Department of Know: Axios malware, TeamPCP campaign, New Storm infostealer

Cybersecurity Headlines31mApril 6, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Department of Know: Axios malware, TeamPCP campaign, New Storm infostealer” inside PodZeus.

AI-Generated Summary

In this episode of Cybersecurity Headlines, host Sarah Lane leads a deep dive into several high-impact security stories from the past week, featuring insights from CISOs Adam Palmer of First Hawaiian Bank and Jack Kufal of Michigan Medicine. The discussion centers on the leak of Anthropic’s Claude source code via a public NPM registry, which both guests agree highlights growing risks in AI governance and insider threats. Apple’s new macOS Terminal warning system for malicious commands is seen as a minor but useful step in user awareness, while the emergence of AI-powered malware like DeepLoad signals a shift toward more efficient, polymorphic attacks. The revival of Iran’s pay2key ransomware operation and its collaboration with criminal groups underscores the accelerating convergence of nation-state tactics and cybercrime, increasing baseline threat levels for all enterprises. The hijacking of the Axios NPM library by UNC 1069 and the Team PCP supply chain campaign reveal systemic vulnerabilities in open source dependencies, with attackers exploiting stolen credentials within hours. Both CISOs emphasize that resilience now hinges on rapid response, continuous monitoring, and rethinking third-party risk management. The episode concludes with a call for CISOs to evolve from purely defensive roles to strategic digital risk leaders who focus on observability, governance, and speed in response. Key takeaways include: 1) AI adoption demands parallel governance maturity to protect intellectual property and infrastructure; 2) Supply chain attacks are no longer slow-moving—they can lead to cloud exploitation within a day; 3) Third-party risk must be assessed dynamically, not just during contracting; 4) Security maturity is defined by response speed, not just prevention; 5) Open source risk stems not from open source itself, but from unverified trust and market concentration; 6) CISOs must shift from 'blocking and tackling' to leading digital risk conversations around AI and data flows; 7) Resilience is now measured in hours, not weeks; 8) The line between nation-state and criminal cyber operations is blurring, making all organizations potential collateral damage.

Key Takeaways
1

AI adoption must be matched with governance maturity to protect intellectual property and infrastructure.

2

Supply chain attacks now enable cloud exploitation within hours, demanding rapid response capabilities.

3

Third-party risk must be assessed continuously, not just during contract negotiations.

4

Security maturity is defined by response speed, not just prevention.

5

Open source risk stems from unverified trust and market concentration, not open source itself.

…and 3 more takeaways available in PodZeus

Chapters
0:00
5 min

Opening: CISO Priorities & Episode Overview

Host Sarah Lane introduces the episode with guest CISOs Adam Palmer and Jack Kufal, setting the stage for a deep dive into recent cybersecurity threats. They discuss their current priorities—business acceleration and Microsoft Fabric/Purview adoption—before launching into the week’s top stories.

5:00
5 min

Claude Source Code Leak: Governance vs. Noise

This is a K-N-O-W for me and my team because it highlights for me the growing gap between AI adoption and governance maturity.

Highlight
10:00
5 min

Apple’s Terminal Security Warning: Incremental or Strategic?

Apple’s new macOS Tahoe 26.4 feature warns users about dangerous commands in Terminal. Both CISOs agree it’s a useful awareness tool but not a strategic shift—users remain the last-mile vulnerability.

15:00
5 min

DeepLoad Malware: AI-Powered Attack Evolution

AI hasn't changed attacker intent, but it's changing attacker efficiency.

Highlight
20:00
5 min

Iran’s Pay2Key Revival: Nation-State & Crime Convergence

You're not being targeted because you're important. You're being targeted because you're connected and that's important.

Highlight
High-Impact Quotes
Cybersecurity is no longer about just preventing bad things from happening. It's about operating safely in an environment where compromise is inevitable.
Adam Palmer28:47
Viral: 95.0
The reason here is that open source isn't the risk. It's unverified trust is the risk.
Adam Palmer20:16
Viral: 92.0
You're not being targeted because you're important. You're being targeted because you're connected and that's important.
Adam Palmer12:40
Viral: 90.0
Speakers

Host

Sarah Lane

Guests

Adam PalmerJack Kufal
Topics Discussed
Supply Chain Security92%AI Security Governance90%Rapid Breach Response90%Nation-State Cyber Operations88%Open Source Software Risk87%Third-Party Risk Management85%Digital Risk Leadership85%Behavioral Threat Detection78%
People & Brands

Adam Palmer

person

28xPositive

Jack Kufal

person

25xPositive

NPM

other

14xNegative

Sarah Lane

person

12xNeutral

Anthropic

organization

11xNeutral

Claude

product

8xNeutral

Apple

organization

7xNeutral

Axios

product

6xNegative

Vanta

organization

6xPositive

Team PCP

other

5xNegative

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Department of Know: Axios malware, TeamPCP campaign, New Storm infostealer” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime