惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Schneier on Security
Recent Announcements
Recent Announcements
C
Check Point Blog
Stack Overflow Blog
Stack Overflow Blog
Vercel News
Vercel News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
A
About on SuperTechFans
爱范儿
爱范儿
D
DataBreaches.Net
The GitHub Blog
The GitHub Blog
L
LangChain Blog
大猫的无限游戏
大猫的无限游戏
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
云风的 BLOG
云风的 BLOG
月光博客
月光博客
AI
AI
美团技术团队
SecWiki News
SecWiki News
WordPress大学
WordPress大学
N
Netflix TechBlog - Medium
V
Vulnerabilities – Threatpost
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
C
Cybersecurity and Infrastructure Security Agency CISA
M
MIT News - Artificial intelligence
PCI Perspectives
PCI Perspectives
aimingoo的专栏
aimingoo的专栏
D
Darknet – Hacking Tools, Hacker News & Cyber Security
V
Visual Studio Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
N
News | PayPal Newsroom
阮一峰的网络日志
阮一峰的网络日志
人人都是产品经理
人人都是产品经理
NISL@THU
NISL@THU
Hacker News: Ask HN
Hacker News: Ask HN
Security Latest
Security Latest
MongoDB | Blog
MongoDB | Blog
H
Heimdal Security Blog
Schneier on Security
Schneier on Security
B
Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
B
Blog RSS Feed
D
Docker
Spread Privacy
Spread Privacy
Cloudbric
Cloudbric
www.infosecurity-magazine.com
www.infosecurity-magazine.com
I
Intezer
T
The Blog of Author Tim Ferriss
Last Week in AI
Last Week in AI
AWS News Blog
AWS News Blog

The Register - Security: Cyber-crime

Election interlopers register 5K+ domains, hope to catch some voting phish Palo Alto VPN bug graduates from advisory to active exploitation ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Carnival confirms ShinyHunters cruised off with 6M customer records after April breach CrowdStrike, Google shatter Glassworm botnet MyPillow must decide whether to be firm or soft as ransomware crims demand pay A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Shai-Hulud copycat worm infects yet another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Cache-poisoning caper turns TanStack npm packages toxic 'CopyFail' attackers start cashing in on Linux flaw Cushman & Wakefield confirms vishing cyberattack ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Critical cPanel exploited: 'Millions' of sites could be hit Pro-Iran group turns Ubuntu DDoS into shakedown French prosecutors link 15-year-old to gov mega-breach UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don’t pay VECT a ransom - your big files are likely gone Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack targets security, dev tools Medical and utility tech companies admit digital breakins Burglar alarm biz gets burgled, ShinyHunters pursues ransom Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival’s booty CISA, NCSC issue Firestarter backdoor warning 500k Biobank volunteers' data listed for sale on Alibaba Another npm supply chain worm hits dev environments France's 'Secure' ID agency probes breach as crooks claim 19M records France's 'Secure' ID agency probes claimed 19M record breach macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets macOS ClickFix attacks deliver AppleScript stealers Yet another ex-ransomware negotiator admits turning rogue after payoff from crimelords Third ransomware pro pleads guilty to cybercrime U-turn AI-assisted intruders pwned Vercel via OAuth abuse and a pilfered employee account AI-pwned: Vercel breach traced to stolen employee creds Crook claims to leak 'video surveillance footage' of companies Crook claims to leak 'video surveillance footage' of firms Adaptavist Group breach spawns imposter emails as ransomware crew claims mega-haul Adaptavist Group breach: Ransomware crew claims mega-haul Scot becomes second Scattered Spider-linked crook to plead guilty in US US gets second Scattered Spider-linked guilty plea North Korea targets macOS users in latest heist McGraw Hill linked to 13.5M-record data leak McGraw Hill linked to 13.5M-record data leak Autovista blames ransomware for service disruption Autovista blames ransomware for service disruption No honor among thieves as 0APT threatens rival ransomware gang Krybit 0APT ransomware gang extorts Krybit amid doxxing threat Fake Linux leader using Slack to con devs into giving up their secrets Fake Linux Foundation leader using Slack to phish devs Booking.com warns of possible reservation data exposure Booking.com warns of possible reservation data exposure Gym giant Basic-Fit breached with at least 1M affected US, UK, Canadian cops disrupt $45M global crypto scam www.theregister.com Old Adobe Reader zero-day uses PDFs to size up targets Zephyr Energy loses £700K to contractor payment fraud Russia's Fancy Bear still attacking routers to boost fake sites, NCSC warns Russia's APT28 behind latest wave of router, DNS attacks AI recruiting biz Mercor says it was 'one of thousands' hit in LiteLLM supply-chain attack Mercor says it was 'one of thousands' hit in LiteLLM attack Telnyx package latest hit in PyPI supply-chain compromise European Commission admits breach of public web systems European Commission admits breach of public web systems AFC Ajax drops ball as hackers transfer tickets, lift bans AFC Ajax drops ball as hackers transfer tickets, lift bans HackerOne slams supplier for delayed breach notice after staff data exposed HackerOne slams supplier over delayed breach notice Russian initial access broker jailed for 81 months in US Russian initial access broker jailed for 81 months in US Smooth criminals talking their way into cloud environments, Google says Chip tester shrugged off ransomware – then came the leak Chip tester shrugged off ransomware – then came the leak Russians posing as Signal support to launch phishing raids JLR cyber bailout risks dangerous precedent, watchdog warns Unknown attackers exploit yet another critical SharePoint bug Microsoft Intune: Lock it down, warn feds after Stryker Ransomware crims abused Cisco 0-day weeks before disclosure North Korea's 100,000-strong fake IT worker army rake in $500M a year for Kim Jong Un Robotics surgical biz Intuitive discloses phishing attack Cybercrime up 245% since the start of the Iran war AI-driven fraud far more profitable, Interpol warns Credential-stealing crew spoofs Ivanti, Fortinet, Cisco VPNs Interpol sinkholes 45,000 IPs linked to global cybercrime SocksEscort fraud-enabling proxy service taken down CISA warns max-severity n8n bug is being exploited in the wild Iran-linked cyber crew claims hit on US med-tech firm Meta, cops deploy AI and handcuffs in scam crackdown Dutch police collar teen over string of bank card frauds EU law advisor wants cybercrime protections fast-tracked Cybercrime isn't just a cover for Iran's government goons Crooks compromise WordPress sites, spread infostealers Ericsson breach blamed on third party vendor vishing attack Polish cyber police busts gang of alleged teen DDoS peddlers
Telnyx package latest hit in PyPI supply-chain compromise
Brandon Vigliarolo · 2026-03-31 · via The Register - Security: Cyber-crime

INFOSEC IN BRIEF The cybercrime crew linked to the Trivy supply-chain attack has struck again, this time pushing malicious Telnyx package versions to PyPI in an effort to plant credential-stealing malware on developers’ systems.

Ox Security warned on Friday that TeamPCP - the group researchers link to the recent compromise of open-source vulnerability scanner Trivy, which led to malicious LiteLLM packages appearing on PyPI - is back, this time with another compromise of a legitimate software package.

In this case, the crew hit Telnyx, which offers VoIP services and AI voice agents. TeamPCP appears to have compromised the PyPI distribution of Telnyx’s Python SDK, replacing current package versions with malicious releases loaded with a multi-stage infostealer and persistence mechanisms. According to Ox, the malware added to the package is similar to the malicious code added to LiteLLM. 

REG AD

According to Ox, the Telnyx malware's main difference from the LiteLLM package is how it's installed: Instead of embedding malicious code directly in the file, the Telnyx package downloads its malware in the form of a .wav file that's decoded and executed on the target machine. 

REG AD

Telnyx told Ox in a post on X that it had found and resolved the issue, while noting that the only affected component was its Python package. None of Telnyx's infrastructure, networking, or other services or APIs were affected, according to the company, though anyone who installed the Python package while the malicious versions were live should treat that environment as compromised.

Those worried they might be affected should check their installed Telnyx version — if you're running 4.87.1 or 4.87.2, Telnyx recommends treating the host as compromised and rotating any exposed credentials.

Telnyx sees more than 34,000 downloads a week on PyPI, Ox noted, so it's possible quite a few developers and services pulled one of the malicious releases before they were removed.

Alleged RedLine operator extradited to US

The mastermind may still be at large, but one of the men alleged to be behind the development and administration of prolific infostealer RedLine is behind bars in the US after being extradited to face charges. 

Hambardzum Minasyan, an Armenian national, last week made his initial appearance in federal court in Austin, Texas, on charges of conspiracy to commit access device fraud, conspiracy to violate the CFAA, and conspiracy to commit money laundering.

According to the indictment, Minasyan's part of RedLine's operations involved registering virtual private servers and domains to host RedLine infrastructure, as well as the creation of repositories used to host RedLine for distribution to affiliates. Minasyan also allegedly registered a cryptocurrency account used to receive RedLine affiliate payments. 

If convicted on all three charges, Minasyan faces up to 30 years in prison. 

REG AD

Law enforcement first publicly identified alleged RedLine developer and administrator Maxim Rudometov in 2024, accusing the Russian national of helping build and run the infostealer operation. Last year, the US government offered a $10 million bounty for information on Rudometov and his co-conspirators. It's not clear whether any money was paid out in relation to the arrest of Minasyan. 

Snapchat, porn platforms, put on notice for DSA violations

What does Snapchat have in common with Pornhub, Stripchat, and other porn platforms? All came under EU scrutiny last week under the Digital Services Act over alleged failures to protect minors online.

In Snapchat's case, the matter is a bit earlier in proceedings, as Pornhub, Stripchat, XNXX, and XVideos were all preliminarily found last week to be in breach of the DSA for failing to implement effective age-verification measures that would keep minors off their services.

According to the European Commission, all four platforms have a simple self-verification system in place requiring visitors to confirm they're over 18 without any formal checks in place. As this is a preliminary finding, the Commission is now giving the porno-pushers an opportunity to respond.

The Commission suspects that Snapchat has a similar weakness in relying on self-declaration, noting the platform's age-assurance measures may be insufficient.

"The Commission suspects that Snapchat is not adequately protecting minors from being contacted by users with harmful intent, such as sexual exploitation or recruitment for criminal activities," the EC explained.

The Commission will now carry out an in-depth investigation into Snapchat before deciding whether to take further enforcement steps.

REG AD

LAPSUS$ spills alleged AstraZeneca data

The cybercriminals behind the LAPSUS$ threat group have released 2.66 GB of data allegedly stolen from drug maker AstraZeneca, and threat watchers say it could become one of the more serious healthcare cyber incidents of 2026 so far if the claims hold up.

According to SOCRadar, LAPSUS$ claimed to have hit AstraZeneca recently, making off with what they claim are internal code repositories, access-related data, cloud and infrastructure references, and employee records - data which could be devastating to the company in the hands of the right - or wrong - person. 

Per SOCRadar, the data they reviewed "points to a potentially meaningful internal code and operations exposure rather than a small credential-only leak." They warn that the purportedly stolen data could be used for follow-on intrusions, to target phishing attacks, and to compromise AstraZeneca partners in supply chain attacks.

LAPSUS$ released the full dataset over the weekend, SOCRadar reported.

US National Lab creates exascale AI model vulnerability detector

Researchers at Oak Ridge National Laboratory have created what they say is an efficient, effective AI vulnerability detection machine that can operate at the exascale level, and all it took was turning a friendly neural network optimization bot into an exploitative one. 

"It might sound devious, but it's worked very well," said ORNL Center for Artificial Intelligence Security Research director Edmon Begoli.

Photon, as the ORNL team dubbed it, is designed to explore, discover, and exploit AI vulnerabilities at scale. According to the team, it starts by applying publicly known attacks against a target model and refining them based on the results. Simultaneously, the team said, it continues exploring the model for new weaknesses, which it can then exploit as part of an ongoing cycle to refine the most effective attacks it finds.

Photon is also able to significantly reduce bottlenecks and auxiliary tasks associated with red team AI campaigns - per the team, it scaled without loss of computational efficiency, and maintained 95 percent resource utilization across 1,920 GPUs on the lab's Frontier supercomputer.  

And there's the rub: This thing can find and exploit anything it can find in an AI model, but such capabilities are limited to supercomputing labs for now. 

"Photon represents a paradigm shift in how we approach AI security," Begoli said. Thankfully it won't be something bad actors will have the resources to utilize for some time. ®