- Ledger Phishing CampaignPhysical phishing letters with QR codes targeting Ledger hardware wallet users to harvest recovery seed phrases
ThreatNoir Weekend Brief — May 17
Afternoon Review in IT Security — May 17, 2026
The cybersecurity landscape continues to evolve with threats spanning multiple vectors, from physical social engineering targeting cryptocurrency users to supply chain compromises affecting major technology companies. Today's review highlights the persistent ingenuity of threat actors in exploiting both human psychology and software vulnerabilities.
Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases
A sophisticated phishing campaign is targeting cryptocurrency users through traditional mail delivery. Scammers are sending fake Ledger phishing letters to users in Italy, embedding QR codes designed to trick wallet holders into revealing their seed phrases. This represents a notable shift in attack methodology, combining physical mail with digital exploitation techniques to compromise cryptocurrency assets. Source: Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases
Grafana Says It Rejected Ransom Demand After Source Code Theft
Grafana has disclosed that attackers stole its source code following unauthorized access to a GitHub token. The company confirmed that hackers obtained the code repository but emphasized that no customer data or systems were compromised in the incident. Grafana rejected the ransom demand associated with the theft, prioritizing transparency with its user base over negotiation with the threat actors. Source: Grafana Says It Rejected Ransom Demand After Source Code Theft
OpenAI Hit by TanStack Supply Chain Attack
OpenAI has fallen victim to a supply chain attack involving the TanStack library, resulting in the compromise of two employee devices. Credential material was stolen from OpenAI code repositories during the incident, raising concerns about the security of sensitive development infrastructure. The attack underscores the vulnerability of major technology companies to supply chain exploitation, even when security measures are in place. Source: OpenAI Hit by TanStack Supply Chain Attack
Another Windows Zero Day Released by Nightmare Eclipse
A previously unpatched Windows vulnerability has been disclosed, revealing that Microsoft failed to properly address a CVE from 2020. The oversight left systems exposed to exploitation despite the company's patch cycle, demonstrating the challenges in comprehensive vulnerability remediation across legacy issues. Source: Another Windows zero day released by Nightmare Eclipse (sort of)
Today's threat landscape reflects the multifaceted nature of modern cybersecurity challenges, ranging from targeted physical attacks on cryptocurrency users to systemic vulnerabilities in widely deployed software. Organizations must remain vigilant across both digital and physical attack vectors while maintaining rigorous patch management practices.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Shai-HuludWorm deployed by TeamPCP to infect developer devices in TanStack supply chain attack