[ DAILY DIGEST ] 2026-04-06 Mon

Full Daily Digest

4 articles · 7.80 avg score

Daily Overview

Date: 2026-04-06. Article count: 4. Average score: 7.80. Top categories: Incidents (3), Vulnerability (1). Recurring terms: UNC4736, CVE-2026-35616, credential harvesting, Privilege Escalation, Strapi.

Per-Article Analysis

Incidents The Hacker News Score 7.8

$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation

Incidents: A sophisticated six-month social engineering operation by North Korea's UNC4736 hacking group culminated in a $285 million theft from the Solana-based decentralized exchange Drift.

Deep Analysis and Expert Commentary

A sophisticated six-month social engineering operation by North Korea's UNC4736 hacking group culminated in a $285 million theft from the Solana-based decentralized exchange Drift. The attack, attributed with medium confidence to the DPRK-linked group, showcases their persistent focus on cryptocurrency theft, building on past exploits like the $53 million Radiant Capital hack and the X_TRADER/3CX

Original Article Brief Intro

The Hacker News · 2026-04-05 · Incidents: A sophisticated six-month social engineering operation by North Korea's UNC4736 hacking group culminated in a $285 million theft from the Solana-based decentralized exchange Drift.

Related Terms and Notes

Threat Actors
  • UNC4736 — A North Korean state-sponsored hacking group linked to cryptocurrency theft and social engineering campaigns.
Context Notes
  • Cryptocurrency
  • Cybercrime
  • Golden Chollima — An offshoot of Labyrinth Chollima, focused on financial theft to support DPRK's military and economic goals.
  • North Korea
  • Social Engineering
  • Threat Intelligence
Incidents Help Net Security Score 7.8

Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploited

Incidents: A recent npm supply chain attack targeting Axios, a widely used HTTP client library, has raised alarms across the cybersecurity community.

Deep Analysis and Expert Commentary

A recent npm supply chain attack targeting Axios, a widely used HTTP client library, has raised alarms across the cybersecurity community. Attackers compromised the GitHub and npm accounts of the main developer, injecting malicious dependencies that deployed droppers and remote access trojans. This incident, linked to North Korean hackers by Google researchers, underscores the escalating threat of

Original Article Brief Intro

Help Net Security · 2026-04-05 · Incidents: A recent npm supply chain attack targeting Axios, a widely used HTTP client library, has raised alarms across the cybersecurity community.

Related Terms and Notes

Context Notes
  • Axios — A popular JavaScript library used for making HTTP requests, widely utilized in web development.
  • deepfake
  • FortiClient EMS — Fortinet's endpoint management solution, designed to secure and manage endpoints across an organization.
  • Mimecast
Incidents The Hacker News Score 7.8

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

Incidents: A coordinated campaign has deployed 36 malicious npm packages masquerading as Strapi CMS plugins, exploiting Redis and PostgreSQL to establish persistent implants and harvest credentials.

Deep Analysis and Expert Commentary

A coordinated campaign has deployed 36 malicious npm packages masquerading as Strapi CMS plugins, exploiting Redis and PostgreSQL to establish persistent implants and harvest credentials. These packages, uploaded by four sock puppet accounts within a 13-hour window, lack metadata and mimic legitimate plugin naming conventions ('strapi-plugin-*'), leveraging postinstall hooks to execute malicious c

Original Article Brief Intro

The Hacker News · 2026-04-05 · Incidents: A coordinated campaign has deployed 36 malicious npm packages masquerading as Strapi CMS plugins, exploiting Redis and PostgreSQL to establish persistent implants and harvest credentials.

Related Terms and Notes

Techniques / TTPs
  • credential harvesting
  • Strapi — Open-source headless CMS built with Node.js, often extended via plugins.
  • supply chain attack
Context Notes
  • npm registry
  • persistent implant
  • postinstall hook — A script in npm packages that executes automatically after installation, commonly abused for malicious payloads.
  • reverse shell
Vulnerability The Hacker News Score 7.8

Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

Vulnerability: A critical vulnerability, CVE-2026-35616, has been actively exploited in FortiClient EMS, allowing unauthenticated attackers to bypass API access controls and execute arbitrary code.

Deep Analysis and Expert Commentary

A critical vulnerability, CVE-2026-35616, has been actively exploited in FortiClient EMS, allowing unauthenticated attackers to bypass API access controls and execute arbitrary code. With a CVSS score of 9.1, this flaw impacts versions 7.4.5 through 7.4.6, prompting Fortinet to release an out-of-band hotfix ahead of the full patch in version 7.4.7. Researchers Simo Kohonen and Nguyen Duc Anh disco

Original Article Brief Intro

The Hacker News · 2026-04-05 · Vulnerability: A critical vulnerability, CVE-2026-35616, has been actively exploited in FortiClient EMS, allowing unauthenticated attackers to bypass API access controls and execute arbitrary code.

Related Terms and Notes

CVE IDs
  • CVE-2026-35616 — A critical vulnerability in FortiClient EMS allowing unauthenticated API access bypass and privilege escalation.
Techniques / TTPs
  • Privilege Escalation
  • Zero-Day Exploitation
Context Notes
  • FortiClient EMS — Fortinet's endpoint management solution for deploying and managing FortiClient software across endpoints.