Threat Intelligence — Page 19

Megalodon Campaign Pushed 5,718 Malicious Commits Into GitHub Repos in Six Hours
An automated backdooring operation abused compromised GitHub credentials to silently inject base64-encoded bash payloads into CI/CD workflows across more than 5,500 public repositories on May 18.

The Bot That Learned to Lie: Inside the New Generation of AI-Driven DDoS
Defenders describe attack waves that pause, study traffic patterns, and resume from fresh infrastructure — behavior that looks less like a script and more like a sparring partner.

Infosecurity Europe 2026: What the London Gathering Means for the Security Calendar
The industry's largest European security conference returns to London on June 2–4, 2026, and the programme signals where enterprise security investment is heading.

TrapDoor: The Supply Chain Campaign That Wants Your Whole Dev Environment, Not Just Your Secrets
A cross-registry malware campaign hitting npm, PyPI, and Crates.io is going after CI/CD pipelines, SSH trust chains, and AI coding assistant files — not just credentials on install.

The Boring Attacks Are Winning: Why Defenders Keep Losing to Trusted Tools
Leaked tokens, poisoned npm packages, and login replays are doing more damage than zero-days this quarter. Here is how to spot the pattern before it spots you.

Showboat: A Modular Linux Backdoor Quietly Camped in a Middle East Telco Since 2022
Lumen's Black Lotus Labs ties the SOCKS5-capable implant to a years-long intrusion at a regional carrier, with an in-memory loader and ELF payloads that sidestep most host telemetry.

Megalodon Campaign Plants Malicious Workflows in 5,561 GitHub Repos in Six Hours
Throwaway accounts pushed 5,718 commits forging build-bot identities to exfiltrate CI/CD secrets, researchers said.

CERT-UA Attributes Prometheus-Themed Phishing Run Against Ukrainian Government to Ghostwriter (UAC-0057)
Compromised mailboxes deliver lures impersonating a Ukrainian e-learning platform, with the Belarus-aligned operator tracked as UNC1151 named as the responsible cluster.

Laravel-Lang Packages Hijacked to Push a Cross-Platform Credential Stealer
Four popular Laravel-Lang packages were tagged with malicious releases that drop a credential-harvesting framework on Windows, macOS, and Linux.

Eight Packagist Projects Hijacked to Pull Linux Payload From GitHub Releases
The injected code lived in package.json, not composer.json, and targeted JavaScript-shipping Composer projects.

TrapDoor Campaign Plants Credential Stealers Across npm, PyPI, and Crates.io
A coordinated operation seeded 34+ malicious packages across three registries since May 2026. If you ship code, this one is sitting in your dependency tree right now.

GRU Operators Drained Microsoft 365 Tokens by Rewriting DNS on 18,000 SOHO Routers
Forest Blizzard shifted from targeted router malware to mass DNS hijacking after a UK advisory in August, intercepting OAuth tokens on Outlook on the web.

The Boy Who Topped the Leaderboard: How 'Tylerb' Became a Cooperating Witness
Tyler Buchanan, the Scottish core of Scattered Spider's 2022 phishing spree, pleaded guilty in U.S. federal court. His path there ran through a blowtorch, a Barcelona departure gate, and a Telegram scoreboard.

The Firewall Guard Was Holding a Crowbar: Brazilian DDoS-Protection Firm Caught Powering the Attacks
Exposed archive ties Huge Networks infrastructure and its CEO's SSH keys to a long-running Mirai botnet hammering Brazilian ISPs. The CEO blames a competitor.

Ottawa 23-Year-Old Charged as 'Dort,' Alleged Operator of the 30 Tbps Kimwolf IoT Botnet
Jacob Butler is in OPP custody on a U.S. extradition warrant. Prosecutors say his botnet pushed nearly 30 terabits per second. The questions I sent his lawyer remain unanswered.