APJ Ransomware, Axios NPM Hijack, and AI Privacy Nightmares

EPISODE · Apr 7, 2026 · 23 MIN

APJ Ransomware, Axios NPM Hijack, and AI Privacy Nightmares

from Dragon Bytes · host Dragon Bytes

This week on Dragon News Bytes, Eli Woodward and Will Baxter are joined by Ben Archie to break down a high-velocity week of supply chain compromises and surging regional threats. We cover the explosive growth of ransomware in the APJ region, the North Korean state-actor hijack of the Axios NPM package, and the TrueConf zero-day exposing Southeast Asian governments. Plus, we discuss how the recent Anthropic Claude code leak could weaponize package management and the frightening implications of AI on personal data extortion.Topics & References:Part 1: The APJ Threat Landscape & TrueConf Zero-DayRansomware Surge: APJ is currently the fastest-growing region for ransomware, marking a 59% year-on-year increase and accounting for 64% of global incidents.Healthcare Under Fire: The Dragonforce ransomware group recently claimed a breach of the Australian health management system, underscoring massive third-party risks across the country's health sector.TrueConf Zero-Day (CVE-2026-3502): A critical vulnerability in video conferencing software is being abused to compromise on-prem servers and push Havoc malware to connected endpoints. This supply chain attack heavily targets Southeast Asian government networks and was recently added to the CISA KEV catalog.Part 2: Supply Chain Nightmares & The Axios CompromiseThe Axios NPM Hijack: Attackers compromised the NPM publishing account of Axios' lead maintainer, releasing two malicious legacy versions (1.14.1 and 0.30.40). The threat actors injected a phantom runtime dependency without altering the source code, and the packages remained live for roughly two to three hours before NPM yanked them.Attribution: Microsoft has attributed the Axios NPM compromise infrastructure to Sapphire Sleet, a known North Korean state actor.Shiny Hunters Target Cisco: The group claims to have breached Cisco’s internal development environment using credentials stolen during the Trivy GitHub compromise. They allege the theft of AWS keys and over three million Salesforce records, setting an extortion deadline of April 3.Part 3: Threat Actor Drama & AI Privacy RisksRansomware Soap Opera: Threat groups like Team PCP and The Comm are engaging in public trash-talk, echoing previous incidents where The Comm publicly dumped an Oracle EBS zero-day to humiliate Klopp.Anthropic Claude Code Leak: The team discusses how leaked source code could lower the barrier to entry for attackers, allowing them to better understand package management prioritization and weaponize AI models for supply chain attacks.Handala Hack & AI Extortion: Iranian activist group Handala breached the personal email of FBI Director Kash Patel. This sparks a broader discussion on the future of personal extortion, warning that attackers could soon use LLMs to scrape and weaponize the intimate, sensitive data users dump into AI mental health and companion apps.Events & Community:RISE Ireland: April 14 -25 in Dublin, Ireland🔗 to register: https://go.team-cymru.com/rise-irelandRISEx Sydney: May 6 in Sydney, Australia🔗 to register: https://www.team-cymru.com/events/rise-sydney-2026RISEx Frankfurt: May 28th in Frankfurt, Germany🔗 to register: https://www.team-cymru.com/events/rise-frankfurt-2026RISEx New York: June 16 in New York City, US🔗 to register: https://www.team-cymru.com/events/rise-new-york-city-2026Underground Economy: September 7th -9th in Strasbourg, FranceTo be hosted at the Council of Europe, expecting 600-700 attendees. FirstCon26 (Denver): Eli Woodward will be presenting two sessions.🔗 to register: https://www.first.org/conference/2026/registration-options Connect with Us:Follow us on LinkedIn: https://www.linkedin.com/company/team-cymruSubscribe to the Dragon News Bytes feed: https://www.team-cymru.com/dnbDisclaimer: The views expressed in this podcast are those of the hosts and do not necessarily reflect the official policy or position of our employers.

NOW PLAYING

APJ Ransomware, Axios NPM Hijack, and AI Privacy Nightmares

0:00 23:52

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Epic: Silver Wing Realm EPIC is your new HQ for Realm’s exhilarating action and adventure stories, with new episodes dropping every Monday introduced by host Faith McQuinn.Embark on your greatest adventures yet, whether it’s crash landing on a desolate planet with only a cerebrally-embedded AI to guide you, or realizing that your latest game design is the only thing staving off total global annihilation. So unsheath those earbuds, clench that steering wheel, and buckle up because EPIC is about to take off.This month, we are featuring Silver Wing: On a desert planet in the far future, an old dragon hunter embarks on a desperate journey to save her estranged son. For centuries, the dragons have been sleeping. But in their rest, they provide a crucial energy source necessary to keep the planet Toon Flats habitable. Amphet Dahl is a diviner, gifted with the ability to sense the dragons’ dreams and memories and to the disappointment of her son, Afton, she uses this ability to House Podcastica | All the Shows Podcastica This podcast aggregates most of the Podcastica shows into a single feed, for your convenience. Join us as we cover some of our favorite shows, like The Walking Dead, A Knight of the Seven Kingdoms, Severance, Pluribus, The Last of Us, The White Lotus, Fallout, Buffy the Vampire Slayer, Welcome to Derry, The Great British Baking Show, Yellowjackets, House of the Dragon, The Rings of Power, Monarch, and many more! We're fans, and we aim to enhance your experience of these shows. P.S. You can be a part of the discussion: Send us a text or voice message at [email protected] or comment at facebook.com/podcastica, and we'll respond on the air. EDHRECast EDHRECast EDHRECast is your resource for the most popular Magic: The Gathering gameplay format - Elder Dragon Highlander (EDH); widely known as Commander. Made by the community for the community, EDHRECast is hosted by three well-seasoned MTG players, Joey Schultz, Matt Morgan, and Dana Roach. Each week they dive into the latest news and changes to the Commander format and breakdown the meta so that you can play your deck with confidence. Building off the articles found at EDHREC.com the team is here to use data-driven recommendations and analysis to help you make each and every one of your cards work for you. Whether you’re on a budget and still trying to get the most of our your builds, or if you’re trying to get a leg up with the best card combos, or you’re looking to figure out the best early, mid, and late game strategies, we’ll be sure to bring you all the latest information so that you’ll be the Commander of your local scene. Find the cast on Twitter! Dana: @danaroach Matt: @mathimus55 All Things DnD's Story Dungeon All Things DnD This is the official Podcast channel of All Things DnD which is dedicated bringing you the most entertaining Dungeons and Dragon stories this side of Faerun! Need ideas for your next campaign or are you interested in listening to epic tales and some epic fails? Well look no further, you've come to the right place. New stories are posted every three days! 
URL copied to clipboard!