The week in one line
Supply chains cracked while AI-powered threats emerged from research labs.
What happened
Cybercriminals weaponized software development infrastructure at unprecedented scale while governments suffered coordinated data breaches. Critical infrastructure operators discovered widespread exposure of industrial control systems to active exploitation campaigns.
- Miasma and IronWorm malware infected 100+ legitimate npm packages and GitHub repositories including Microsoft Azure
- Chinese APT UNC5221 maintained 18-month persistence in Microsoft 365 environments using three new malware families
- Over 900 US gas station tank gauge systems discovered exposed to internet with active exploitation underway
- Cisco disclosed 7th exploited SD-WAN zero-day of 2026 with no available patches
- Government breaches in Ecuador, Spain, Mexico affected 13.5M+ citizen records
- ShinyHunters breached DentaQuest exposing 2.6M dental patient records after failed extortion
Why it matters for defenders and leaders
Attackers demonstrated ability to compromise trusted software distribution channels while exploiting gaps in cloud security architectures and critical infrastructure monitoring. The emergence of AI-assisted discovery tools is accelerating vulnerability identification faster than patching capabilities.
- Supply chain attacks now target GitHub repositories directly, bypassing traditional package registry controls
- Cloud-native extortion campaigns eliminate need for traditional ransomware deployment and encryption
- Critical infrastructure systems lack basic network segmentation and expose legacy protocols to internet
- AI agents discovered 21 zero-day vulnerabilities in a single library, indicating coming tsunami of findings
What to do this week
- Audit npm and GitHub integrations for anomalous commits and unexpected package modifications
- Implement Conditional Access policies for Microsoft 365 with device compliance requirements
- Inventory internet-facing industrial control systems and implement network segmentation
- Patch SolarWinds Serv-U CVE-2026-28318 and WordPress Everest Forms Pro CVE-2026-3300
- Review VPN appliance configurations for Cisco SD-WAN and Palo Alto GlobalProtect vulnerabilities