Weekly review

ThreatNoir Weekend Brief — May 17

2026-05-17Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — May 17, 2026

The cybersecurity landscape continues to evolve with threats spanning multiple vectors, from physical social engineering targeting cryptocurrency users to supply chain compromises affecting major technology companies. Today's review highlights the persistent ingenuity of threat actors in exploiting both human psychology and software vulnerabilities.

Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases

A sophisticated phishing campaign is targeting cryptocurrency users through traditional mail delivery. Scammers are sending fake Ledger phishing letters to users in Italy, embedding QR codes designed to trick wallet holders into revealing their seed phrases. This represents a notable shift in attack methodology, combining physical mail with digital exploitation techniques to compromise cryptocurrency assets. Source: Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases

Grafana Says It Rejected Ransom Demand After Source Code Theft

Grafana has disclosed that attackers stole its source code following unauthorized access to a GitHub token. The company confirmed that hackers obtained the code repository but emphasized that no customer data or systems were compromised in the incident. Grafana rejected the ransom demand associated with the theft, prioritizing transparency with its user base over negotiation with the threat actors. Source: Grafana Says It Rejected Ransom Demand After Source Code Theft

OpenAI Hit by TanStack Supply Chain Attack

OpenAI has fallen victim to a supply chain attack involving the TanStack library, resulting in the compromise of two employee devices. Credential material was stolen from OpenAI code repositories during the incident, raising concerns about the security of sensitive development infrastructure. The attack underscores the vulnerability of major technology companies to supply chain exploitation, even when security measures are in place. Source: OpenAI Hit by TanStack Supply Chain Attack

Another Windows Zero Day Released by Nightmare Eclipse

A previously unpatched Windows vulnerability has been disclosed, revealing that Microsoft failed to properly address a CVE from 2020. The oversight left systems exposed to exploitation despite the company's patch cycle, demonstrating the challenges in comprehensive vulnerability remediation across legacy issues. Source: Another Windows zero day released by Nightmare Eclipse (sort of)

Today's threat landscape reflects the multifaceted nature of modern cybersecurity challenges, ranging from targeted physical attacks on cryptocurrency users to systemic vulnerabilities in widely deployed software. Organizations must remain vigilant across both digital and physical attack vectors while maintaining rigorous patch management practices.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).