threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
supply-chain The ‘Miasma’ worm source code briefly leaked on GitHub The source code for the Miasma credential-stealing worm framework, previously linked to supply-chain attacks targeting open-source ecosystems, was briefly leaked on GitHub. This leak, mirroring the earlier Shai-Hulud wor… BleepingComputer · Jun 10, 2026 High USsupply chaincredential theftopen source
supply-chain Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories A sophisticated supply chain attack, orchestrated by the Miasma worm (a variant of Shai-Hulud), targeted 73 Microsoft GitHub repositories, primarily within the Azure organization. The attack, initially discovered through… Dark Reading · Jun 9, 2026 High supply chaingithubazure
supply-chain GitHub disables Microsoft repos pushing password-stealing malware Microsoft repositories on GitHub were temporarily disabled on June 5th due to concerns about distributing malware, specifically linked to the ongoing Miasma/Shai-Hulud supply-chain campaign. The incident involved the com… BleepingComputer · Jun 9, 2026 High USsupply-chain attackgithubmalware
threat-intel Everybody Is Vibe Coding But Nobody Told the Security Team This article discusses the emerging security challenges posed by "vibe coding," a new approach to software development heavily reliant on AI-assisted tools. Rapid, AI-driven application development, particularly using pl… SecurityWeek · Jun 8, 2026 High UKaivibe-codingshadow-ai
supply-chain Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack A sophisticated supply chain attack, dubbed Miasma, has compromised 73 Microsoft GitHub repositories, including several within the Azure and Microsoft organizations. The attack leverages a re-compromised PyPI package, du… The Hacker News · Jun 6, 2026 High supply chaingithubopen source
supply-chain IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks A sophisticated supply chain attack targeting the npm ecosystem has resulted in the deployment of both IronWorm, a Rust-based information stealer with self-replicating capabilities, and a new variant of the Miasma worm.… The Hacker News · Jun 5, 2026 High USsupply-chainnpmrust
threat-intel Attackers Use AI to Automate EDR Evasion Testing Attackers are leveraging artificial intelligence to automate the process of testing and developing malware designed to evade endpoint detection and response (EDR) systems. Sophos researchers discovered a sophisticated re… Dark Reading · Jun 3, 2026 High aiedrred teaming
supply-chain ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems The ‘SymJack’ attack leverages AI coding agents as a supply chain delivery mechanism, exploiting developer trust in automation to inject malicious code into CI pipelines. Attackers gain control by compromising coding age… SecurityWeek · May 27, 2026 High USaicoding agentssupply chain