惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
Engineering at Meta
Engineering at Meta
A
About on SuperTechFans
T
The Blog of Author Tim Ferriss
I
InfoQ
博客园_首页
G
Google Developers Blog
爱范儿
爱范儿
Last Week in AI
Last Week in AI
量子位
阮一峰的网络日志
阮一峰的网络日志
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
Vercel News
Vercel News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
月光博客
月光博客
The GitHub Blog
The GitHub Blog
V
Visual Studio Blog
N
Netflix TechBlog - Medium
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 司徒正美
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 聂微东

The Register - Security: Cyber-crime

Election interlopers register 5K+ domains, hope to catch some voting phish Palo Alto VPN bug graduates from advisory to active exploitation ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Carnival confirms ShinyHunters cruised off with 6M customer records after April breach CrowdStrike, Google shatter Glassworm botnet MyPillow must decide whether to be firm or soft as ransomware crims demand pay A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Shai-Hulud copycat worm infects yet another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Cache-poisoning caper turns TanStack npm packages toxic 'CopyFail' attackers start cashing in on Linux flaw Cushman & Wakefield confirms vishing cyberattack ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Critical cPanel exploited: 'Millions' of sites could be hit Pro-Iran group turns Ubuntu DDoS into shakedown French prosecutors link 15-year-old to gov mega-breach UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don’t pay VECT a ransom - your big files are likely gone Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack targets security, dev tools Medical and utility tech companies admit digital breakins Burglar alarm biz gets burgled, ShinyHunters pursues ransom Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival’s booty
Telnyx package latest hit in PyPI supply-chain compromise
Brandon Vigliarolo · 2026-03-31 · via The Register - Security: Cyber-crime

INFOSEC IN BRIEF The cybercrime crew linked to the Trivy supply-chain attack has struck again, this time pushing malicious Telnyx package versions to PyPI in an effort to plant credential-stealing malware on developers’ systems.

Ox Security warned on Friday that TeamPCP - the group researchers link to the recent compromise of open-source vulnerability scanner Trivy, which led to malicious LiteLLM packages appearing on PyPI - is back, this time with another compromise of a legitimate software package.

In this case, the crew hit Telnyx, which offers VoIP services and AI voice agents. TeamPCP appears to have compromised the PyPI distribution of Telnyx’s Python SDK, replacing current package versions with malicious releases loaded with a multi-stage infostealer and persistence mechanisms. According to Ox, the malware added to the package is similar to the malicious code added to LiteLLM. 

REG AD

According to Ox, the Telnyx malware's main difference from the LiteLLM package is how it's installed: Instead of embedding malicious code directly in the file, the Telnyx package downloads its malware in the form of a .wav file that's decoded and executed on the target machine. 

REG AD

Telnyx told Ox in a post on X that it had found and resolved the issue, while noting that the only affected component was its Python package. None of Telnyx's infrastructure, networking, or other services or APIs were affected, according to the company, though anyone who installed the Python package while the malicious versions were live should treat that environment as compromised.

Those worried they might be affected should check their installed Telnyx version — if you're running 4.87.1 or 4.87.2, Telnyx recommends treating the host as compromised and rotating any exposed credentials.

Telnyx sees more than 34,000 downloads a week on PyPI, Ox noted, so it's possible quite a few developers and services pulled one of the malicious releases before they were removed.

Alleged RedLine operator extradited to US

The mastermind may still be at large, but one of the men alleged to be behind the development and administration of prolific infostealer RedLine is behind bars in the US after being extradited to face charges. 

Hambardzum Minasyan, an Armenian national, last week made his initial appearance in federal court in Austin, Texas, on charges of conspiracy to commit access device fraud, conspiracy to violate the CFAA, and conspiracy to commit money laundering.

According to the indictment, Minasyan's part of RedLine's operations involved registering virtual private servers and domains to host RedLine infrastructure, as well as the creation of repositories used to host RedLine for distribution to affiliates. Minasyan also allegedly registered a cryptocurrency account used to receive RedLine affiliate payments. 

If convicted on all three charges, Minasyan faces up to 30 years in prison. 

REG AD

Law enforcement first publicly identified alleged RedLine developer and administrator Maxim Rudometov in 2024, accusing the Russian national of helping build and run the infostealer operation. Last year, the US government offered a $10 million bounty for information on Rudometov and his co-conspirators. It's not clear whether any money was paid out in relation to the arrest of Minasyan. 

Snapchat, porn platforms, put on notice for DSA violations

What does Snapchat have in common with Pornhub, Stripchat, and other porn platforms? All came under EU scrutiny last week under the Digital Services Act over alleged failures to protect minors online.

In Snapchat's case, the matter is a bit earlier in proceedings, as Pornhub, Stripchat, XNXX, and XVideos were all preliminarily found last week to be in breach of the DSA for failing to implement effective age-verification measures that would keep minors off their services.

According to the European Commission, all four platforms have a simple self-verification system in place requiring visitors to confirm they're over 18 without any formal checks in place. As this is a preliminary finding, the Commission is now giving the porno-pushers an opportunity to respond.

The Commission suspects that Snapchat has a similar weakness in relying on self-declaration, noting the platform's age-assurance measures may be insufficient.

"The Commission suspects that Snapchat is not adequately protecting minors from being contacted by users with harmful intent, such as sexual exploitation or recruitment for criminal activities," the EC explained.

The Commission will now carry out an in-depth investigation into Snapchat before deciding whether to take further enforcement steps.

REG AD

LAPSUS$ spills alleged AstraZeneca data

The cybercriminals behind the LAPSUS$ threat group have released 2.66 GB of data allegedly stolen from drug maker AstraZeneca, and threat watchers say it could become one of the more serious healthcare cyber incidents of 2026 so far if the claims hold up.

According to SOCRadar, LAPSUS$ claimed to have hit AstraZeneca recently, making off with what they claim are internal code repositories, access-related data, cloud and infrastructure references, and employee records - data which could be devastating to the company in the hands of the right - or wrong - person. 

Per SOCRadar, the data they reviewed "points to a potentially meaningful internal code and operations exposure rather than a small credential-only leak." They warn that the purportedly stolen data could be used for follow-on intrusions, to target phishing attacks, and to compromise AstraZeneca partners in supply chain attacks.

LAPSUS$ released the full dataset over the weekend, SOCRadar reported.

US National Lab creates exascale AI model vulnerability detector

Researchers at Oak Ridge National Laboratory have created what they say is an efficient, effective AI vulnerability detection machine that can operate at the exascale level, and all it took was turning a friendly neural network optimization bot into an exploitative one. 

"It might sound devious, but it's worked very well," said ORNL Center for Artificial Intelligence Security Research director Edmon Begoli.

Photon, as the ORNL team dubbed it, is designed to explore, discover, and exploit AI vulnerabilities at scale. According to the team, it starts by applying publicly known attacks against a target model and refining them based on the results. Simultaneously, the team said, it continues exploring the model for new weaknesses, which it can then exploit as part of an ongoing cycle to refine the most effective attacks it finds.

Photon is also able to significantly reduce bottlenecks and auxiliary tasks associated with red team AI campaigns - per the team, it scaled without loss of computational efficiency, and maintained 95 percent resource utilization across 1,920 GPUs on the lab's Frontier supercomputer.  

And there's the rub: This thing can find and exploit anything it can find in an AI model, but such capabilities are limited to supercomputing labs for now. 

"Photon represents a paradigm shift in how we approach AI security," Begoli said. Thankfully it won't be something bad actors will have the resources to utilize for some time. ®