on April 3, 2026 at 5:00 pm — Axios NPM supply chain incident
Cisco Talos is actively investigating the March 31, 2026 supply chain attack on the official Axios node package manager (npm) package during which two malicious versions (v1.14.1 and v0.30.4) were deployed. Axios is one of the more popular JavaScript libraries with as many as 100 million downloads per week. Axios is a widely-deployed HTTP client
on April 3, 2026 at 5:00 pm — Axios NPM supply chain incident Read More »
on April 3, 2026 at 1:46 am — Chromium: CVE-2026-5285 Use after free in WebGL
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
on April 3, 2026 at 1:46 am — Chromium: CVE-2026-5285 Use after free in WebGL Read More »