Related Threat Clusters
-
Malicious NuGet Packages Target Chinese Developers, Steal Sensitive Data
Five malicious NuGet packages were discovered targeting developers in the Chinese .NET ecosystem. The packages, published under the account bmrxntfj, impersonate legitimate libraries and have accumulated around 65,000…
3 articles · Updated May 7, 2026 -
JetBrains Cadence Breach: Exploitation of Unpatched TeamCity CVE-2026-63077
Between August 8 and August 24, 2026, attackers exploited CVE-2026-63077, a critical vulnerability in JetBrains TeamCity, to breach the JetBrains Cadence cloud compute service. The attackers accessed sensitive data,…
4 articles · Updated September 6, 2026 -
Microsoft Issues Emergency Patches for Critical ASP.NET Core Vulnerability
On April 21, 2026, Microsoft released an emergency out-of-band update, .NET 10.0.7, to address a critical privilege escalation vulnerability tracked as CVE-2026-40372. This flaw, found in the ASP.NET Core Data…
16 articles · Updated April 22, 2026 -
AI Coding Agents Expand Software Supply Chain Risks
AI coding agents are introducing significant vulnerabilities into the software supply chain by selecting insecure dependencies without human oversight. Research indicates that only 20% of dependency versions recommended…
7 articles · Updated July 27, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026 -
NuGet Typosquatting Attack Rigging Digitain Game Results
A malicious NuGet package named 'Newtonsoftt.Json.Net' was discovered, targeting the Digitain betting platform by rigging game results. The package, which mimicked the legitimate Newtonsoft.Json library, was downloaded…
3 articles · Updated July 22, 2026 -
Malicious NuGet Package Targets Sicoob SDK, Exfiltrates Banking Credentials
A malicious NuGet package named 'Sicoob.Sdk' has been identified, which impersonates an official software development kit for Sicoob, a major Brazilian cooperative financial system. This package, affecting versions…
3 articles · Updated May 29, 2026 -
Malicious NuGet Packages Deploy Windows Surveillance Malware to Gamers
Eleven malicious NuGet packages disguised as game cheats and automation tools have been identified, deploying a Windows payload known as pepesoft.exe. These packages target gaming communities, particularly for titles…
2 articles · Updated July 15, 2026 -
RapidFort Introduces Curated Libraries to Combat Supply Chain Attacks
On June 11, 2026, RapidFort announced the launch of RapidFort Curated Libraries, a catalog of malware-scanned open-source libraries aimed at preventing supply chain malware from infiltrating development pipelines. The…
2 articles · Updated June 11, 2026 -
Chainguard Partners with AWS Security Hub to Enhance Supply Chain Security
On August 4, 2026, Chainguard announced its partnership with AWS Security Hub Extended to provide enhanced supply chain security for AWS customers. This partnership allows users to access Chainguard Libraries, which…
6 articles · Updated August 5, 2026
Recent Intelligence Reports
- Jetbrains Told Everyone To Patch It Didnt Patch Itself — thenewstack.io · September 6, 2026
- GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems — Gbhackers · August 10, 2026
- GitHub Dependabot malware alerts now cover eight ecosystems — Feeds2.Feedburner · August 10, 2026
- Chainguard Libraries — edge.prnewswire.com · August 5, 2026
- State Of Dependency Management 2025 — www.endorlabs.com · July 28, 2026
- Supply Chain Security in the Agentic Era — Augmentcode · July 27, 2026
- Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Game Results — Gbhackers · July 22, 2026
- NuGet typosquat targets Digitain game results — Feeds.Feedburner · July 22, 2026