Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios

    September 25, 2026

    Social Media Bans for Kids Need Smarter Safety Design

    September 25, 2026

    The Pentagon wants $30 million to build an AI-powered lie detector

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios
    • Social Media Bans for Kids Need Smarter Safety Design
    • The Pentagon wants $30 million to build an AI-powered lie detector
    • Google’s Gemini Can Now Make Calls for You on Pixel Phones
    • EPICS in IEEE Team Builds Portable Educational Platform
    • A Digital Cell Predicts Which Drugs Will Be Most Effective in Deadly Breast Cancer
    • I Think I Found an AI Agent Worth the Risk
    • AI is dominating the conversation at Climate Week
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Software supply chain hacks trigger wave of intrusions, data theft
    Cybersecurity

    Software supply chain hacks trigger wave of intrusions, data theft

    kirklandc008@gmail.comBy kirklandc008@gmail.comApril 2, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Software supply chain hacks trigger wave of intrusions, data theft
    Share
    Facebook Twitter LinkedIn Pinterest Email

    After linking the Axios npm supply chain attack to North Korean hackers, Google researchers warned that “hundreds of thousands of stolen secrets could potentially be circulating” as a result of this and the Trivy, KICS, LiteLLM, and Telnyx supply chain attacks (linked to TeamPCP).

    “This could enable further software supply chain attacks, software as a service (SaaS) environment compromises (leading to downstream customer compromises), ransomware and extortion events, and cryptocurrency theft over the near term,” they added.

    TeamPCP exploits stolen secrets for cloud intrusions

    Google-owned cloud security company Wiz has responded to multiple attacks being carried out by TeamPCP.

    “[The Wiz Customer Incident Response Team (CIRT)] saw indications in Cloud, Code, and Runtime evidence that the credentials and secrets stolen in the supply chain compromises were quickly validated and used to explore victim [cloud] environments and exfiltrate additional data,” they said.

    “While the speed at which they were used suggests that it was the work of the same threat actors responsible for the supply chain operations, we are not able to rule out the secrets being shared with other groups and used by them.”

    Tech firm OwnCloud stated last week that it had been affected by the Trivy compromise and their ability to ship new builds of and patches for their software solutions “is temporarily suspended.”

    Mercor, a startup that connects human experts with companies building AI, confirmed on Wednesday that it was affected by the LiteLLM supply chain attack.

    The company said it is “one of thousands of companies” impacted and its security team and third-party forensics experts are still investigating the incident.

    Though the Lapsus$ cyber extortion group claimed to have accessed the company’s databases and source code, Mercor has yet to disclose the extent of the impact/breach.

    The connection between TeamPCP and Lapsus$ has been documented. Evidence from Lapsus$’s Telegram channel indicates they had prior knowledge of TeamPCP’s planned supply chain attacks.

    TeamPCP has also apparently partnered with the Vect ransomware-as-a-service operation, and is professedly working on spinning up its own RaaS program called CipherForce.

    Axios compromise affected organizations around the world

    Axios is one of the most widely used JavaScript libraries out there, and the Axios npm supply chain compromise is expected to have a widespread impact.

    “With over 100 million weekly downloads across both [affected] branches [of Axios npm], the blast radius of a three-hour compromise window is significant,” Tenable researchers noted.

    Palo Alto Networks reports that this supply chain compromise has affected organizations across the US, Europe, Middle East, South Asia and Australia, operating in a variety of industries: financial services, high-tech, retail, professional and legal services, insurance, higher education, customers service, and more.

    The attack resulted in a remote access trojan being installed on Windows, macOS and Linux systems, allowing operators to perform system reconnaissance and drop and execute additional binary payloads and commands.

    The North Korean group (UNC1069) behind the Axios breach is known for using social engineering to trick people – especially in crypto, DeFi, software, and VC firms – into installing malware, which matches how the Axios maintainer said his system was compromised.

    Historically, they have been financially motivated.

    “While UNC1069 has had a smaller impact on cryptocurrency heists compared to other groups like UNC4899 in 2025, it remains an active threat targeting centralized exchanges and both entities and individuals for financial gain,” Mandiant researchers noted earlier this year.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    chain data Hacks intrusions software Supply theft Trigger wave
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Shortwave Radio Gets a Secure Data Upgrade With HERMES

    September 21, 2026

    It’s Donald Trump Versus MAGA on Data Centers

    September 20, 2026

    Adopt This Data Center Plushie and Hear Its Piercing Scream

    September 19, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios
    • Social Media Bans for Kids Need Smarter Safety Design
    • The Pentagon wants $30 million to build an AI-powered lie detector
    • Google’s Gemini Can Now Make Calls for You on Pixel Phones
    • EPICS in IEEE Team Builds Portable Educational Platform

    How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios

    September 25, 2026

    Social Media Bans for Kids Need Smarter Safety Design

    September 25, 2026

    The Pentagon wants $30 million to build an AI-powered lie detector

    September 25, 2026

    Google’s Gemini Can Now Make Calls for You on Pixel Phones

    September 25, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.