One Year of Decipher (Relaunched)
It’s been one year since we relaunched Decipher in September 2025. Here are the videos, podcasts, and articles that best reflect our mission statement: Security without fear.
All topics
It’s been one year since we relaunched Decipher in September 2025. Here are the videos, podcasts, and articles that best reflect our mission statement: Security without fear.
The unknown threat actor gained unauthorized access to legitimate npm accounts, allowing them to inject malicious dependencies into widely used packages.
Researchers said that they found a Red Hat employee's GitHub account had been compromised and was used by threat actors to push malicious orphan commits directly to several repositories.
The disruption, which was a joint effort among CrowdStrike, Google, and the Shadowserver Foundation, targeted Glassworm’s C2 architecture, which was deliberately engineered for extreme resilience.
In the spring, a young attacker’s fancy turns to supply chain compromises, and this season’s crop includes the GitHub breach and the Grafana intrusion, which are connected and trace back to the TanStack supply chain attack and…TeamPCP.
The company said it is still working through the intrusion but does not believe any customer repositories or data was affected at this point.