Mini Shai-Hulud Turns Package Publishing into a Wormable Trust Path

A coordinated compromise of npm and PyPI packages shows how trusted publishing, CI caches and maintainer identities can combine into an automated supply-chain attack. Security researchers reported a new “Mini Shai-Hulud” campaign on 11 May involving trojanised packages in the…

The Canvas Breach Exposes the Hidden Scale of Education Platforms

Two intrusions into Instructure’s Canvas platform show why a shared education service needs tenant-level visibility, tested fallbacks and careful treatment of attacker claims. Instructure detected unauthorised activity in Canvas on 29 April. On 7 May, the same actor obtained access…

The Vercel Incident Turns AI OAuth Apps into a Security-Control Question

Vercel’s April incident began with a compromised third-party AI application and ended inside internal systems. OAuth consent deserves the same scrutiny as a privileged integration. Vercel disclosed that an attacker gained unauthorised access to certain internal systems after compromising Context.ai,…

Internet-Facing PLCs Turn Routine Exposure into Physical Risk

A joint US advisory on attacks against internet-connected controllers shows how weak OT exposure management can turn a basic intrusion into operational disruption. US agencies warned on 7 April that Iranian-affiliated cyber actors were exploiting internet-connected operational-technology devices across several…

The FBI Breach Shows Why Investigative Metadata Is High-Value Data

A breach of an FBI system used for court-authorised surveillance is a reminder that “metadata” can reveal operations, targets and methods even when message content remains untouched. The FBI has acknowledged suspicious activity involving an unclassified internal system used to…

A Compromised Trivy Update Led to a European Commission Cloud Breach

The European Commission used a compromised version of a trusted security scanner. The resulting breach shows that build tools can become credential-harvesting infrastructure inside the systems they are meant to protect. CERT-EU published its investigation into a European Commission cloud…