GitHub, PyPI add time-absed defenses against supply chain attacks
2026-07-26T19:23:26Z•452ddca4a1cb9928bf13ad3d783e3e5b5109e09b26d3a8e8c7918fcb9df3fd88
ai-agentai-driven-attacksazure-outagechick-fil-acredential-stuffingcryptominerdata-breachdependabotdns-hijackgithubhermeshotel-wifiin-memory-malwarejavascriptmalvertisingmicrosoft-365ontracphantom-domainspypisextortionshinyhuntersslopsquattingsteam-forumssupply-chainxmrig
What happened
Collection of security news covering multiple active threats and incidents: GitHub and PyPI added time-based Dependabot defenses against supply-chain attacks; Steam forums are being used for ClickFix XMRig cryptominer infections; a large malvertising campaign uses JavaScript to assemble malware in browser memory; ShinyHunters breach data fuels $2,000 sextortion emails; OnTrac notified customers after a network breach; attackers automated post-exploitation with the open-source Hermes AI agent against Thailand's Finance Ministry; hotel Wi‑Fi DNS hijacks are stealing Microsoft 365 credentials; a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 452ddca4a1cb9928bf13ad3d783e3e5b5109e09b26d3a8e8c7918fcb9df3fd88
- Enrichment time
- 2026-07-26T19:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.