MEDIUMSupply Chain
Global

AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks

·Source: Infosecurity Magazine

Updated:

Executive Summary

AWS has linked North Korea to the axios campaign to other attacks on npm libraries

Analysis

AWS has linked North Korea to the axios campaign to other attacks on npm libraries
Source Attribution

Originally published by Infosecurity Magazine on Jul 31, 2026.

Related Threats

CRITICALSupply Chain

JetBrains says a crafted HTTP request could break TeamCity

JetBrains is warning of a critical security vulnerability in its TeamCity DevOps platform that could allow unauthenticated attackers to execute arbitrary operating system commands on vulnerable servers. “If exploited, this vulnerability may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary commands,“ the company said in

CVE-2026-63077
CSO Online
CRITICALSupply Chain

After OpenAI, Anthropic finds Claude breached three organizations during cyber tests

Less than two weeks after OpenAI disclosed that an experimental AI model breached Hugging Face during a cybersecurity evaluation, Anthropic has revealed that its own review uncovered three incidents in which Claude models gained unauthorized access to the production infrastructure of three organizations during similar testing. Anthropic said it launched the review after OpenAI disclosed that one o

CSO Online
CRITICALSupply Chain

Microsoft confirms an AI worm is propagating through Copilot and other MS apps

A prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including Word and Copilot. The report from noted Norwegian AI researcher Håkon Måløy , now confirmed by Microsoft, said that an attacker can conceal instructions in a document that is later used as source material for Copilot-generated or Copilot-edited Word doc

CSO Online