threat-intel Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says Cisco research reveals that country-of-origin labels on AI models are misleading because they don't accurately reflect a model's lineage and can mask potentially problematic inherited behaviors. The study highlights a ‘supply chain’ effect, where models can inherit vulnerabilities and biases from upstream models regard… SecurityWeek · 2d ago Medium CHUSaimodel lineageprovenance
supply-chain Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware A sophisticated supply-chain attack leveraging compromised npm packages has delivered a multi-stage botnet loader, Miasma, to numerous developers. The attacker exploited a GitHub Actions release pipeline to inject malici… The Hacker News · Jul 15, 2026 High supply chainnpmgithub actions
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th) The TeamPCP supply chain campaign intensified significantly on May 17th, 2026, marked by the confirmed compromise of a Checkmarx Jenkins plugin and the emergence of a new Mini Shai-Hulud worm. This campaign targeted npm… SANS Internet Storm Center · May 18, 2026 Critical CVE-2026-45321CVE-2025-29927CVE-2025-55182GBILIRsupply-chainnpmpypi