September 10, 2026
BlueMoon exploit kit chains Chrome and Windows zero-days within days of patch publication, with four suspected China-linked espionage groups weaponizing the same toolkit on US and Southeast Asian targets from late August onward. Cisco Secure Firewall Management Center CVEs are under active exploitation by three distinct post-compromise clusters including a ransomware operator and Sandworm-attributed activity. DeepSeek AI agent harness contained an authentication bypass allowing remote agents to escalate privileges via a single shell command; Anthropic declined to provide pre-release model access to UK authorities, triggering debate over AI protectionism. Stealer logs now monetize replayable AI-service tokens from compromised systems, with over 500 valid Google, Anthropic, and Cursor credentials found in a single 7 GB dump.
September 4, 2026
- The Shai-Hulud infostealer worm now sweeps 469 credential locations, up from 189 in earlier variants — covering CI/CD tooling, cloud configs and, notably, AI tool configuration files (The Hacker News).
· Threat Activity
in Malware That Gaslights the AI Analyst
August 7, 2026
- ChainDrop, a self-propagating npm worm, compromised 400+ packages (starting from a poisoned
keyv/cacheable), backdooring packages, extracting GitHub Actions runner memory secrets, and using an Ethereum transaction to rotate its C2 domain. It's the latest evolution of the Shai-Hulud family (earlier coverage). Elastic Security Labs, Unit 42. Critically, SANS ISC warns do not revoke the stolen token first — revocation is exactly what arms the payload; upgrade to npm 12+ and stage rotation carefully instead. SANS ISC
· Supply Chain
in Meta Becomes the Fourth Lab to Admit Its AI Hacked a Stranger
August 5, 2026
- Shai-Hulud npm worm resurges, poisoning 1,280+ packages. The self-propagating worm is back, injecting a credential stealer and lifecycle hooks across a broad set of packages (Hackread).
· Supply Chain
in Frontier AI Agents Broke Containment and Attacked Real Targets During UK Government Testing
July 27, 2026
- Another cluster of malicious npm, PyPI, and RubyGems packages surfaced. GitGuardian counts four fresh supply-chain hits between early June and mid-July — a Shai-Hulud worm variant, typosquatted payment SDKs, a stolen publishing token, and a hijacked CI pipeline — all aimed at credentials in developer environments and build pipelines (GitGuardian, flagged by NCSC-FI). Separately, a macOS infostealer disguised as
@copilot-mcp/apex was re-published to npm after an earlier takedown, running AppleScript and persisting via LaunchAgents (safedep).
· Supply Chain
in Two Live Exploits and a Bench of Fresh Offensive Tooling
June 17, 2026
- GitHub dismissed two formal vulnerability reports on design flaws researchers say are now being exploited by variants of the Shai-Hulud supply-chain worm to compromise hundreds of packages and developer accounts. The Record.
· Supply Chain
in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists