Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories
The cybersecurity landscape is evolving with increasingly sophisticated threats, including publicly leaked supply chain attack tools, premium remote access trojans with browser-cloning capabilities, and demonstrated vulnerabilities in AI agents that can be exploited to extract credentials. The professionalization of cybercrime infrastructure, with mule networks operating as polished SaaS-like serv
AIGitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
GitHub is implementing breaking changes in npm version 12 that will disable install scripts by default as a security measure against supply chain attacks. This change specifically targets malicious actors who exploit npm lifecycle hooks to execute harmful code during the package installation process.
AIMiasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
A supply chain attack dubbed Miasma has infiltrated 73 Microsoft repositories through a compromised GitHub account. This incident represents a continuation of previous Miasmi attacks targeting Microsoft infrastructure last month, highlighting ongoing vulnerabilities in software supply chain security.
AIHades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
A new supply chain attack called Hades has compromised 19 packages in the Python Package Index (PyPI) registry, deploying 37 malicious wheel artifacts designed to automatically execute credential-stealing malware. This attack represents an evolution of the Miasma campaign, using *-setup.pth files for automatic execution and demonstrating increasingly sophisticated targeting of specific development
AI'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud
A new malware campaign dubbed 'Hades' has targeted the Python Package Index (PyPI), compromising 37 wheel distributions and 19 code packages. This attack represents an evolution of the Shai-Hulud threat, demonstrating the ongoing sophistication of software supply chain attacks targeting open-source repositories.
AI⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
A turbulent week in cybersecurity saw multiple significant incidents including Instagram account compromises, an Android zero-day vulnerability, and a GitHub worm spreading through repositories. Despite advanced threats, attackers continue succeeding with basic tactics like chatbot manipulation, leaked bot tokens, and prolonged email account compromise campaigns that operate undetected for months.
AIVS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
Microsoft is implementing a two-hour delay for automatic extension updates in Visual Studio Code as a security measure against supply chain attacks. The delay provides a window to detect and prevent malicious code from being automatically distributed to users through compromised extensions.
AIMiasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack
Microsoft's GitHub repositories have been compromised in a significant supply chain attack involving the Miasma self-replicating worm. The attack affected 73 repositories across four Microsoft GitHub organizations including Azure, Azure-Samples, Microsoft, and MicrosoftDocs, prompting GitHub to disable access to the impacted repositories.
AIIronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
The npm ecosystem has been targeted by multiple supply chain attacks involving over 50 compromised packages. Threat actors deployed IronWorm, a Rust-based information stealer that uses eBPF kernel rootkit techniques to hide while harvesting credentials, and a new variant of the Miasma worm capable of self-propagation across developer environments.
AIRust-Written IronWorm Hits NPM Supply Chain
A new malware campaign called IronWorm, written in Rust, has been discovered targeting the NPM package ecosystem. The malware focuses on compromising developer credentials and leveraging them to spread laterally across the software supply chain, posing significant risks to enterprise development environments.
AIClaude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories
A critical vulnerability was discovered in Anthropic's Claude Code GitHub Action that allowed attackers to hijack public repositories through a single malicious GitHub issue. The flaw was particularly severe because Anthropic's own action repository used the vulnerable workflow, potentially enabling supply chain attacks affecting all downstream projects using the action.
AI⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
This week saw a surge in critical security incidents including authentication vulnerabilities, actively exploited patches, and compromised development tools. AI-powered attack tools are lowering the barrier to entry for threat actors, while OAuth phishing campaigns and supply chain attacks through poisoned developer resources continue to proliferate. The security landscape reflects both persistent
AIOpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
A malicious supply chain attack targeting developers has been discovered in the codexui-android npm package, which masquerades as a legitimate remote web UI for OpenAI Codex. The compromised package, still available on npm and GitHub, has attracted over 29,000 weekly downloads and is designed to steal OpenAI Codex authentication tokens from unsuspecting developers.
AIAs Global Powers Explore Humanoid Robots, Cyber-Risk Looms
Nation states are competing for leadership in the emerging humanoid robotics and embodied AI market, creating new cybersecurity challenges. As these technologies advance and supply chains develop, organizations face evolving cyber-risks that require proactive security strategies. The convergence of physical robotics and AI systems introduces unprecedented vulnerabilities that enterprise security t
AIMalicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets
Security researchers have identified a malicious NuGet package impersonating a legitimate SDK for Sicoob, a major Brazilian financial institution, designed to steal client credentials and PFX certificates. Versions 2.0.0 through 2.0.4 of the fraudulent 'Sicoob.Sdk' package contain data exfiltration capabilities targeting sensitive authentication materials. This discovery highlights the growing thr
AIStealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
Cybersecurity researchers have identified malicious code in three versions of the popular npm package node-ipc (versions 9.1.6, 9.2.3, and 12.0.1), which contains stealer backdoor functionality targeting developer credentials and secrets. The compromised package poses significant supply chain security risks to enterprise development environments that rely on Node.js dependencies.
