Related Threat Clusters
-
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
On July 1, 2026, security firm SlowMist identified a fake trading bot on GitHub designed to spread malware targeting Polymarket users and DeFi developers. The bot, named 'polymarket-arbitrage-bot', was promoted as a…
2 articles · Updated July 1, 2026 -
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
11 articles · Updated May 20, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026 -
AI-Generated Security Patches Fail 74% of the Time, Study Reveals
A recent study by 1Password's Off-by-1 Labs found that AI-generated patches for software vulnerabilities succeeded only 26% of the time. The research analyzed 6,080 patches created by AI models ChatGPT 5.5 and Claude…
13 articles · Updated August 6, 2026 -
GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
149 articles · Updated May 20, 2026 -
New 'PleaseFix' Vulnerabilities Threaten Agentic Browsers with Widespread Attacks
Security researchers have identified a new class of vulnerabilities called 'PleaseFix' that severely compromise agentic browsers. These vulnerabilities allow attackers to exploit the browsers using simple English…
11 articles · Updated July 29, 2026 -
RubyGems Implements Dependency Cooldowns to Combat Supply Chain Attacks
RubyGems has introduced dependency cooldowns in Bundler to mitigate supply chain attacks that exploit newly published packages. This feature delays the installation of packages until they have been available for a…
2 articles · Updated June 8, 2026 -
Comet AI Browser Vulnerable to Phishing via Agentic Blabbering Exploit
Perplexity's Comet AI browser has been compromised through a novel attack method called 'Agentic Blabbering', which exploits the browser's interaction with AI services. Analysts from Guardio reported that this phishing…
2 articles · Updated March 13, 2026 -
Oracle Red Bull Racing Enhances Security with IAM Tools Amid F1 Challenges
Oracle Red Bull Racing has implemented identity and access management (IAM) tools from 1Password to streamline operations and enhance security in the face of stringent Formula 1 regulations. The team has experienced…
2 articles · Updated May 1, 2026 -
Zenity Labs Reveals PleaseFix Vulnerabilities in Perplexity Comet and Other Browsers
Zenity Labs disclosed a family of critical vulnerabilities known as PleaseFix, affecting agentic browsers including Perplexity Comet. These vulnerabilities enable zero-click agent hijacking, local file exfiltration, and…
18 articles · Updated March 3, 2026
Recent Intelligence Reports
- AI failed to properly patch software flaws 74% of the time, 1Password's study warns — Zdnet · August 6, 2026
- Zenity Labs Discloses Pleasefix Perplexedagent Vulnerability — zenity.io · July 28, 2026
- DeFi devs, Polymarket trading bot users targeted in fresh info — Cryptopolitan · July 1, 2026
- Christian Schneider — christian-schneider.net · June 8, 2026
- Endor Labs — www.endorlabs.com · June 4, 2026
- Mini Shai — Itnews.Au · May 20, 2026
- GitHub confirms 3,800 internal repos stolen through poisoned VS Code extension as supply ... — Venturebeat · May 20, 2026
- Hackers Infiltrate GitHub by Compromising Employee Device — Uk.Pcmag · May 20, 2026