supply-chain Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more Two men from Western Australia have been charged in connection with TeamPCP, a cybercriminal group responsible for a global supply-chain hacking campaign that targeted over 1000 organizations, including OpenAI and the European Commission. The group used a self-propagating worm, Shai-Hulud, to steal data and credentials… Graham Cluley · 2d ago High AUsupply chainopen sourcemalware
threat-intel Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning Cybersecurity researchers at McAfee Labs have identified a campaign where malicious websites disguised as legitimate Minecraft clients are distributing the Weedhack malware. These sites, leveraging SEO poisoning and mimi… The Hacker News · 5d ago Medium seo poisoningmalwareminecraft
threat-intel Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub Mozilla has revoked a signing key for Firefox after an unencrypted copy of the key was accidentally uploaded to GitHub. This significantly increases the risk of malicious actors creating fake Firefox installations. The i… The Register · Aug 11, 2026 High key-managementfirefoxvulnerability
threat-intel Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development North Korea's Kimsuky hacking group is building an offline AI infrastructure to bolster its phishing attacks and automate malware development. Security firm Genians discovered this setup, finding tools like Ollama, GPT4A… The Hacker News · Aug 10, 2026 High KRaiphishingnorth korea
threat-intel ChainDrop: Inside a Self-Propagating npm Worm A self-propagating npm worm, nicknamed ChainDrop, has infected over 400 packages, collectively downloaded hundreds of millions of times weekly. Developed by a threat actor, the worm steals sensitive data including cloud… Palo Alto Unit 42 · Aug 6, 2026 High npmgithubcredential theft
vulnerability Multiples vulnérabilités dans KeyCloak (06 août 2026) Multiple vulnerabilities have been discovered in Keycloak, potentially allowing for privilege escalation, denial of service attacks, and data compromise. These vulnerabilities affect versions 26.6.x through 26.6.5, 26.7.… CERT-FR · Aug 6, 2026 High CVE-2026-15572CVE-2026-15573CVE-2026-16071keycloakvulnerabilitysecurity
threat-intel Flaws in Google APK for Python Unlock Agent-to-Agent Attack Researchers at Pillar Security discovered a critical vulnerability in Google's Agent Development Kit (ADK) for Python, allowing a low-privileged AI agent to trigger actions by a more privileged agent via prompt injection… Dark Reading · Aug 5, 2026 High prompt injectionai agentssupply chain
threat-intel Leaked n8n API Tokens Exposed Live Instances to Credential Theft GitGuardian researchers discovered that 321 n8n instances were accepting leaked API tokens in public GitHub commits, exposing a significant security risk. They demonstrated four attack techniques that could be used to a… The Hacker News · Aug 5, 2026 High CVE-2025-68613apicredentialssecurity
supply-chain Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack A sophisticated supply chain attack, dubbed ChainDrop, has infected over 2,200 malicious versions of 440 NPM packages, resulting in over 500 million weekly downloads. The attack began with a compromised GitHub account an… SecurityWeek · Aug 5, 2026 High supply chainnpmgithub
vulnerability Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering A vulnerability in Google’s Agent Development Kit (ADK) for Python allowed an attacker to manipulate low-privileged agents to gain access to high-privilege capabilities, potentially leading to pull request poisoning and… SecurityWeek · Aug 4, 2026 High agent-to-agentpull request poisoningremote code execution
threat-intel HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm A previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family named Matryoshka were used in a spear-phishing attack targeting a law firm. The attack involved a multi-stage process… The Hacker News · Jul 31, 2026 High spear-phishinggorust
supply-chain New GitHub, PyPI Policies Boost Supply Chain Security GitHub and PyPI are implementing new policies to bolster supply chain security by delaying the adoption of newly released package versions and preventing the poisoning of older, stable releases. These measures aim to red… SecurityWeek · Jul 27, 2026 Medium KPsupply chainpackage managementsecurity
threat-intel GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption GitHub has implemented a three-day cooldown period for Dependabot to mitigate the risk of malicious packages being rapidly adopted by downstream projects. This new feature aims to slow down the spread of poisoned package… The Hacker News · Jul 27, 2026 Medium supply-chainpackage-managementdependency-updates
threat-intel Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers A sophisticated campaign leveraging compromised GitHub repositories is targeting cPanel and WHM servers. Attackers are using malicious GitHub Actions workflows to launch GitHub-hosted runners that scan for vulnerable ser… The Hacker News · Jul 23, 2026 High CVE-2026-41940githubmalwarecpanel
threat-intel GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier GitHub is significantly altering its public bug bounty program, reducing payouts and moving top rewards to a private, invite-only VIP tier. Public payouts will be fixed, with a maximum of $10,000 for critical findings, d… The Hacker News · Jul 22, 2026 High bug bountyvulnerabilityai
threat-intel FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware A sophisticated campaign dubbed FakeGit has leveraged nearly 7,600 malicious GitHub repositories to spread SmartLoader malware, utilizing AI agents to discover these fake repositories and execute the attack. The campaign… The Hacker News · Jul 20, 2026 High aigithubmalware
vulnerability Vulnérabilité dans Traefik (16 juillet 2026) A security vulnerability has been identified in Traefik versions 3.7.x, allowing attackers to bypass security policies. Users are advised to apply the latest security patch released by Traefik to mitigate this risk. CERT-FR · Jul 16, 2026 Medium traefikvulnerabilitysecurity
supply-chain The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) The npm ecosystem experienced a critical inflection point in September 2025 with the emergence of the Shai-Hulud worm, marking a shift from nuisance attacks to a high-consequence threat landscape. Since then, Unit 42 has… Palo Alto Unit 42 · Jul 15, 2026 High NLsupply chainnpmgithub
threat-intel Lessons Learned from CISA’s Recent GitHub Leak A CISA contractor inadvertently published a massive trove of sensitive credentials, including AWS GovCloud keys and plaintext passwords, in a public GitHub repository for nearly six months before CISA was notified. The a… Krebs on Security · Jul 13, 2026 High secretsgithubaws
threat-intel Ghost Accounts Abuse GitHub API in Mass Recon Campaign Threat actors are systematically abusing GitHub's public API using a network of dormant ghost accounts to map organizations, repositories, and user accounts – a reconnaissance tactic that occasionally leads to data exfil… SecurityWeek · Jul 11, 2026 Medium CHINreconnaissancegithubapi