supply-chain Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer A new supply chain attack, dubbed Hades, is leveraging the Miasma campaign to compromise 37 PyPI packages, including those used in bioinformatics and computational biology. The attack utilizes a malicious setup.pth file… The Hacker News · Jun 9, 2026 High RUsupply-chainpythoncredential-stealing
ransomware LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE A critical command injection vulnerability (CVE-2026-42271) in BerriAI’s LiteLLM has been actively exploited in the wild. The flaw, combined with a separate Starlette vulnerability (CVE-2026-48710), allows for unauthenti… The Hacker News · Jun 9, 2026 Critical CVE-2026-42271CVE-2026-48710CVE-2026-42208command injectionremote code executionunauthenticated
supply-chain New Shai-Hulud attack trojanizes 19 science-focused PyPI packages A new supply-chain attack, dubbed Shai-Hulud, has compromised 19 popular Python packages hosted on the PyPI, distributing a trojan designed to steal developer secrets. The malware leverages a chain of execution to downlo… BleepingComputer · Jun 8, 2026 High supply-chainpythonsecrets
supply-chain 'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud A new wave of attacks, dubbed the 'Hades' campaign, has targeted the Python Package Index (PyPI) with a variant of the Shai-Hulud worm. This campaign involved compromising 37 PyPI wheels and 19 code packages, utilizing a… Dark Reading · Jun 8, 2026 High USsupply-chainpythonopen-source
supply-chain Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack A sophisticated supply chain attack, dubbed Miasma, has compromised 73 Microsoft GitHub repositories, including several within the Azure and Microsoft organizations. The attack leverages a re-compromised PyPI package, du… The Hacker News · Jun 6, 2026 High supply chaingithubopen source
threat-intel Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting This article details Cisco Talos' approach to threat hunting, which differs from traditional alert-based detection. Instead of waiting for alerts, Talos analysts formulate hypotheses about adversary behavior based on tel… Cisco Talos · Jun 4, 2026 High USthreat huntingaicorrelation
threat-intel Attackers Use AI to Automate EDR Evasion Testing Attackers are leveraging artificial intelligence to automate the process of testing and developing malware designed to evade endpoint detection and response (EDR) systems. Sophos researchers discovered a sophisticated re… Dark Reading · Jun 3, 2026 High aiedrred teaming
supply-chain TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO A sophisticated supply chain attack, dubbed TrapDoor, is spreading credential-stealing malware across npm, PyPI, and Crates.io, targeting developers in the crypto, DeFi, Solana, and AI communities. The attack utilizes a… The Hacker News · May 25, 2026 High USsupply-chaincredential-stealingdeveloper-workflow
threat-intel GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos GitHub experienced a breach originating from an employee device compromised by a poisoned Microsoft Visual Studio Code extension. The attacker exfiltrated over 3,800 internal repositories, facilitated by the threat actor… The Hacker News · May 20, 2026 High USILIRsupply chaincredential theftinfostealer
vulnerability Max-severity flaw in ChromaDB for AI apps allows server hijacking A critical vulnerability (CVE-2026-45829) has been identified in the ChromaDB project, allowing unauthenticated attackers to execute arbitrary code on exposed servers. This flaw stems from a misplacement of authenticatio… BleepingComputer · May 19, 2026 Critical CVE-2026-45829apipythonfastapi
supply-chain OceanLotus suspected of using PyPI to deliver ZiChatBot malware Securelist researchers identified a PyPI supply chain attack orchestrated by OceanLotus, utilizing seemingly legitimate Python packages (uuid32-utils, colorinal, and termncolor) to deliver the previously unknown malware… Securelist · May 6, 2026 High UKsupply-chainpythonpypi