Daily Digest

Supply Chain Attacks and Critical Zero-Days Rattle Global Infrastructure

Supply Chain Attacks and Critical Zero-Days Rattle Global Infrastructure

April 5, 2026
12 articles (8 new, 4 updated)
36 min read

Summary

This edition covers a tumultuous period in cybersecurity for April 5, 2026, dominated by sophisticated supply chain attacks and the active exploitation of critical zero-day vulnerabilities. The European Commission and AI firms like Meta suffered major data breaches originating from compromised open-source tools including Trivy and LiteLLM, with threat actor TeamPCP implicated in both. Concurrently, Fortinet and Google scrambled to patch actively exploited zero-days in FortiClient EMS (CVE-2026-35616) and the Chrome browser (CVE-2026-5281), both added to CISA's KEV catalog. Critical infrastructure also came under fire, with CISA issuing an emergency directive to decommission medical IoT gateways due to the 'Vitals Vapor' exploit, and Australian water facilities thwarting an attack on their control systems.

Filter by Category

New Articles (8)

Updated Articles (4)

📢 Share This Publication

Help others stay informed about cybersecurity threats