Cybersecurity intelligence

Know what changed.
Trace why it matters.

A daily, source-linked briefing for security practitioners. Every record carries its publication context, evidence links, and known limitations.

Get Security Weekly by email

Latest security briefing

Security Daily

Read latest edition
Latest signal

High-signal changes

View full briefing →
Security Daily

Incident · Theregister Security

What happened

Attackers hijacked the .gh, .sl, and .as country-code top-level namespaces, altered authoritative DNS records, and obtained unauthorized HTTPS certificates for several Google and other organizations’ domains. Google said the attacks did not compromise its systems, and Chrome blocked suspected counterfeit certificates across the affected namespaces; Google said Chrome users were therefore protected.

Why it matters

With control of DNS routing and the unauthorized certificate’s private key, attackers could potentially intercept or modify user data sent to an impersonated site and use the trusted brand for malware or phishing.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

Cloud · The Hacker News

What happened

The npm package “tensorlake,” a TypeScript SDK for Tensorlake applications, sandboxes, and cloud services, was compromised in a ChainDrop/Shai-Hulud supply-chain attack. Version 0.5.144 reportedly contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code.

Why it matters

Dependency intake warrants ownership across engineering and security rather than being treated solely as a developer convenience.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

AI & Agents · Cyberscoop

What happened

Black Lotus Labs reported that PoeLLM, malware targeting open-source AI services, had compromised more than 3,400 servers since April and formed an exploit-scanning and cryptocurrency-mining botnet. Researchers encountered PoeLLM infrastructure while investigating a maximum-severity defect affecting Ivanti’s Sentry secure mobile gateway; the botnet was linked to compromised LiteLLM, Ollama, Gotenberg and Gitea services and tools.

Why it matters

Changing the poem’s keywords lets the actor change the C2 location without updating the malware; Black Lotus Labs said many campaign C2s were not detected by crowd-sourced security tools.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Curated context

Selected historical incidents

View library →

This is a curated historical collection, not a measure of global incident prevalence.

Build practical skill

Learn from the same evidence discipline

Open learning hub →
Trust through limits

Evidence is visible. Uncertainty stays visible too.

Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.

Read methodology and limitations →
Your Monday security briefing

BaitaPhish Security Weekly

Get the week's most important security developments by email, with links to the evidence and the narrated edition.

Monday mornings, when a new edition is published.

We’ll email you a link to confirm your subscription. Previously unsubscribed? Use this form to request a fresh confirmation link.

Explore Security Weekly