Ongoing Supply Chain Attack Expands to PyPi
Researchers have linked the compromise to the "Mini Shai-Hulud" campaign, which has been ongoing for several weeks and is associated with TeamPCP.
Editor
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.
Researchers have linked the compromise to the "Mini Shai-Hulud" campaign, which has been ongoing for several weeks and is associated with TeamPCP.
If we needed any more evidence that the internet was a mistake, this week provided it. We kick things off with a discussion of the Canvas breach that has affected thousands of schools worldwide, then we dig into the disclosure of two new vulnerabilities in Ivanti and Palo Alto Networks products that are actively exploited, […]
The vulnerability class is a potent new iteration of kernel bugs that corrupt the page cache of read-only files and is a follow-on to the recently disclosed Copy Fail Linux LPE bug.
Will Dixon has seen the evolution of cybercrime as both a GCHQ intelligence officer and a private sector executive and analyst, and has seen the way these groups operate up close. He joins Dennis to talk about the ongoing threat from ransomware gangs, how organizations are managing their responses, and what he expects to come […]
PAN released an advisory about the vulnerability on Tuesday and said it will release a patch in an upcoming version of PAN-OS.
The vulnerability (CVE-2026-23918) only affects version 2.4.66 and the Apache Software Foundation has released a fix for the bug in version 2.4.67.