Mastra AI Hit By npm Compromise
The unknown threat actor gained unauthorized access to legitimate npm accounts, allowing them to inject malicious dependencies into widely used packages.
All topics
The unknown threat actor gained unauthorized access to legitimate npm accounts, allowing them to inject malicious dependencies into widely used packages.
Alex Pinto, one of the lead authors of the Verizon Data Breach Investigations Report, joins Dennis to talk about his organization’s newest publication, the Breach Impact Study, which digs into the real world cost of breaches, both in dollars and in organizational impact. Spoiler: Breaches are expensive. Verizon BIS: https://www.verizon.com/business/resources/reports/2026-breach-impact-study-dbir.pdf
This week was blessedly free of any major supply chain compromises, so we start by talking about new research from Anthropic on the shrinking window between bug disclosure and exploitation, then we discuss the changing patch schedule for Cisco and how all of this is changing the prioritization process for security teams, and finally we […]
“Because this activity predates Oracle's June 10, 2026 advisory, the vulnerability was exploited as a zero-day," said Mandiant researchers.
Anthropic researchers warned that modern AI tools are further intensifying the existing issue of threat actors creating N-day exploits.
We've arrived at a point where billions of us have opted in to types of surveillance that would have caused massive demonstrations just a couple of decades ago.
June 17, 2026 | 1 min read