Operative reported tensions with Nigeria in Kwara [8 sources]
Published
Apr 23, 2026, 12:00 AM UTC
20d ago
Significance
Google Threat Intelligence reports a sophisticated supply chain attack on axios NPM package versions 1.14.1 and 0.30.4 (March 31, 2026), where attackers injected malicious 'plain-crypto-js' dependency to deploy WAVESHAPER.V2 backdoor across Windows, macOS, and Linux platforms. Attribution to UNC1069 based on malware signatures, infrastructure overlaps, and operational patterns. Remediation guidance includes version pinning, dependency auditing, CI/CD pipeline security, and credential rotation.
Bandit reported tensions with Operative in Kyara [10 sources]
Lebanon carried out physical assault on Special Operations in Lebanon [10 sources]
50fc4ec2…openwatch.io →