
Weekly Axis Of Easy #462
Last Week’s Quote was: “Who looks outside, dreams; who looks inside, awakes.” — was by Carl Jung. Several got the right answer, but Cheryl got it right first! Congrats!
This Week’s Quote: “Future shock is the shattering stress and disorientation that we induce in individuals by subjecting them to too much change in too short a time.” By ???
THE RULES: No searching up the answer, must be posted at the bottom of this blog post, in the comments section.
The Prize: First person to post the correct answer gets their next domain or hosting renewal on us.
This is your easyDNS #AxisOfEasy Briefing for the week of August 3rd, 2026. Our Technology Correspondent Joann L Barnes and easyCEO Mark E. Jeftovic send out a short briefing on the state of the ‘net and how it affects your business, security and privacy.
To Listen/watch this podcast edition with commentary and insight from Joey and Len the Lengend click here.
In this issue:
- The npm Worm That Ate The JavaScript Supply Chain
- 75 Million Revolut Records For Sale, Revolut Says Nothing To See Here
- Your “Private” Claude Chats Were On Google The Whole Time
- Cisco’s Firewall Manager Had Hard-Coded Credentials, Guess What Happened
- VMware’s vCenter Has A “Skip Authentication Entirely” Button Now
- Brussels Starts Actually Enforcing The AI Act This Week
Elsewhere Online:
easyHermes is here…
We’re pleased to announce the expansion of our agentic hosting platform with the rollout of easyHermes, the latest agent-enabled VPS appliance on the easyNode.ai platform.

Now you can answer the “openclaw vs Hermes” question for yourself, or run them both.
Check it out today, and get your first month on us when you use promo code AXISOFEASY
The npm Worm That Ate The JavaScript Supply Chain
On August 4th an attacker took over the GitHub account of the maintainer behind keyv, a caching library with roughly 127 million weekly downloads, and used it to push a credential-stealing worm directly to main. New releases went out for keyv, cacheable, flat-cache, file-entry-cache and half a dozen siblings from the same account — all signed with valid npm provenance, courtesy of GitHub Actions, because the attacker owned the account doing the signing. The payload adds a preinstall hook that pulls down the Bun runtime and runs an obfuscated stealer after your credentials, tokens, AWS keys, SSH keys and crypto wallets — and, because 2026, it also drops execution hooks for Claude and VS Code. By the following afternoon trackers had counted anywhere from 400 to over 2,200 affected package artifacts and a combined 2 billion-plus monthly installs caught in the blast radius.
This is the third time this exact toolkit — same filenames, same lineage, traced back to April’s PyTorch Lightning compromise on PyPI and May’s @antv incident on npm — has been run through a different ecosystem in the space of months. “Provenance” was supposed to mean something. It still does, technically: it proves the malware really was published by the account it claims to be from. That account was just owned at the time. If you run Node anywhere near production, this week’s homework is: turn off install scripts (npm config set ignore-scripts true), rotate every credential that touched a CI runner since August 4th, and stop assuming a green checkmark means clean code.
More via Wiz Research
275 Million Revolut Records For Sale, Revolut Says Nothing To See Here
Late in July a seller on a cybercrime forum listed a database allegedly containing 75 million Revolut customer records, split across five CSV files — cards, credentials, devices, users, accounts, plus a fifth with bank account numbers and SWIFT codes. Researchers who examined the sample found partial card details, bcrypt/argon2id-hashed passwords, names, emails and phone numbers, with the newest records dating to roughly May 2025. The asking price was $500, which is either a very good deal or a very good tell. Revolut disputes that any of this reflects a fresh breach of its systems, noting the listing came with no verifiable record count and no technical evidence to back the claim.
A suspiciously cheap price tag for a claimed 75 million rows usually means aggregated or recycled data rather than a brand-new intrusion — but “not new” doesn’t mean “not useful” to a phisher. Contact details plus partial card data is exactly the combination that makes a fake “verify your Revolut account” text convincing. If you bank with them: enable MFA if you haven’t, and treat any unsolicited password-reset message as hostile until proven otherwise.
More via Cybernews
Your “Private” Claude Chats Were On Google The Whole Time
Late July, Reddit users discovered that Claude conversations and Artifacts shared via “anyone with a link” were being merrily crawled and indexed by Google, Bing and DuckDuckGo. What turned up: clinical trial data with patient names, ages and treatment dates, internal company documents, employee reviews, and at least one crypto-wallet key. Anthropic updated its robots.txt and scrubbed the results by July 28th, and pointed out that shared links are public by design — which is technically true and also exactly the problem. ChatGPT and Grok have each had their own version of this moment already this year.
“Share” defaulting to “public and crawlable” is not a bug, it’s a feature nobody read the fine print on. If you’ve ever hit share on a chat or an Artifact containing anything you wouldn’t want indexed — a resume, a contract, a client dashboard — go check your settings and unpublish it, because the assumption that a link is only findable if someone gives it to you has now failed publicly, twice, for the same product. Treat every “shareable link” like a billboard, not a locked drawer.
More via Cybernews
Cisco’s Firewall Manager Had Hard-Coded Credentials, Guess What Happened
CVE-2026-20316 sounds boring on paper — a CVSS of only 5.3 — right up until you learn it’s a set of static, hard-coded credentials baked into the web interface of Cisco’s Secure Firewall Management Center. Cisco confirmed active exploitation, CISA slapped it into the Known Exploited Vulnerabilities catalog and told federal agencies to patch by August 1st. Hotfixes cover FMC 7.0 through 10.0; Cloud-Delivered FMC, ASA and Threat Defense software are unaffected.
A “low” score doesn’t mean low risk when the bug is functionally a backdoor an attacker can chain into something worse — which is exactly why Cisco rated it High Impact despite the number. There’s no workaround, only the hotfix. Check your logs for references to /var/tmp/license.tmp, and rotate every credential, key and certificate on the appliance whether or not you find evidence of a visitor.
More via SecurityWeek
VMware’s vCenter Has A “Skip Authentication Entirely” Button Now
Broadcom’s VMSA-2026-0006 covers five vulnerabilities across vCenter, ESX, Workstation, Fusion and various Cloud Foundation products, two of them rated a maximum-adjacent CVSS 9.8. CVE-2026-59309 is an authentication bypass in the VMware Directory Service — a network-adjacent attacker with no credentials at all can walk straight into the vCenter management plane. Its companion, CVE-2026-59310, is a directory-traversal flaw in the vCenter Syslog server that leads to remote code execution. Neither has a workaround. The patch is the only fix.
vCenter has landed on CISA’s KEV list ten separate times before, so treat “no known exploitation yet” as a countdown, not a reprieve. Patch on an emergency basis, and while you’re in there, confirm vCenter isn’t reachable from anywhere the internet can see — management traffic belongs behind a VPN or a dedicated, firewalled management VLAN, not on the open network because it was convenient in 2019.
More via The Hacker News
Brussels Starts Actually Enforcing The AI Act This Week
August 2nd was the day the EU AI Office and national regulators started enforcing Article 50 transparency obligations — disclose when someone’s talking to an AI, and attach provenance signals like watermarks to synthetic content. Fines for this tranche run up to €15 million or 3% of global turnover; the headline €35 million / 7% number is reserved for the small set of outright-prohibited practices. An AI Omnibus package has pushed the heaviest high-risk system requirements out to December 2027, but the transparency and general-purpose-AI obligations are live now, alongside a December 2026 ban on AI-generated non-consensual sexual content and CSAM.
The regulatory picture here is genuinely messy — different obligations landing on different clocks, with more amendments proposed than passed — but “we’ll get to compliance eventually” stops being a defensible posture the moment enforcement actually begins, which is now. If your product touches EU users and generates or serves synthetic content, this is the week to check your disclosure labeling, not the week after your first inquiry letter arrives.
More via Help Net Security
Also on AxisOfEasy this week:
Nothing new from the Curated Posts feed since last issue — our contributors were apparently taking the week off, unlike the npm worm. Back to normal next week.
Elsewhere Online:
Check Point SmartConsole Zero-Day Let Attackers Grab Admin With A Stolen Token
Read: https://www.securityweek.com/new-check-point-zero-day-vulnerability-exploited-in-the-wild/
Fastjson’s Zero-Day Has No Patch Coming, Ever
Read: https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
Russian Spies Used A Zimbra Zero-Day To Read Five Months Of Someone’s Email
Read: https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
Malware Can Now Steal Your Google-Synced Passkeys, No Fingerprint Required
Read: https://www.malwarebytes.com/blog/news/2026/08/googles-synchronized-passkeys-can-be-stolen-in-pass-ta-key-attacks
Previously on #AxisOfEasy
If you missed the previous issues, they can be read online here:
-
-
-
-
-
-
-
-
-
-
-
-
- July 31, 2026: #AxisOfEasy 461: In First-of-Its-Kind Case, Atlanta Man Charged Over Phone’s Self-Wiping Passcode
- July 24th, 2026: AI Agent Breaches Hugging Face Infrastructure In Unprecedented Security Incident
- July 17th, 2026: UK Protects Teens From Midnight Scrolling, As Long As Teens Consent To Being Protected
- July 10th, 2026: Ottawa Weighed Suing Citizens Over “Misleading” Social Media Posts
- July 3rd, 2026: Canada’s New Cyber Law Lets A Minister Cut Your Phone Off — No Warrant Required
-
-
-
-
-
-
-
-
-
-
-

Alan Toffler. Is a good but long read