Two Arrests Put a Number on TeamPCP’s Supply-Chain Damage

Australian authorities charged two alleged TeamPCP participants and quantified the campaign's reach: more than 1,000 organisations, 500,000 credentials and 300 GB of data.

Australian authorities charged two alleged TeamPCP participants and quantified the campaign's reach: more than 1,000 organisations, 500,000 credentials and 300 GB of data.

A new Shai-Hulud descendant spread through npm packages with legitimate-looking provenance. The incident shows why a trusted build path is not necessarily a trustworthy one. Security researchers identified a fast-moving npm supply-chain campaign on 4 August and named it ChainDrop.…

A malicious notebook could turn github.dev into a GitHub OAuth-token theft path with read and write access across the developer's repositories.

A compromised Nx Console update reached a GitHub employee device, stole credentials, and exposed roughly 3,800 internal repositories.