⤷ Title: ShadowLink Exposed: How Your Home Router Became a Puppet for Corporate Supply Chain Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 10:09:12 +0000
════════════════════════
⌗ Tags: #Malware #Asus #CVE_2024_21833 #cybersecurity #GitHub Actions #malware #proxy network #ShadowLink #supply chain attack #TP_Link #Xygeni
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 10:09:12 +0000
════════════════════════
⌗ Tags: #Malware #Asus #CVE_2024_21833 #cybersecurity #GitHub Actions #malware #proxy network #ShadowLink #supply chain attack #TP_Link #Xygeni
Penetration Testing Tools
ShadowLink Exposed: How Your Home Router Became a Puppet for Corporate Supply Chain Attacks
The compromise of a residential router may initially appear as a localized grievance, while the manipulation of code
⤷ Title: TeamPCP Hijacks Checkmarx in Sprawling Supply Chain Strike
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:19:36 +0000
════════════════════════
⌗ Tags: #Malware #Checkmarx #Credential Theft #cybersecurity #docker #GitHub Actions #infosec #Malware Analysis #npm #supply chain attack #TeamPCP #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:19:36 +0000
════════════════════════
⌗ Tags: #Malware #Checkmarx #Credential Theft #cybersecurity #docker #GitHub Actions #infosec #Malware Analysis #npm #supply chain attack #TeamPCP #VS Code
Daily CyberSecurity
TeamPCP Hijacks Checkmarx in Sprawling Supply Chain Strike
Checkmarx Docker images and VS Code extensions hijacked by TeamPCP to siphon cloud secrets and spread via npm. Audit your "Dune" repositories today.
⤷ Title: Supply Chain Sabotage: Bitwarden CLI Compromised in Global “Checkmarx” Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:41:43 +0000
════════════════════════
⌗ Tags: #Malware #Bitwarden #Bitwarden CLI #bw1.js #Checkmarx Campaign #cybersecurity #Dune Malware #GitHub Actions #infosec #malware #secret management #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:41:43 +0000
════════════════════════
⌗ Tags: #Malware #Bitwarden #Bitwarden CLI #bw1.js #Checkmarx Campaign #cybersecurity #Dune Malware #GitHub Actions #infosec #malware #secret management #supply chain attack
Daily CyberSecurity
Supply Chain Sabotage: Bitwarden CLI Compromised in Global "Checkmarx" Campaign
Bitwarden CLI v2026.4.0 compromised in "Dune"-themed supply chain attack. Malware steals cloud secrets and SSH keys. Rotate your credentials immediately.
⤷ Title: Patching the CVSS 10 RCE Hole in Gemini CLI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 03:01:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@google/gemini_cli #AI security #Automation #CI/CD security #CVSS 10 #Gemini CLI #GitHub Actions #infosec #Patch Alert #Prompt injection #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 03:01:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@google/gemini_cli #AI security #Automation #CI/CD security #CVSS 10 #Gemini CLI #GitHub Actions #infosec #Patch Alert #Prompt injection #rce
⤷ Title: The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular “Elementary-Data” Library
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:30:10 +0000
════════════════════════
⌗ Tags: #Malware #2026 Tech News #cloud security #Credential Stealer #Data Engineering #dbt #Docker #Elementary_data #GitHub Actions #GITHUB_TOKEN #PyPI #Python Security #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:30:10 +0000
════════════════════════
⌗ Tags: #Malware #2026 Tech News #cloud security #Credential Stealer #Data Engineering #dbt #Docker #Elementary_data #GitHub Actions #GITHUB_TOKEN #PyPI #Python Security #supply chain attack
Penetration Testing Tools
The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular "Elementary-Data" Library
The ubiquitous Python library elementary-data has emerged as a conduit for the exfiltration of sensitive developer telemetry. The
⤷ Title: Desert Power in the Code: How the “Mini Shai-Hulud” Malware Burrows into SAP’s npm Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 07:44:09 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js #CI/CD Security #CircleCI #cloud security #Credentials Theft #Cyber Security 2026 #GitHub Actions #malware #Mini Shai_Hulud #npm #SAP #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 07:44:09 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js #CI/CD Security #CircleCI #cloud security #Credentials Theft #Cyber Security 2026 #GitHub Actions #malware #Mini Shai_Hulud #npm #SAP #supply chain attack
Information Security News
Desert Power in the Code: How the "Mini Shai-Hulud" Malware Burrows into SAP’s npm Supply Chain
Adversaries have once again targeted the npm supply chain, though this incursion pursued a surgical and perilous objective:
⤷ Title: Supply Chains in the Crosshairs: Scan and Simulate Multi-Stage Attacks with Trajan
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 08:24:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure DevOps #CI/CD Security #DevSecOps #GitHub Actions #GitLab CI #jenkins #JFrog #Pentesting Tools #supply chain attack #Taint Tracking #Trajan #WebAssembly
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 08:24:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure DevOps #CI/CD Security #DevSecOps #GitHub Actions #GitLab CI #jenkins #JFrog #Pentesting Tools #supply chain attack #Taint Tracking #Trajan #WebAssembly
Penetration Testing Tools
Supply Chains in the Crosshairs: Scan and Simulate Multi-Stage Attacks with Trajan
Trajan isn't just a scanner. It maps dependency graphs and uses built-in attack plugins to simulate real-world CI/CD supply chain compromises.
⤷ Title: Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:37:03 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack/react_router #CI/CD security #credential stealer #GitHub Actions #infosec #JavaScript Security #Malware Analysis #npm Security #Socket Threat Research #supply chain attack #TanStack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:37:03 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack/react_router #CI/CD security #credential stealer #GitHub Actions #infosec #JavaScript Security #Malware Analysis #npm Security #Socket Threat Research #supply chain attack #TanStack
Daily CyberSecurity
Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets
Urgent: 84 TanStack npm packages hijacked to harvest GitHub Actions secrets. Over 12M weekly downloads impacted. Audit your CI/CD pipelines and rotate tokens.
⤷ Title: Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
Daily CyberSecurity
Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
Composer CVE-2026-45793 leaks GitHub tokens into CI/CD logs due to a validation error. Update to version 2.9.8 now and audit your GitHub Action logs.
⤷ Title: Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
Penetration Testing Tools
Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
The Mini Shai-Hulud incursion has once again laid siege to the software supply chain. While the initial offensive