
Security Advisory: npm axios Supply Chain Compromise
A recent npm supply chain compromise tied to axios has turned a routine dependency update into a vulnerability. On March 31, 2026, attackers used a
Important security information, news, and advisories regarding anything relevant to the life science, startup, or IT space.

A recent npm supply chain compromise tied to axios has turned a routine dependency update into a vulnerability. On March 31, 2026, attackers used a

A critical vulnerability (CVE-2025-55182) in React Server Components allows unauthenticated attackers to execute code on affected servers. Companies using React 19 with Server Components are urged to patch their systems promptly. This risk poses severe threats to sensitive data and scientific integrity, necessitating immediate action and enhanced security measures.

This security advisory is for companies with software development teams. If your teams use the public npm registry or GitHub (especially GitHub Actions), please read

If your company is wondering whether to try new AI‑powered, “agentic” web browsers like ChatGPT Atlas, Perplexity Comet, or Dia, here’s the short answer: don’t, not yet. Due to security risks, our current recommendation is for companies to avoid these tools until further notice.