Back

Cybersecurity

vulnerability

The Auth Check Is the Attack Surface

A pre-authentication SQL injection in LiteLLM's API key verification path gave attackers read/write access to every credential the proxy manages — and the 401 it returned made each successful query look like a failed login.

supply-chain

A Self-Replicating Worm Just Poisoned 170 npm and PyPI Packages

On May 11, 2026, a worm called Mini Shai-Hulud compromised 84 malicious package versions across the TanStack ecosystem in six minutes — without stealing a single credential. Here's what happened, how it spread, and what to do if your environment was affected.

vulnerability

When the Firewall Is the Vulnerability

CVE-2026-0300 gives an unauthenticated attacker root-level code execution on PAN-OS firewalls — no credentials, no interaction required. Here's how the Captive Portal became the entry point, what the attackers did next, and why owning the perimeter is a different category of problem.

supply-chain

Signed, Delivered, Compromised

DAEMON Tools installers downloaded from the official website between April 8 and May 5 were backdoored — signed with the developer's own certificate, distributed through the legitimate domain, and undetected for nearly a month. Here's how the trust model that code signing is built on became the attack's primary weapon.

threat-intelligence

Phishing Emails Used to Be Easy to Spot. AI Changed That.

82% of phishing emails now use AI. They have perfect grammar, know your name, and reference real details about your life. The old advice — look for typos — no longer works. Here's what does.

incident

The Breach Nobody Talked About

Data breaches hit a record high in 2025. Most of them never made the news. Here's what happened, why it matters, and what to actually do about it.

MECHANICS

How OIDC Trusted Publishing Works — and Where Mini Shai-Hulud Found the Gap

OIDC trusted publishing was designed to eliminate the long-lived credentials that supply chain attackers steal. Mini Shai-Hulud bypassed it anyway. Here's how the mechanism works, what it actually guarantees, and how three individually reasonable configuration decisions combined to let an attacker publish under TanStack's own verified identity.

reports

Claude Code Source Leak and Active Malware Campaign

Technical record of the March 31, 2026 Anthropic npm packaging failure, the concurrent axios supply chain compromise, and the Vidar/GhostSocks campaign that followed.