threat-intel Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories A security researcher discovered a flaw in Anthropic's Claude Code GitHub Action that allowed attackers to take over vulnerable public repositories by exploiting a permissive trigger check and prompt injection techniques… The Hacker News · Jun 4, 2026 High prompt-injectiongithub-actionsai-security
supply-chain Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets A malicious NuGet package, 'Sicoob.Sdk,' disguised as a C# SDK for Sicoob, Brazil's largest cooperative financial system, was discovered to be stealing client IDs and PFX certificates. This allowed unauthorized access to… The Hacker News · May 29, 2026 High BRsupply-chaincredentialsbanking
threat-intel MyPillow listed on ransomware gang’s leak site, but denies it has been breached The Play ransomware gang claims to have stolen data from MyPillow, a US pillow manufacturer, and threatens to release it publicly. MyPillow denies the breach and claims it doesn't hold sensitive data internally, relying… Graham Cluley · May 28, 2026 High USransomwaredata-breachthird-party
threat-intel ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More This Hacker News bulletin details several recent cyber threats, including a massive C2 infrastructure footprint discovered in the Middle East dominated by IoT botnets, a privilege escalation vulnerability in Azure Backup… The Hacker News · May 28, 2026 High CVE-2026-8398SAROUSc2supply-chainprivilege-escalation
malware Malicious npm Package Stole Files From Claude AI User Directory via GitHub A malicious npm package, "mouse5212-super-formatter," was discovered that leveraged GitHub to steal files from Anthropic's Claude AI user directory. The package masqueraded as a legitimate archive deployment sync utility… The Hacker News · May 27, 2026 High USnpmgithubai
supply-chain Glassworm botnet disrupted after resilient C2 infrastructure takedown The Glassworm botnet, a supply-chain threat targeting developers, has been significantly disrupted following a coordinated takedown of its resilient command-and-control infrastructure. The botnet utilized a complex archi… BleepingComputer · May 27, 2026 High supply-chainbotnetc2
supply-chain Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos A six-hour malware campaign, dubbed 'Megalodon,' targeted over 5,500 GitHub repositories, injecting malicious commits containing credential-stealing payloads. The campaign, orchestrated by an unknown threat actor potenti… Dark Reading · May 26, 2026 High githubsupply-chainmalware
threat-intel The Hackers Behind Shai-Hulud: Lucky or Skilled? The cybercrime group TeamPCP has been identified as a primary driver behind the Shai-Hulud worm, causing significant damage to the open-source ecosystem through exploiting vulnerabilities like React2Shell and misconfigur… Dark Reading · May 26, 2026 High USsupply-chainopen-sourcedeveloper-tooling
threat-intel MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries The MuddyWater hacking group, backed by Iran, has been conducting a sophisticated espionage campaign targeting organizations across nine countries on four continents during Q1 2026. The campaign utilizes DLL side-loading… The Hacker News · May 26, 2026 High KRSAAEdll-side-loadingcredential-stealingreconnaissance
threat-intel ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos This week’s security news highlights a significant GitHub breach orchestrated by TeamPCP, stemming from a compromised developer’s device and leveraging vulnerabilities exposed by the TanStack supply chain attack. Simulta… The Hacker News · May 25, 2026 High CVE-2026-46333CVE-2026-41091CVE-2026-45498USGBsupply-chainlinuxgithub
supply-chain TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO A sophisticated supply chain attack, dubbed TrapDoor, is spreading credential-stealing malware across npm, PyPI, and Crates.io, targeting developers in the crypto, DeFi, Solana, and AI communities. The attack utilizes a… The Hacker News · May 25, 2026 High USsupply-chaincredential-stealingdeveloper-workflow
supply-chain npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks npm has implemented a new staged publishing feature to bolster the security of its software supply chain, addressing concerns about malicious package releases. This system requires maintainers to verify releases with a t… The Hacker News · May 23, 2026 High supply-chain2fasecurity
supply-chain Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware A coordinated supply chain attack targeting the Packagist repository has compromised eight PHP packages, inserting malicious code into their package.json files. The attack leveraged GitHub Releases URLs to deploy a Linux… The Hacker News · May 23, 2026 High supply-chainphpcomposer
supply-chain Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer A sophisticated supply chain attack targeting Laravel-Lang PHP packages has been identified, involving the mass modification of Git tags to inject a cross-platform credential-stealing framework. The attacker leveraged co… The Hacker News · May 23, 2026 Critical USsupply-chaincredential-stealingphp
threat-intel In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking This week’s cybersecurity news highlights several incidents, including Iranian hackers targeting US gas station tank monitor systems, a CISA contractor exposing sensitive credentials, a Huawei router vulnerability causin… SecurityWeek · May 22, 2026 High CVE-2024-9643CVE-2026-45401USLUiotcritical infrastructuresupply-chain
supply-chain GitHub links repo breach to TanStack npm supply-chain attack A supply-chain attack targeting GitHub originated with a malicious version of the Nx Console VS Code extension, facilitated by the TeamPCP threat group. The attack compromised over 3,800 internal repositories and extende… BleepingComputer · May 21, 2026 High USsupply-chainnpmvscode
threat-intel GitHub Confirms Breach, 4K Internal Repos Stolen GitHub experienced a data breach where approximately 4,000 internal code repositories were stolen by the threat actor TeamPCP. The breach originated from a poisoned VS Code extension compromising an employee's device, an… Dark Reading · May 20, 2026 High vscodeopen sourcedeveloper tooling
supply-chain Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem This article highlights a significant shift in cyberattack tactics, moving away from traditional phishing and towards a supply chain attack leveraging AI-generated lookalike domains and compromised third-party scripts. T… The Hacker News · May 20, 2026 Critical USsupply-chainbrowserai
threat-intel GitHub investigates internal repositories breach claimed by TeamPCP GitHub is investigating a breach of its internal repositories following a claim by the TeamPCP hacker group, who gained access to approximately 4,000 private code repositories. The incident highlights a vulnerability wit… BleepingComputer · May 20, 2026 High supply-chaingithubmalware
threat-intel What Will Make AI BOMs Real? This article discusses the growing momentum behind the adoption of AI Bills of Materials (AIBOMs) within the cybersecurity industry. Driven by standards development, commercial tool releases, regulatory pressure, and evo… Dark Reading · May 19, 2026 Medium USEUaisbommodel-training