threat-intel Lessons Learned from CISA’s Recent GitHub Leak A CISA contractor inadvertently published a massive trove of sensitive credentials, including AWS GovCloud keys and plaintext passwords, in a public GitHub repository for nearly six months before CISA was notified. The a… Krebs on Security · Jul 13, 2026 High secretsgithubaws
threat-intel Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption Jesse McGraw, once a notorious blackhat hacker known as GhostExodus and leader of the Electronik Tribulation Army (ETA), has undergone a dramatic transformation. Driven by a complex mix of factors including neurodiversit… SecurityWeek · Jul 13, 2026 High neurodiversityred-hatosint
threat-intel The Language of AI Could Change How Humans Speak A joint statement from the Five Eyes intelligence alliance warns of rapidly increasing cyber risks stemming from the accelerating development of AI models. The core concern is that AI, particularly open-source models, is… Schneier on Security · Jul 9, 2026 High aicybersecurityhacking
threat-intel European Organizations Have a Collaboration Security Confidence Gap A recent survey by Wire reveals a significant gap between European organizations' confidence in their collaboration security and the actual practices surrounding sensitive data sharing. Despite high confidence levels, ma… Dark Reading · Jul 9, 2026 Medium shadow itdata governanceaccess control
threat-intel Adding some Automation to the favicon.ico method of Host Recon, (Mon, Jun 29th) This SANS Internet Storm Center article details a technique for host reconnaissance using favicon.ico files. The author demonstrates a workflow to identify hosts by extracting the favicon hash value from a website and qu… SANS Internet Storm Center · Jun 29, 2026 Low CAreconnaissancefaviconshodan
supply-chain Cybersecurity Firms Impacted by Klue Supply Chain Attack A supply chain attack targeting the Klue market intelligence platform resulted in the unauthorized harvesting of customer data from various integrations, including Salesforce and HubSpot. The attack, attributed to a new… SecurityWeek · Jun 19, 2026 High supply-chainoauthcrm
supply-chain Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer A new supply chain attack, dubbed Hades, is leveraging the Miasma campaign to compromise 37 PyPI packages, including those used in bioinformatics and computational biology. The attack utilizes a malicious setup.pth file… The Hacker News · Jun 9, 2026 High RUsupply-chainpythoncredential-stealing
supply-chain 'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud A new wave of attacks, dubbed the 'Hades' campaign, has targeted the Python Package Index (PyPI) with a variant of the Shai-Hulud worm. This campaign involved compromising 37 PyPI wheels and 19 code packages, utilizing a… Dark Reading · Jun 8, 2026 High USsupply-chainpythonopen-source
supply-chain IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks A sophisticated supply chain attack targeting the npm ecosystem has resulted in the deployment of both IronWorm, a Rust-based information stealer with self-replicating capabilities, and a new variant of the Miasma worm.… The Hacker News · Jun 5, 2026 High USsupply-chainnpmrust
threat-intel ISC Stormcast For Wednesday, May 27th, 2026 https://isc.sans.edu/podcastdetail/9946, (Wed, May 27th) The SANS Internet Storm Center's Stormcast for May 27th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The broadcast detailed ongoing campaigns involving phishing attacks… SANS Internet Storm Center · May 27, 2026 Medium phishingmalwareemail
supply-chain Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos A six-hour malware campaign, dubbed 'Megalodon,' targeted over 5,500 GitHub repositories, injecting malicious commits containing credential-stealing payloads. The campaign, orchestrated by an unknown threat actor potenti… Dark Reading · May 26, 2026 High githubsupply-chainmalware
threat-intel ISC Stormcast For Friday, May 22nd, 2026 https://isc.sans.edu/podcastdetail/9942, (Fri, May 22nd) The SANS Internet Storm Center's Stormcast for May 22nd, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 22, 2026 Medium phishingvulnerabilitythreat-intelligence
supply-chain Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials A GitHub Actions workflow, actions-cool/issues-helper, was compromised through an imposter commit attack, allowing threat actors to steal CI/CD credentials from running workflows. The attack leveraged malicious code inje… The Hacker News · May 19, 2026 High USgithubci/cdsupply-chain
supply-chain OceanLotus suspected of using PyPI to deliver ZiChatBot malware Securelist researchers identified a PyPI supply chain attack orchestrated by OceanLotus, utilizing seemingly legitimate Python packages (uuid32-utils, colorinal, and termncolor) to deliver the previously unknown malware… Securelist · May 6, 2026 High UKsupply-chainpythonpypi