Back to Feed

Tag

Threat Intelligence

65 items tagged #threat-intelligence

Articles

Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects

Malicious postinstall hooks discovered across 700+ GitHub repos targeting PHP and Node.js packages via Packagist.

AI Has Taken Over Open Source

AI-generated packages surge exponentially on npm, reshaping open source production and consumption.

5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours

Megalodon attack compromises 5,561 GitHub repos via malicious CI workflows in six hours.

Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds

Deleted Google API keys remain active for up to 23 minutes due to eventual consistency delays.

GitHub links repo breach to TanStack npm supply-chain attack

GitHub breach of 3,800 repos linked to malicious Nx Console extension in TanStack npm supply-chain attack

🚨🇮🇩 Perumda Tirta Musi Palembang Alleged Customer Database Sale: 437K+ Utility Records Adverti...

Perumda Tirta Musi Palembang utility database with 437K+ customer records allegedly for sale.

First VPN Service — Website Seized by Law Enforcement

1VPNS VPN service website seized by joint international law enforcement action.

Uruguay DNIC allegedly leaked: 5.8M citizen database records exposed

Uruguay DNIC citizen database with 5.8M records allegedly leaked on underground forum

🚨🇺🇾 Uruguay DNIC allegedly leaked: 5.8M citizen database records exposed https://t.co/n2zsCshQ1r

Uruguay's DNIC citizen database with 5.8M records allegedly leaked online.

GitHub Breach: TeamPCP Steals 3,800 Repositories via VS Code Extension

TeamPCP steals 3,800 GitHub repositories via poisoned VS Code extension, demands $95K

Verizon DBIR: AI Helped Hackers Exploit Vulnerabilities in 31% of Recent Breaches

Verizon DBIR 2026: AI exploited software vulnerabilities in 31% of breaches, compressing exploit timelines from months

Banana RAT Malware in Fake Invoices Hits Customers at 16 Brazilian Banks

Banana RAT malware targets 16 Brazilian banks via fake invoices, stealing data with QR code fraud.

GitHub confirms they were compromised after an employee device involving a poisoned VS Code exten...

GitHub confirms employee device compromise via malicious VS Code extension.

GitHub investigates internal repositories breach claimed by TeamPCP

GitHub investigates breach of ~4,000 internal repositories claimed by TeamPCP hacker group

ShinyHunters Goes After Cybersecurity Firm Warning Victims Not to Pay Ransoms https://t.co/FUrgx...

ShinyHunters targets cybersecurity firm that advises ransomware victims against paying.

New Shai-Hulud malware wave compromises 600 npm packages

Shai-Hulud campaign injects malware into 600+ npm packages to steal developer credentials.

7-Eleven confirms data breach claimed by the ShinyHunters gang

7-Eleven confirms cyberattack by ShinyHunters gang that stole 600K+ records from Salesforce systems.

INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers

INTERPOL Operation Ramz arrests 200+ individuals, seizes 53 malware and phishing servers across MENA region.

SHub macOS infostealer variant spoofs Apple security updates

SHub macOS infostealer variant 'Reaper' spoofs Apple security updates via AppleScript to steal data and install

Leaked Shai-Hulud malware fuels new npm infostealer campaign

Leaked Shai-Hulud malware deployed in four malicious npm packages by threat actor.

Grafana says stolen GitHub token let hackers steal codebase

Grafana Labs' GitHub environment breached via stolen token; source code stolen by CoinbaseCartel extortion gang.

First Shai-Hulud Worm Clones Emerge

Shai-Hulud worm clones emerge days after source code release on GitHub.

Grafana Confirms Breach After Hackers Claim They Stole Data

Grafana confirms data breach via compromised GitHub token; source code stolen by Coinbase Cartel.

Exploitation of Critical NGINX Vulnerability Begins

Active in-the-wild exploitation of critical NGINX heap buffer overflow CVE-2026-42945 begins days after patch release.

Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026

Pwn2Own Berlin 2026 awards $1.3M for 47 zero-day exploits across enterprise and AI products.

Hackers Earn $1.3 Million at Pwn2Own Berlin 2026

Pwn2Own Berlin 2026 awards $1.3M for 47 zero-day exploits across Windows, Linux, VMware, Nvidia, and AI products.

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

Tycoon2FA phishing kit adds device-code attacks to hijack Microsoft 365 accounts via Trustifi URLs.

Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases

Scammers mail fake Ledger phishing letters with QR codes to steal crypto wallet seed phrases from Italian users.

Grafana Says It Rejected Ransom Demand After Source Code Theft

Grafana confirms source code theft via compromised GitHub token; rejects ransom demand.

RDP Stealer with Windows Defender Bypass https://t.co/4jNuZxUJMZ

RDP stealer malware discovered with Windows Defender evasion capability.

Another Windows zero day released by Nightmare Eclipse (sort of) It turns out Microsoft just str...

Microsoft failed to properly patch 2020 Windows CVE, allowing Nightmare Eclipse exploitation.

‼️🇪🇸 Ícaro Cloud Allegedly Breached: Firewall Configs, VPN Keys, TLS Certificates, and Internal...

Ícaro Cloud breach exposes firewall configs, VPN keys, and TLS certs for 20 Spanish firms.

Hackers Use PyInstaller and AMSI Patching to Deliver XWorm RAT v7.4

Hackers deploy XWorm RAT v7.4 via PyInstaller with AMSI patching to bypass Windows security.

Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution

REMUS infostealer malware evolves into MaaS platform targeting session tokens and password managers.

OpenAI Hit by TanStack Supply Chain Attack

OpenAI hit by TanStack supply chain attack; credentials stolen from code repositories.

CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions

CalPhishing campaign exploits Outlook invites and device code phishing to steal M365 tokens and bypass MFA.

TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code

TeamPCP releases Shai-Hulud worm source code on GitHub, fueling supply chain attacks with monetary rewards.

Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools

Unit 42 analyzes AD CS exploitation techniques including template misconfigurations and shadow credential misuse.

TeamPCP hackers advertise Mistral AI code repos for sale

TeamPCP hackers demand $25K for stolen Mistral AI source code via supply-chain compromise.

‼️🇺🇸⚡ Lightning AI allegedly breached: internal codebase and project files exposed from the cre...

Lightning AI allegedly breached; internal codebase and PyTorch Lightning project files exposed.

🚨 Nightmare Eclipse just released another vulnerability called MiniPlasma GitHub: https://t.co/...

Nightmare Eclipse releases MiniPlasma vulnerability (CVE-2020-17103) in Windows Cloud Files Mini Filter Driver

Maximum Severity Cisco SD-WAN Bug Exploited in the Wild

Cisco SD-WAN maximum severity vulnerability exploited in active attacks.

CVE-2026-20182: Critical Cisco SD-WAN Auth Bypass Under Active Exploitation

Cisco SD-WAN Controller/Manager CVE-2026-20182 critical auth bypass under active exploitation

‼️CVE-2026-20182: Critical Cisco SD-WAN Auth Bypass Under Active Exploitation https://t.co/mm9rX...

CVE-2026-20182 critical Cisco SD-WAN authentication bypass under active exploitation

Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks

Cisco patches critical SD-WAN Controller authentication bypass (CVE-2026-20182) exploited in active zero-day attacks.

1/2‼️🇧🇷 Nuvidio allegedly breached: 40K files including KYC records, biometrics, private keys,...

Brazilian identity verification provider Nuvidio allegedly breached; 40K files with KYC, biometrics, private keys

Burkina Faso Passport & ID Records Allegedly Leaked: 50K+ Scanned Identity Documents Exposed Online

Threat actor advertises 50K+ leaked Burkina Faso passports and national ID cards online.

‼️🇧🇫 Burkina Faso Passport & ID Records Allegedly Leaked: 50K+ Scanned Identity Documents E...

50,000+ scanned Burkina Faso passport and ID records allegedly leaked online.

OpenAI confirms security breach in TanStack supply chain attack

OpenAI confirms two employee devices breached in TanStack supply chain attack via Mini Shai-Hulud malware.

1/2‼️🇬🇹 Guatemalan Ministry of Finance allegedly breached: 130,000 RGAE registrations and 235,0...

Guatemalan Ministry of Finance allegedly breached; 130K RGAE registrations and 235K PDFs exposed via IDOR.

Events