threat-intel Phishing Attack Volume Down 20%, but Risk Still Rising The volume of phishing attacks has decreased by 20% across multiple industries, despite a shift towards more sophisticated attacks utilizing AI. Threat actors are prioritizing targeted campaigns with higher conversion ra… Dark Reading · Jun 12, 2026 High CAESAUphishingaicloud
supply-chain The ‘Miasma’ worm source code briefly leaked on GitHub The source code for the Miasma credential-stealing worm framework, previously linked to supply-chain attacks targeting open-source ecosystems, was briefly leaked on GitHub. This leak, mirroring the earlier Shai-Hulud wor… BleepingComputer · Jun 10, 2026 High USsupply chaincredential theftopen source
threat-intel Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility This article from Palo Alto Unit 42 details how attackers are exploiting cloud logging services, specifically AWS CloudTrail and Google Cloud Logging, to evade detection and gain continuous visibility into target environ… Palo Alto Unit 42 · Jun 9, 2026 High cloud securityloggingevasion
supply-chain IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks A sophisticated supply chain attack targeting the npm ecosystem has resulted in the deployment of both IronWorm, a Rust-based information stealer with self-replicating capabilities, and a new variant of the Miasma worm.… The Hacker News · Jun 5, 2026 High USsupply-chainnpmrust
threat-intel PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network PCPJack, a threat actor initially linked to TeamPCP, has established a covert SMTP email relay network by hijacking 230 cloud servers across AWS, Google Cloud, and Azure. The operation involved converting business server… The Hacker News · Jun 5, 2026 High USUKDEsmtp relaycloud proxyc2
threat-intel With Complex Cloud Integrations, Small Errors Lead to Major Compromises This article details a near-breach at Zapier, a popular low-code automation service, highlighting the risks associated with complex cloud integrations and inadequate security practices. Researchers at Token Security disc… Dark Reading · May 29, 2026 High UScloud-securitysecretspermissions
threat-intel Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security This Dark Reading article reflects on the evolution of the cybersecurity industry over the past 20 years, highlighting a shift from traditional perimeter defenses focused on antivirus and firewalls to a more complex land… Dark Reading · May 27, 2026 Medium cybersecuritycloud securityiot security
threat-intel Lawmakers Demand Answers as CISA Tries to Contain Data Leak A significant security breach occurred involving the intentional publication of sensitive CISA data, including AWS GovCloud keys and internal system credentials, by a CISA contractor. The exposed data, hosted on a public… Krebs on Security · May 22, 2026 High USgithubcredentialleak
data-breach CISA Security Leak A contractor for CISA inadvertently exposed sensitive credentials and internal system details through a public GitHub repository. This included access to highly privileged AWS GovCloud accounts and information about CISA… Schneier on Security · May 22, 2026 Critical USgithubawscredentials
supply-chain GitHub links repo breach to TanStack npm supply-chain attack A supply-chain attack targeting GitHub originated with a malicious version of the Nx Console VS Code extension, facilitated by the TeamPCP threat group. The attack compromised over 3,800 internal repositories and extende… BleepingComputer · May 21, 2026 High USsupply-chainnpmvscode
threat-intel GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension GitHub experienced a breach of its internal repositories due to a compromised employee device utilizing a malicious VS Code extension, the Nx Console. The attack, orchestrated by TeamPCP, leveraged a supply chain vulnera… The Hacker News · May 21, 2026 High CVE-2026-45321CVE-2026-48027supply chainvscodeopen source
threat-intel GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos GitHub experienced a breach originating from an employee device compromised by a poisoned Microsoft Visual Studio Code extension. The attacker exfiltrated over 3,800 internal repositories, facilitated by the threat actor… The Hacker News · May 20, 2026 High USILIRsupply chaincredential theftinfostealer
threat-intel CISA Exposes Secrets, Credentials in 'Private' Repo A public GitHub repository belonging to the Cybersecurity and Infrastructure Security Agency (CISA) was discovered containing 844MB of sensitive data, including plain-text passwords, authentication tokens, and cloud infr… Dark Reading · May 19, 2026 High USsecretsgithubcloud
threat-intel CISA Admin Leaked AWS GovCloud Keys on Github A contractor for CISA inadvertently exposed highly privileged AWS GovCloud credentials and internal CISA system information via a public GitHub repository. The repository contained plaintext passwords, cloud keys, and lo… Krebs on Security · May 18, 2026 High USgithubawscredentials
phishing “Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security This Securelist article details a concerning trend of attackers leveraging Amazon Simple Email Service (Amazon SES) for phishing campaigns. Attackers exploit legitimate access keys to send convincing emails that bypass s… Securelist · May 4, 2026 High USphishingawsamazon ses