threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
malware Over 400 Arch Linux packages compromised to push rootkit, infostealer Over 400 Arch Linux packages within the AUR repository have been compromised, distributing a Linux rootkit and infostealer malware designed to steal developer credentials and access tokens. The attack involved a maliciou… BleepingComputer · Jun 12, 2026 High USrootkitinfostealeraur
supply-chain Early Warning Signs of Supply-Chain Attacks Live in the Dark Web This BleepingComputer article highlights the increasing threat of supply-chain attacks, which target the tools and vendors organizations rely on. The article details how early warning signs of these attacks often appear… BleepingComputer · Jun 12, 2026 High GEsupply chaingithubcredentials
supply-chain The ‘Miasma’ worm source code briefly leaked on GitHub The source code for the Miasma credential-stealing worm framework, previously linked to supply-chain attacks targeting open-source ecosystems, was briefly leaked on GitHub. This leak, mirroring the earlier Shai-Hulud wor… BleepingComputer · Jun 10, 2026 High USsupply chaincredential theftopen source
supply-chain Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories A sophisticated supply chain attack, orchestrated by the Miasma worm (a variant of Shai-Hulud), targeted 73 Microsoft GitHub repositories, primarily within the Azure organization. The attack, initially discovered through… Dark Reading · Jun 9, 2026 High supply chaingithubazure
supply-chain Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues Microsoft is investigating a recent security incident involving the compromise of 73 open-source GitHub repositories as part of the ongoing "Miasma" supply chain attack. The attackers, utilizing a technique involving inf… The Hacker News · Jun 9, 2026 High supply chainopen sourceinformation stealer
supply-chain GitHub disables Microsoft repos pushing password-stealing malware Microsoft repositories on GitHub were temporarily disabled on June 5th due to concerns about distributing malware, specifically linked to the ongoing Miasma/Shai-Hulud supply-chain campaign. The incident involved the com… BleepingComputer · Jun 9, 2026 High USsupply-chain attackgithubmalware
supply-chain Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer A new supply chain attack, dubbed Hades, is leveraging the Miasma campaign to compromise 37 PyPI packages, including those used in bioinformatics and computational biology. The attack utilizes a malicious setup.pth file… The Hacker News · Jun 9, 2026 High RUsupply-chainpythoncredential-stealing
supply-chain New Shai-Hulud attack trojanizes 19 science-focused PyPI packages A new supply-chain attack, dubbed Shai-Hulud, has compromised 19 popular Python packages hosted on the PyPI, distributing a trojan designed to steal developer secrets. The malware leverages a chain of execution to downlo… BleepingComputer · Jun 8, 2026 High supply-chainpythonsecrets
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th) This report details the ongoing TeamPCP supply chain campaign, which has recently seen increased activity and expanded impact. CISA has formally acknowledged and addressed the campaign, adding vulnerabilities to its Know… SANS Internet Storm Center · Jun 8, 2026 High CVE-2026-45321CVE-2026-48027CVE-2026-8398USsupply chainnpmgithub
threat-intel ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More This week’s security news highlights a series of attacks and vulnerabilities, including a supply chain attack targeting Microsoft GitHub repositories via the Miasma Worm, a zero-day exploit in Android, and ongoing cyberc… The Hacker News · Jun 8, 2026 High CVE-2025-48595CVE-2026-28318CVE-2026-39210CHUSGEsupply-chainzero-daycybercrime
other Hands on with Intelligent Terminal, an AI-powered Windows Terminal Microsoft has released Intelligent Terminal, an open-source extension for Windows Terminal that integrates AI assistance directly into the terminal environment. The tool leverages various AI models, such as GitHub Copilo… BleepingComputer · Jun 7, 2026 Low aiwindowsterminal
supply-chain Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack A sophisticated supply chain attack, dubbed Miasma, has compromised 73 Microsoft GitHub repositories, including several within the Azure and Microsoft organizations. The attack leverages a re-compromised PyPI package, du… The Hacker News · Jun 6, 2026 High supply chaingithubopen source
supply-chain IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks A sophisticated supply chain attack targeting the npm ecosystem has resulted in the deployment of both IronWorm, a Rust-based information stealer with self-replicating capabilities, and a new variant of the Miasma worm.… The Hacker News · Jun 5, 2026 High USsupply-chainnpmrust
supply-chain Rust-Written IronWorm Hits NPM Supply Chain A new Rust-written malware campaign, dubbed "IronWorm," is targeting developers through compromised npm publishing workflows, stealing credentials like API keys and cloud credentials to spread across the software supply… Dark Reading · Jun 4, 2026 High USsupply chaincredential theftebpf
threat-intel 4 Critical Threats Where Attackers Have the Advantage This Dark Reading article highlights four critical cybersecurity threats identified by Gartner: deepfakes, software supply chain risks, prompt injections, and AI application compromises. Gartner analysts contend that cur… Dark Reading · Jun 4, 2026 High deepfakesai securitysupply chain
threat-intel Reporting from Vegas: Networking, AI, and good boys This Cisco Talos Threat Source newsletter highlights the ongoing challenges of managing data at scale in an AI-driven world, particularly during large technology conferences like Cisco Live. It details Talos’ expansion o… Cisco Talos · Jun 4, 2026 High USRUaithreat huntingc2
supply-chain New IronWorm malware hits 36 packages in npm supply-chain attack A new supply-chain attack leveraging the IronWorm malware has compromised 36 npm packages, targeting developers and CI environments with infostealer capabilities. The malware utilizes stolen credentials and a sophisticat… BleepingComputer · Jun 4, 2026 High supply chainnpmrust
threat-intel Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories A security researcher discovered a flaw in Anthropic's Claude Code GitHub Action that allowed attackers to take over vulnerable public repositories by exploiting a permissive trigger check and prompt injection techniques… The Hacker News · Jun 4, 2026 High prompt-injectiongithub-actionsai-security
threat-intel Offroad Emerges From Stealth With $7 Million to Tackle Enterprise Identity Risk Offroad, a new cybersecurity firm, has launched with $7 million in funding to address the growing risk of identity-related vulnerabilities in enterprise environments. The company utilizes AI-powered agents to proactively… SecurityWeek · Jun 4, 2026 Medium USILISoauthidentity riskai