GitHub, PyPI add time-absed defenses against supply chain attacks

2026-07-26T19:23:26Z452ddca4a1cb9928bf13ad3d783e3e5b5109e09b26d3a8e8c7918fcb9df3fd88
ai-agentai-driven-attacksazure-outagechick-fil-acredential-stuffingcryptominerdata-breachdependabotdns-hijackgithubhermeshotel-wifiin-memory-malwarejavascriptmalvertisingmicrosoft-365ontracphantom-domainspypisextortionshinyhuntersslopsquattingsteam-forumssupply-chainxmrig

What happened

Collection of security news covering multiple active threats and incidents: GitHub and PyPI added time-based Dependabot defenses against supply-chain attacks; Steam forums are being used for ClickFix XMRig cryptominer infections; a large malvertising campaign uses JavaScript to assemble malware in browser memory; ShinyHunters breach data fuels $2,000 sextortion emails; OnTrac notified customers after a network breach; attackers automated post-exploitation with the open-source Hermes AI agent against Thailand's Finance Ministry; hotel Wi‑Fi DNS hijacks are stealing Microsoft 365 credentials; a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
452ddca4a1cb9928bf13ad3d783e3e5b5109e09b26d3a8e8c7918fcb9df3fd88
Enrichment time
2026-07-26T19:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · GitHub, PyPI add time-absed defenses against supply chain attacks · Baitaphish