Incident37 PyPI Packages Poisoned: What Failed
Between late 2024 and early 2025, attackers compromised 37 wheel distributions and 19 source packages on the Python Package Index (PyPI) . This campaign, known as Hades, represents a tactical evolutio
Expert perspectives on application security, compliance, and emerging threats
IncidentBetween late 2024 and early 2025, attackers compromised 37 wheel distributions and 19 source packages on the Python Package Index (PyPI) . This campaign, known as Hades, represents a tactical evolutio
IncidentWhat Happened Microsoft has introduced a two-hour automatic update delay for Visual Studio Code extensions to mitigate supply chain attack risks. This delay applies to all third-party extensions excep
ResearchOnly 11% of AI agents deployed in production meet high security standards. This statistic should alarm you, but what s more concerning is why the other 89% fail — and how similar the mistakes are acro
GeneralSecurity teams often treat browser security as a simple task—install an extension, block a few domains, and consider it done. However, your true attack surface lies in the thousands of active browser
Get weekly security insights and compliance updates delivered to your inbox.
IncidentOn May 1, 2022, npm removed a malicious package called gxm-reference-web-auth-server from the public registry. This targeted attack used encryption and multi-stage obfuscation to hide data exfiltratio
IncidentSnyk discovered 12 malicious packages in the Python Package Index (PyPI) that stole Discord tokens, Roblox credentials, and payment card data. The attackers used Discord s content delivery network (CD
DeadlinesYour application inherits the security posture of every package in your dependency tree. With over 500 malicious packages released into npm earlier this year and 80% of npm vulnerabilities surfacing t
IncidentWhat Happened Snyk s security research team discovered over 200 malicious packages in the npm registry, exploiting dependency confusion attacks to deliver Cobalt Strike payloads. These packages used i
IncidentWhat Happened CVE-2022-33980 allowed attackers to execute arbitrary code through Apache Commons Configuration s string interpolation feature. The vulnerability affected versions 2.4 through 2.7 and st
IncidentWhat Happened Between April 13 and April 15, attackers exploited CVE-2026-3300 , a critical vulnerability in the Everest Forms Pro WordPress plugin, to create rogue administrator accounts on vulnerabl
IncidentA developer on your team merges a routine dependency update. The diff shows a few version bumps in Gemfile.lock . Your CI passes. The code deploys. Three days later, your build server is mining crypto
IncidentWhat Happened In mid-2026, the Miasma worm—a variant of Mini Shai-Hulud—compromised 73 Microsoft GitHub repositories. This attack didn t exploit a traditional vulnerability but instead manipulated the
ResearchYour security team approved an OAuth app six months ago. The publisher s domain is now parked. The app still has read access to your company s Google Drive. This isn t a hypothetical. An OhAuth audit
IncidentWhat Happened On September 29, 2022, Snyk disclosed CVE-2022-40764, a command injection vulnerability in their CLI tool that allowed arbitrary code execution. This flaw affected all versions before 1.
IncidentWhat Happened OpenAI didn t suffer a data breach. Instead, they acknowledged a fundamental architectural risk: ChatGPT s features create multiple pathways for prompt injection attacks to exfiltrate da
IncidentIMPORTANT NOTICE : This teardown analyzes a hypothetical scenario based on researcher predictions about AI worm capabilities. As of this writing, no documented enterprise breach by an autonomous AI wo