OpenMandriva Linux says contributor tried to sabotage the project
2026-07-10T01:23:31Z•29c1adbeb6d0cea02007a5bba6f72e40a08879d8b76169e374283827ab689a28
AiTMAssuranceAmerica','Mount Royal University'DefenderEntraMFA-abuseMicrosoftOpenMandrivaRoguePlanetRoundcubeWindowscredential-theftcryptocurrencydata-breachdevice-code-phishinginsider-sabotagenpmopen-sourcepasskeypatchingphishingpypisupply-chainvishingwallet-stealerzero-day
What happened
BleepingComputer roundup: multiple active supply-chain attacks and credential-stealing packages were observed on npm and PyPI — notably an Injective Labs SDK package that stole cryptocurrency wallet keys and fake Paysafe/Skrill SDKs delivering stealers. New phishing/vishing campaigns and platforms (Helix, Forg365) are abusing voice phishing, device-code phishing, AiTM techniques, MFA abuse and AI-generated lures to steal Microsoft 365/SharePoint access and enroll fake Entra passkeys. Microsoft-related items include increased AI-driven vulnerability discovery, retirement plans for OWA Light, a/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 29c1adbeb6d0cea02007a5bba6f72e40a08879d8b76169e374283827ab689a28
- Enrichment time
- 2026-07-10T01:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.