August 1, 2026
- Arch Linux disabled AUR package adoption to stem a flood of malware being planted in orphaned user-repository packages (BleepingComputer). · Supply Chain
in When the Attacker Is a Model: AI Lands on Both Sides of the Fight
daily cyber × ai intelligence
tagged
4 editions · 3 items
August 1, 2026
in When the Attacker Is a Model: AI Lands on Both Sides of the Fight
June 19, 2026
FortiBleed exposed working SSL-VPN credentials for 70,000+ Fortinet devices across 194 countries via industrialized hash-cracking by a Russian-speaking group, while a forgotten GitHub token cost Novo Nordisk 1.3TB of drug formulas and internal AI models. Critical vulnerabilities in NGINX (CVE-2026-42530), Cisco SD-WAN and ISE, Splunk, and Joomla are under active exploitation, alongside AI pipeline supply-chain attacks hitting Mastra, JetBrains Marketplace, and Google Vertex AI. The AtomicArch campaign compromised ~1,500 Arch Linux AUR packages with Rust infostealers and eBPF rootkits.
June 18, 2026
June 17, 2026
npm install; a second obfuscated wave hit Node.js, Firefox, LibreWolf, and NeoVim packages. Arch suspended new AUR signups; Nextron published YARA rules. The Register, YARA rules.
· Supply Chain