by developers, reflecting strong real-world utility. The newly raised capital will be used to expand the company’s AI research team, develop additional specialized security models, and accelerate enterprise adoption of its platform. KEY QUOTES: “When you own the training process, you can optimize for what

Why I'm done calling humans the weakest link

Why I’m done calling humans the weakest link Cybersecurity has long suffered from a people problem, but not in the way we often hear about. As industry that is based on enabling communication across the globe via the internet and many types of devices, many of us practitioners are very bad at communicating to people. A primary example is the phrase “humans are the weakest link” which is well known phrase in our industry. This phrase implies that if it were not for human our systems would be fully secure, but most worryingly projects the message to non-cybersecurity people that there are inferior to us. So not only does this phrase alienate our fellow workers it is a phrase that I firmly believe is unfair and completely misleading. The real issue around cybersecurity is not human error, it is the failure of the technology and the system designs and architecture to support real human behavior. Despite years of awareness campaigns, data breaches linked to phishing and credential misuse continue to dominate incident reports and news headlines. And after each of these breaches the vendors and experts commenting on the breach will reuse the phrase “humans are the weakest link” laying the blame not on any failures in the technology meant to protect us but, instead placing the blame on the person using the computer. Even if a person did get phished or fell victim to a malicious email this should not prompt another round of finger-pointing. Instead, it should raise urgent questions about why so many of our systems still leave people so vulnerable. Take phishing, for example. If a malicious email lands in an inbox and a staff member clicks it, the typical response is to blame the individual for not spotting the signs. But why did the email

The Great Repricing Crushed This <b>Cybersecurity</b> Growth Stock. That's a Buying Opportunity.

Zscaler (ZS +2.34%) was one of the market's hottest cybersecurity stocks, reaching an all-time high of $368.78 per share on Nov. 19, 2021. But today, it trades at about $139. Zscaler's stock initially lost its luster as its growth cooled, but macro headwinds -- including rising interest rates and geopolitical conflicts -- further compressed its valuation. Yet after that steep sell-off, Zscaler's stock might be a good contrarian play for patient investors. How fast is Zscaler growing? Zscaler develops "zero trust" tools that treat everyone, including a company's CEO, as a potential threat. Those tools can shield organizations from both internal and external threats while being integrated into larger, more diversified cybersecurity platforms. Before Zscaler was founded in 2007, many organizations installed their zero-trust services on physical appliances -- which took up space, required on-site maintenance, and were difficult to scale. Zscaler addressed those issues by launching its tools as a cloud-native service that locked its users into sticky subscriptions and didn't require any on-site appliances. It subsequently expanded its ecosystem with additional cloud-based cybersecurity tools and now serves more than 9,400 customers, including 40% of the Forbes Global 2000 companies. NASDAQ: ZS Key Data Points From fiscal 2020 to fiscal 2025 (which ended in July 2025), Zscaler's revenue and adjusted net income grew at CAGRs of 44% and 75%, respectively. However, it still isn't profitable by generally accepted accounting principles (GAAP), mainly due to its stock-based compensation expenses and long streak of ecosystem-expanding acquisitions. From fiscal 2025 to fiscal 2028, analysts expect Zscaler's revenue to grow at a 21% CAGR. They also expect it to turn profitable on a GAAP basis in the final year. Its growth is slowing down as its business matures. However, it's still expanding its AI-powered ZDX Copilot platform, deepening its integrations with other cloud-based

VendRespect Introduces Advanced <b>Cybersecurity</b> Scoring System to Help Businesses ...

Los Angeles, California – March 31, 2026 – PRESSADVANTAGE – VendRespect, a Valley Village-based cybersecurity and vendor management company, has introduced a comprehensive scoring system designed to help businesses quantify and manage their digital security risks across their entire vendor ecosystem. The new system addresses a critical challenge facing modern businesses: understanding and managing cybersecurity vulnerabilities not just within their own operations, but throughout their supply chain. With cyber threats becoming increasingly sophisticated and supply chain attacks rising dramatically, organizations need clear metrics to assess their security posture and that of their vendors. VendRespect cybersecurity scoring provides businesses with a dynamic, real-time assessment that changes as vendor security profiles evolve. The system integrates multiple assessment methods, including automated risk evaluations, third-party verifications, and continuous monitoring of vendor security practices. “Businesses today face an unprecedented challenge in managing cybersecurity across their entire vendor network,” said Maksim Avrukin, founder of VendRespect. “Our scoring system transforms complex security data into actionable intelligence that business owners and IT professionals can use to make informed decisions about their digital infrastructure and vendor relationships.” The scoring methodology evaluates multiple security factors including current security practices, vendor security profiles, and third-party verification results. Unlike static assessments that quickly become outdated, the system updates continuously to reflect changes in the threat landscape and vendor security status. For managed service providers and IT consultants, the platform offers integration with existing documentation systems such as IT Glue, enabling seamless incorporation of security scoring into current workflows. This integration allows service providers to leverage existing client data while providing visual documentation that supports security recommendations and compliance requirements. The system also addresses supply chain risk management by identifying critical vendors within an organization’s ecosystem and assessing how their security practices impact overall organizational risk. This comprehensive approach helps businesses understand vulnerabilities

Supply-Chain Compromise of axios npm Package

Note: This Rapid Response article has been written with AI assistance. Acknowledgments: Special thanks to Jevon Ang, Michael Elford, Jordan Sexton, Armelle French, Stephanie Fairless, Juzzy Allen, Ryan Dowd, Chad Hudson, Lindon Wass, James Maclachlan, James Northey, Josh Kiriakoff, Jai Minton, and Max Rogers for their contributions to this investigation and response. TL;DR: Huntress has observed active exploitation of a supply chain compromise targeting the axios npm package -- one of the most widely used JavaScript libraries, with over 100 million weekly downloads. The attack delivered a cross-platform Remote Access Trojan (RAT) to macOS, Windows, and Linux systems via a malicious dependency injected into backdoored axios releases. Organizations should immediately audit their dependencies for axios@1.14.1 or axios@0.30.4, treat any system that installed either version as compromised, and follow the remediation guidance below. Background On March 31, 2026, a coordinated supply chain attack was executed against the axios npm package. An attacker compromised the npm credentials of the lead maintainer account (jasonsaayman) and manually published two backdoored releases: axios@1.14.1 (tagged latest) and axios@0.30.4 (tagged legacy). These versions introduced a phantom dependency -- plain-crypto-js@4.2.1 ... a package that had not existed before that day and is never actually imported by axios code. Its sole purpose was to execute a postinstall script that drops and runs a cross-platform RAT targeting macOS, Windows, and Linux. axios is a promise-based HTTP client used extensively across the JavaScript and Node.js ecosystem. It is a transitive dependency for countless packages, CI/CD pipelines, developer workstations, and production applications worldwide. The scope of this compromise is significant: any environment that ran npm install and resolved to axios@1.14.1 or axios@0.30.4 during the approximately three-hour exposure window may have executed the malicious payload automatically with no user interaction required. The malicious versions were published during overnight hours (just after midnight UTC,

Dual Enrollment Student Helps Win Cyber Title

by Cara Ramer, Student Public Relations Writer After hours of defending simulated networks against coordinated cyberattacks, a team of Cedarville University students secured first place in one of two Midwest Divisions of the NCAE Cyber Games on Feb. 7, 2026 — and one member of the winning team has yet to graduate from high school. For Kieran Klukas, a high school senior from Westerville, Ohio, taking dual enrollment courses at Cedarville, competing in a collegiate-level cybersecurity competition was an unexpected opportunity. After attending the university’s summer cybersecurity camp, Klukas discovered a passion for cybersecurity and began pursuing the field academically. Klukas sought additional hands-on opportunities within Cedarville’s cybersecurity program, which ultimately led to his selection for the NCAE Cyber Games team. Dual enrollment senior excels in collegiate cybersecurity competition The competition follows a red team-blue team format in which industry professionals and graduate students attempt to breach the systems of competing teams. Participants must defend network infrastructure, maintain system uptime and respond to live attacks in a scenario designed to simulate real-world cybersecurity threats facing businesses, government agencies and critical infrastructure. NCAE Cyber Games: red team–blue team live-fire format Over seven hours, the competition operated as a live-fire exercise, with industry professionals deploying real exploits against each team’s systems. From the opening minutes, services were “catching on fire” as the red team exposed vulnerabilities across the machines. Klukas shifted rapidly between systems, patching weaknesses and shutting down access points as they appeared. By the final stretch, Cedarville was one of the only teams still operational, making it a primary target. Klukas spent the last hours of the competition jumping from service to service, eliminating threats and refusing to let their systems go dark. Cedarville winning team roster and majors Cedarville’s winning team included computer engineering, computer science and cyber operations

Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains

Chinese-speaking users are the target of an active campaign that uses typosquatted domains impersonating trusted software brands to deliver a previously undocumented remote access trojan named AtlasCross RAT. "The operation covers VPN clients, encrypted messengers, video conferencing tools, cryptocurrency trackers, and e-commerce applications, with eleven confirmed delivery domains impersonating brands including Surfshark VPN, Signal, Telegram, Zoom, Microsoft Teams, and others," Germany-based cybersecurity company Hexastrike said in a report published last week. The activity has been attributed to a Chinese cybercrime group called Silver Fox, which is also tracked as SwimSnake, The Great Thief of Valley (or Valley Thief), UTG-Q-1000, and Void Arachne. The discovery of AtlasCross RAT represents an evolution of the threat actor's arsenal from Gh0st RAT derivatives like ValleyRAT (aka Winos 4.0), Gh0stCringe, and HoldingHands RAT (aka Gh0stBins). The attack chains involve using bogus websites as lures to trick users into downloading ZIP archives containing an installer that drops a trojanized Autodesk binary along with the legitimate decoy application. The trojanized AutoDesk installer, in turn, launches a shellcode loader that decrypts an embedded Gh0st RAT configuration to extract the command-and-control (C2) details and then downloads a second-stage shellcode payload from "bifa668[.]com" over TCP on port 9899, ultimately leading to the execution of AtlasCross RAT in memory. The majority of fake websites were registered in a single day on October 27, 2025, indicating a deliberate approach behind the campaign. The list of confirmed malware delivery domains is listed below - - app-zoom.com (Zoom) - eyy-eyy.com (unknown) - kefubao-pc.com (KeFuBao, a Chinese customer service software for e-commerce) - quickq-quickq.com (QuickQ VPN) - signal-signal.com (Signal) - telegrtam.com.cn (Telegram) - trezor-trezor.com (Trezor) - ultraviewer-cn.com (UltraViewer) - wwtalk-app.com (WangWang) - www-surfshark.com (Surfshark VPN) - www-teams.com (Microsoft Teams) All identified installer packages have been found to carry the same stolen Extended Validation code-signing certificate