Microsoft says China-linked operators have used NeedyMantis since at least October 2025 to keep access to telecom, university and government-linked networks. It goes in after the break-in, so defenders have to hunt for it inside networks already breached.
Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 67%
- Investor
- Investor 11%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+18
- Incentives40
- Confidence60
Microsoft says China-aligned NeedyMantis malware, active since at least October 2025, is installed after attackers already have access, to keep it long term. Because entry routes vary, organisations in the five sectors it targets need to look for copies already installed.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives40
- Confidence60
Malicious versions of three Rust crates ran code at compile time on August 20. Wiz says the infrastructure overlaps with DPRK operations, so the campaign should be treated as live.
Perspective Coverage
6 publishers
- Builder
- Builder 45%
- Operator
- Operator 48%
- Investor
- Investor 7%
Reality
- Evidence80
- Adoption30
- Hype gap+25
- Incentives55
- Confidence75
CISA says CVE-2026-72529 and CVE-2026-72530 are under active exploitation. For federal civilian agencies, patching an exposed instance is only half of the obligation.
Perspective Coverage
4 publishers
- Builder
- Builder 25%
- Operator
- Operator 68%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence70
Kaspersky says malware reached Android car head units through the vendor's own update mechanism, using a flag that installs apps the device never had. The payload has no interface at all.
Perspective Coverage
8 publishers
- Builder
- Builder 36%
- Operator
- Operator 50%
- Investor
- Investor 14%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence68
Socket found 19 Chrome and Edge extensions carrying crypto-draining code, five of them bought from their original owners. The malware landed in updates after each listing had earned real installs, which is exactly what a one-time vetting pass never re-checks.
Reality
- Evidence60
- Adoption35
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
Malwarebytes found Kothamine, an undocumented Windows RAT hidden in malicious npm packages, that takes its 30-plus commands over Tailscale's tailcat. The encrypted channel leaves no command-and-control domain to block, pushing detection onto the endpoint.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence58
A credential held by a third-party app vendor gave attackers four days of access to shopper records in BigCommerce stores. Cutting off that access meant uninstalling the app.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 62%
- Investor
- Investor 11%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence60
TeamPCP's npm compromise of TanStack reached CrowdSec through a departed employee's laptop, and the company learned its private repositories had been copied only when the code surfaced on a dark web forum in September.
Reality
- Evidence58
- Adoption55
- Hype gap+12
- Incentives72
- Confidence60
Aikido found the Graphalgo campaign's Go port inside two Terraform providers, one of them a typosquat of kreuzwerker/docker. The payload decrypts only when containerName and networkID hash to a hardcoded SHA256.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+12
- Incentives62
- Confidence61
Treasury secretary Scott Bessent ruled out liability exemptions for the frontier labs in the same week, so the labs stay inside existing law while their agents accumulate logged incidents.
Reality
- Evidence22
- Adoption
- Insufficient
- Hype gap+30
- Incentives65
- Confidence38
Checkmarx found that indexed-btree declares no lifecycle hooks and starts its loader when application code calls set() with key 100. The loader reads its C2 address from a smart contract on Ethereum Sepolia.
Reality
- Evidence58
- Adoption38
- Hype gap+18
- Incentives62
- Confidence57
TanStack closed out its package compromise on May 15th, and CrowdSec learned 124 days later that the same incident had cost it a CI credential with read access to its private code. The notice came from an outside researcher.
Reality
- Evidence46
- Adoption55
- Hype gap+12
- Incentives74
- Confidence55
The developer pulled 2.35 and published 2.36, but the distribution server was still compromised, so some 2.36 downloads carried the same code and about 1,500 sites need a restore from backups taken before September 14.
Reality
- Evidence45
- Adoption55
- Hype gap+18
- Incentives45
- Confidence50
A dev.to survey walks seven AI supply chain entry points and the named incidents behind each. The two dataset-poisoning numbers in it are the ones that should change how a model review is scoped.
Reality
- Evidence55
- Adoption45
- Hype gap−10
- Incentives30
- Confidence52
Janis Elsts pulled the trojanised Admin Menu Editor Pro 2.35 after about seven hours and shipped 2.36 at 19:00 UTC. The intruder still held his server and backdoored that build too. At least 230 customers took the first one.
Reality
- Evidence62
- Adoption60
- Hype gap−8
- Incentives55
- Confidence64
Attestation proves a package came out of the pipeline it names. When the pipeline is the thing that was owned, the seal still verifies, and a gate that only checks origin passes all 84 versions pushed on May 11.
Reality
- Evidence45
- Adoption45
- Hype gap+12
- Incentives30
- Confidence50
A study of seven agent harnesses reports 770 confirmed passes in 1,000 runs of a plugin-update attack, and no run was blocked by the model. The harness dispatches the hook, so the model has nothing to refuse.
Reality
- Evidence57
- Adoption
- Insufficient
- Hype gap+14
- Incentives56
- Confidence53
Patchstack logged 11,334 ecosystem vulnerabilities last year, and 46% had no developer fix when they went public. That turns a care plan built on clicking Update All into a plugin inventory problem.
Reality
- Evidence42
- Adoption52
- Hype gap+28
- Incentives62
- Confidence45
The maintainers date the second wave to March 19, eighteen days after they disclosed the first one and rotated credentials without doing it all at once, and the only action tag that came through clean was one GitHub had already frozen.
Reality
- Evidence74
- Adoption52
- Hype gap−14
- Incentives68
- Confidence61
Earlier coverage
- GitGuardian finds a Shai-Hulud variant sweeping 469 credential paths across CI/CD and AI configs
Security · September 3, 2026 · 1 publisher
- TeamPCP poisoned more than 1,000 packages with tactics anyone can copy
Security · August 28, 2026 · 1 publisher
- Thirteen Packagist theme packages hand site visitors a WebKit-to-kernel iOS chain
Security · September 1, 2026 · 2 publishers
- An attacker hijacked Hetzner routing for 33 hours to push malicious Virtualizor updates
Security · September 1, 2026 · 5 publishers
- Pandex hooked a Fortune 500 agent four minutes after claiming a package name from llms.txt
Build · September 2, 2026 · 1 publisher
- Thirteen Packagist themes push mobile ad-fraud, with an iPhone-only kernel exploit chain
Build · August 31, 2026 · 1 publisher
- Jackal IV's 58 arrests cover under a third of the suspects INTERPOL identified
Security · August 28, 2026 · 1 publisher
- TeamPCP hid its infostealer inside the scanners that audit everyone else's code
Science · August 28, 2026 · 1 publisher
- A backdoored litellm release turns every CI job that installed it into a credential incident
Science · August 28, 2026 · 1 publisher
- Oligo dates the crew behind ShadowRay 2.0's self-propagating botnet back to 2020
Security · August 28, 2026 · 1 publisher
- No CVE required: DoFun head units installed whatever their MQTT update broker sent
Build · August 22, 2026 · 1 publisher
- TrueConf's update directory is the delivery route: two KEV bugs, one swapped installer
Build · August 21, 2026 · 1 publisher
- The runner holds your deploy keys, and nobody put it in the scanning program
Build · August 21, 2026 · 1 publisher
- VECT 2.0 shreds anything over 128 KB, which makes paying its ransom pointless
Leadership · August 18, 2026 · 1 publisher