TeamPCP Hijacks Bitwarden CLI, Uses Dependabot to Deploy Shai-Hulud Malware
GitGuardian uncovers TeamPCP attack on Bitwarden CLI, abusing GitHub Dependabot to spread Shai-Hulud and poison AI coding tools.
More results...
GitGuardian uncovers TeamPCP attack on Bitwarden CLI, abusing GitHub Dependabot to spread Shai-Hulud and poison AI coding tools.
I’ve been trying to get real work done, but the Mythos disaster keeps landing in my inbox, so here’s a quick nod. Remember Cybernews framing of the CVE-2026-5873 demo? The researcher “intervened when the model became stuck, redirectin…
French police arrest HexDex hacker, a 20-year-old suspect accused of mass data theft and leaks targeting government, sports groups, and firms.
Calvin Duncan spent 28 years in prison for a murder he did not commit. During those years the Orleans Parish Clerk of Criminal Court office repeatedly denied him access to the records he needed to prove his innocence. He taught himself law inside the p…
A confidentiality breach, loss of privacy, is well known since California delivered landmark legislation in 2003 called SB1386. The amount of money that criminals made by breaching privacy was, well, criminal. And more importantly, laws changed to make…
UK National Cyber Security Centre (NCSC) warns China-linked hackers use hijacked devices as proxy networks to hide activity and evade detection. UK National Cyber Security Centre (NCSC) and global partners warn that China-linked threat actors now rely on large proxy networks built of hacked consumer devices. Groups control routers, cameras, video recorders, and NAS systems […]
UK National Cyber Security Centre (NCSC) warns China-linked hackers use hijacked devices as proxy networks to hide activity and evade detection. UK National Cyber Security Centre (NCSC) and global partners warn that China-linked threat actors now rely on large proxy networks built of hacked consumer devices. Groups control routers, cameras, video recorders, and NAS systems […]
Polymarket CEO tells insiders to leak. So cool, he says. Do it, for the market. …what’s cool about Polymarket is that it creates this financial incentive for people to go and divulge the information to the market and the market to change, a…
Researchers have finally cracked Fast16, mysterious code capable of silently tampering with calculation and simulation software. It was created in 2005—and likely deployed by the US or an ally.
There’s something very strange going on at Anthropic. Day after day I see evidence of what can only be described as what I used to study in the Cold War: closed systems of cooked intelligence. An integrity breach I just stumbled upon might be the…