supply-chain GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say A supply-chain worm, dubbed Shai-Hulud, is exploiting design flaws in GitHub to infect hundreds of software packages and developer accounts worldwide. The vulnerabilities, initially flagged by Deep Specter Research, were… The Record · Jun 16, 2026 High GBFRsupply chainvulnerabilitygithub
threat-intel Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure The Athena coalition, comprised of numerous tech and fintech firms, has been established to proactively identify and mitigate vulnerabilities in open-source software (OSS) before public disclosure. This initiative addres… SecurityWeek · Jun 16, 2026 High ossvulnerabilityai
threat-intel ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More This week’s cybersecurity recap highlights several active exploits and attacks, including a Chrome 0-day being actively leveraged, a ShinyHunters gang exploiting a PeopleSoft zero-day for lateral movement and data exfilt… The Hacker News · Jun 15, 2026 High CVE-2026-11645CVE-2026-2441CVE-2026-3909UNCHzero-dayphishingsupply-chain
malware Over 400 Arch Linux packages compromised to push rootkit, infostealer Over 400 Arch Linux packages within the AUR repository have been compromised, distributing a Linux rootkit and infostealer malware designed to steal developer credentials and access tokens. The attack involved a maliciou… BleepingComputer · Jun 12, 2026 High USrootkitinfostealeraur
supply-chain The ‘Miasma’ worm source code briefly leaked on GitHub The source code for the Miasma credential-stealing worm framework, previously linked to supply-chain attacks targeting open-source ecosystems, was briefly leaked on GitHub. This leak, mirroring the earlier Shai-Hulud wor… BleepingComputer · Jun 10, 2026 High USsupply chaincredential theftopen source
supply-chain Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks A new wave of Shai-Hulud supply chain attacks has impacted over 471 NPM and PyPI packages, utilizing variants named Miasma and Hades. The attacks, originating from TeamPCP, involve credential harvesting and self-replicat… SecurityWeek · Jun 9, 2026 High supply chainnpmpypi
supply-chain Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer A new supply chain attack, dubbed Hades, is leveraging the Miasma campaign to compromise 37 PyPI packages, including those used in bioinformatics and computational biology. The attack utilizes a malicious setup.pth file… The Hacker News · Jun 9, 2026 High RUsupply-chainpythoncredential-stealing
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th) This report details the ongoing TeamPCP supply chain campaign, which has recently seen increased activity and expanded impact. CISA has formally acknowledged and addressed the campaign, adding vulnerabilities to its Know… SANS Internet Storm Center · Jun 8, 2026 High CVE-2026-45321CVE-2026-48027CVE-2026-8398USsupply chainnpmgithub
supply-chain 'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud A new wave of attacks, dubbed the 'Hades' campaign, has targeted the Python Package Index (PyPI) with a variant of the Shai-Hulud worm. This campaign involved compromising 37 PyPI wheels and 19 code packages, utilizing a… Dark Reading · Jun 8, 2026 High USsupply-chainpythonopen-source
supply-chain Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack A sophisticated supply chain attack, dubbed Miasma, has compromised 73 Microsoft GitHub repositories, including several within the Azure and Microsoft organizations. The attack leverages a re-compromised PyPI package, du… The Hacker News · Jun 6, 2026 High supply chaingithubopen source
supply-chain IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks A sophisticated supply chain attack targeting the npm ecosystem has resulted in the deployment of both IronWorm, a Rust-based information stealer with self-replicating capabilities, and a new variant of the Miasma worm.… The Hacker News · Jun 5, 2026 High USsupply-chainnpmrust
threat-intel OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds This article discusses the launch of CVE Lite CLI, an open-source command-line security scanner developed by Sonu Kapoor to address the challenges of managing vulnerabilities within JavaScript and Typescript projects usi… SecurityWeek · Jun 5, 2026 Medium dependency-scanningvulnerabilityjavascript
supply-chain Rust-Written IronWorm Hits NPM Supply Chain A new Rust-written malware campaign, dubbed "IronWorm," is targeting developers through compromised npm publishing workflows, stealing credentials like API keys and cloud credentials to spread across the software supply… Dark Reading · Jun 4, 2026 High USsupply chaincredential theftebpf
threat-intel 4 Critical Threats Where Attackers Have the Advantage This Dark Reading article highlights four critical cybersecurity threats identified by Gartner: deepfakes, software supply chain risks, prompt injections, and AI application compromises. Gartner analysts contend that cur… Dark Reading · Jun 4, 2026 High deepfakesai securitysupply chain
supply-chain New IronWorm malware hits 36 packages in npm supply-chain attack A new supply-chain attack leveraging the IronWorm malware has compromised 36 npm packages, targeting developers and CI environments with infostealer capabilities. The malware utilizes stolen credentials and a sophisticat… BleepingComputer · Jun 4, 2026 High supply chainnpmrust
supply-chain Red Hat npm packages compromised to steal developer credentials A supply-chain attack targeting Red Hat npm packages resulted in the distribution of a new variant of the Shai-Hulud credential-stealing malware, dubbed 'Miasma'. The attackers compromised a Red Hat employee's GitHub acc… BleepingComputer · Jun 1, 2026 High USsupply chaincredential theftgithub
supply-chain Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm A new supply chain attack, dubbed Miasma, has compromised Red Hat npm packages, utilizing a self-propagating worm to steal credentials and secrets from developer machines. The attack, leveraging techniques similar to the… The Hacker News · Jun 1, 2026 High USsupply chain attackcredential theftgithub actions
threat-intel ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More This Hacker News recap details several ongoing cyber threats, including an active exploitation of a PAN-OS GlobalProtect authentication bypass vulnerability, a critical zero-day vulnerability in the Gogs Git service, and… The Hacker News · Jun 1, 2026 High CVE-2026-0257CVE-2026-8732CVE-2026-27771RUvulnerabilityauthenticationc2
threat-intel In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks This week’s cybersecurity news highlights a range of incidents, including a data breach affecting Trump Mobile customers, ongoing Russian government intrusion into US Treasury systems, and vulnerabilities in popular soft… SecurityWeek · May 29, 2026 High UNCHdata breachsupply chainphishing
threat-intel With Complex Cloud Integrations, Small Errors Lead to Major Compromises This article details a near-breach at Zapier, a popular low-code automation service, highlighting the risks associated with complex cloud integrations and inadequate security practices. Researchers at Token Security disc… Dark Reading · May 29, 2026 High UScloud-securitysecretspermissions