threat-intelligence
A poisoned VS Code extension on a single developer device gave TeamPCP access to 3,800 of GitHub's internal repositories. Grafana fell the same week via a different vector in the same campaign.
May 28, 2026
·
4 min read
threat-intelligence
CrowdStrike, Google, and the Shadowserver Foundation simultaneously severed all four C2 channels of the GlassWorm botnet on May 26 — ending a persistent campaign that infiltrated npm, PyPI, VS Code extensions, and GitHub repositories since early 2025.
May 28, 2026
·
4 min read
vulnerability
A pre-authentication SQL injection in LiteLLM's API key verification path gave attackers read/write access to every credential the proxy manages — and the 401 it returned made each successful query look like a failed login.
May 24, 2026
·
5 min read
vulnerability
A pre-authentication buffer overflow in Windows Netlogon puts every unpatched domain controller one crafted packet away from full domain compromise.
May 22, 2026
·
9 min read
supply-chain
On May 11, 2026, a worm called Mini Shai-Hulud compromised 84 malicious package versions across the TanStack ecosystem in six minutes — without stealing a single credential. Here's what happened, how it spread, and what to do if your environment was affected.
May 14, 2026
·
7 min read
vulnerability
CVE-2026-0300 gives an unauthenticated attacker root-level code execution on PAN-OS firewalls — no credentials, no interaction required. Here's how the Captive Portal became the entry point, what the attackers did next, and why owning the perimeter is a different category of problem.
May 11, 2026
·
6 min read
supply-chain
DAEMON Tools installers downloaded from the official website between April 8 and May 5 were backdoored — signed with the developer's own certificate, distributed through the legitimate domain, and undetected for nearly a month. Here's how the trust model that code signing is built on became the attack's primary weapon.
May 11, 2026
·
6 min read
vulnerability
A logic bug buried in the Linux kernel's cryptographic subsystem since 2017 now lets any unprivileged user become root — reliably, silently, and in 732 bytes of Python. Here is exactly how it works, why containers make it worse, and what to do about it.
May 7, 2026
·
13 min read
supply-chain
On March 31, 2026, Anthropic accidentally published the complete source code of Claude Code to the public npm registry. It was the second time in 13 months. Within hours, criminals were using the leak as bait.
April 3, 2026
·
8 min read
threat-intelligence
MFA secures your login. It does not secure your session. Here is exactly how attackers exploit that gap — and what it takes to close it.
March 31, 2026
·
7 min read
threat-intelligence
82% of phishing emails now use AI. They have perfect grammar, know your name, and reference real details about your life. The old advice — look for typos — no longer works. Here's what does.
March 27, 2026
·
7 min read
threat-intelligence
The biggest threat to your accounts right now isn't a massive new hack. It's infostealer malware — silent software that harvests your passwords in seconds and sells them for $10 on the dark web.
March 17, 2026
·
8 min read
incident
Data breaches hit a record high in 2025. Most of them never made the news. Here's what happened, why it matters, and what to actually do about it.
March 16, 2026
·
7 min read
MECHANICS
An expired maintainer email domain and a standard npm password reset handed attackers publish rights to a package with 822,000 weekly downloads — no npm breach required.
May 19, 2026
·
9 min read
MECHANICS
OIDC trusted publishing was designed to eliminate the long-lived credentials that supply chain attackers steal. Mini Shai-Hulud bypassed it anyway. Here's how the mechanism works, what it actually guarantees, and how three individually reasonable configuration decisions combined to let an attacker publish under TanStack's own verified identity.
May 15, 2026
·
14 min read
reports
Technical record of the March 31, 2026 Anthropic npm packaging failure, the concurrent axios supply chain compromise, and the Vidar/GhostSocks campaign that followed.
April 3, 2026
·
12 min read