Linux Foundation Backs New TRACE AI Security Standard
TRACE aims to help prove that sensitive data in organizations is being handled “according to policy” by AI agents and open weight models.
All topics
TRACE aims to help prove that sensitive data in organizations is being handled “according to policy” by AI agents and open weight models.
The disruption, which was a joint effort among CrowdStrike, Google, and the Shadowserver Foundation, targeted Glassworm’s C2 architecture, which was deliberately engineered for extreme resilience.
In the spring, a young attacker’s fancy turns to supply chain compromises, and this season’s crop includes the GitHub breach and the Grafana intrusion, which are connected and trace back to the TanStack supply chain attack and…TeamPCP.
The company said it is still working through the intrusion but does not believe any customer repositories or data was affected at this point.
An "unauthorized party” obtained a token with access to the Grafana Labs GitHub environment and downloaded Grafana’s codebase.
Researchers have linked the compromise to the "Mini Shai-Hulud" campaign, which has been ongoing for several weeks and is associated with TeamPCP.