Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Anthropic Claude AI PyPI Supply Chain Attack: Detection and Mitigation
Anthropic Claude AI PyPI Supply Chain Attack: Detection and Mitigation Introduction The paradigm of automated offensive operations has shift...
Supply Chain Hardening: GitHub and PyPI Time-Based Defenses
Supply Chain Hardening: GitHub and PyPI Time-Based Defenses Introduction GitHub and the Python Package Index (PyPI) have announced a signifi...
Multi-Ecosystem Supply Chain Attack: npm & PyPI Typosquatting Campaign Targeting Payment SDKs
Intelligence Briefing: Multi-Ecosystem Supply Chain Attack Threat Summary AlienVault OTX has detected a coordinated supply chain attack targ...
Meta Business Manager Phishing & PyPI/NPM Supply Chain Attack — OTX Pulse Analysis
Meta Business Manager Phishing & PyPI/NPM Supply Chain Attack — OTX Pulse Analysis Excerpt: Active credential theft via npm/PyPI typosquatti...
PyPI Supply Chain Attack: ZiChatBot Malware Delivered via Zulip APIs on Linux & Windows
PyPI Supply Chain Attack: ZiChatBot Malware Delivered via Zulip APIs on Linux & Windows Introduction Security researchers have identified a ...
PyTorch Lightning Supply Chain Compromise: Detecting Malicious Versions 2.6.2 & 2.6.3
Introduction On April 30, 2026, the Python software supply chain suffered a significant blow with the confirmation that the popular lightnin...
PyPI Supply Chain Attack: Detecting TeamPCP Malicious Telnyx Packages
Introduction A new campaign by the threat actor known as TeamPCP has been identified targeting developers utilizing the Telnyx SDK on the Py...
Defending Against the TeamPCP Telnyx Supply Chain Attack: Detection & Remediation
Defending Against the TeamPCP Telnyx Supply Chain Attack: Detection & Remediation Introduction The open-source ecosystem remains a prime tar...