supply-chain Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more Two men from Western Australia have been charged in connection with TeamPCP, a cybercriminal group responsible for a global supply-chain hacking campaign that targeted over 1000 organizations, including OpenAI and the European Commission. The group used a self-propagating worm, Shai-Hulud, to steal data and credentials… Graham Cluley · 2d ago High AUsupply chainopen sourcemalware
supply-chain Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations A supply-chain attack linked to Aqua Security's Trivy scanner has resulted in the release of two malicious LiteLLM packages containing credential-stealing code. CloudSEK identified over 2,500 organizations potentially ex… The Hacker News · Aug 12, 2026 High CVE-2026-33634USEUsupply chaincredential theftpypi
threat-intel Cyber actualités ZATAZ de la semaine du 27 juillet au 2 août 2026 This week’s ZATAZ news focuses heavily on data breaches and security incidents, primarily targeting French organizations and involving a wide range of sensitive information. Numerous data leaks are being reported, includ… ZATAZ · Jul 31, 2026 High FRdata breachcybersecurityhacktivism
threat-intel Mercor face aux affirmations d’un pirate A hacker claiming to be linked to Lapsus$ is alleging a major data breach at Mercor, a US startup specializing in AI data and intelligence. The hacker claims to possess 1.150GB of user data, including biometric informati… ZATAZ · Jul 30, 2026 High N/data breachbiometricslapsus$
supply-chain GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say A supply-chain worm, dubbed Shai-Hulud, is exploiting design flaws in GitHub to infect hundreds of software packages and developer accounts worldwide. The vulnerabilities, initially flagged by Deep Specter Research, were… The Record · Jun 16, 2026 High GBFRsupply chainvulnerabilitygithub
supply-chain Red Hat removes tainted packages after software pipeline compromise Red Hat removed numerous software packages from its distribution pipeline after a compromised GitHub account was used to distribute credential-stealing malware. The attack, utilizing a variant of the Mini Shai-Hulud worm… The Record · Jun 2, 2026 High NOUKsupply chaingithubmalware