🚨 ACTIVE EXPLOITS & INCIDENTS
- Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials — The Hacker News The Security Service of Ukraine (SSU), in collaboration with the FBI, uncovered an ongoing Russian intelligence campaign targeting messaging accounts of government officials, military personnel, politicians, and activists across Ukraine, Europe, and the U.S. The attackers used fake support texts to phish credentials, enabling persistent espionage on high-value targets. Organizations with personnel in these regions should heighten monitoring for phishing and credential theft attempts.
🕵️ THREAT RESEARCH & DEEP DIVES
- Clean GitHub Repo Tricks AI Coding Agents into Running Malware — BleepingComputer A novel supply chain attack technique abuses AI coding assistants by presenting a seemingly clean GitHub repository that, when cloned and set up by AI agents, executes hidden malicious payloads undetectable by scanners, AI, and human reviewers. This highlights a new vector where AI-driven automation can be manipulated to introduce malware into development pipelines, urging security teams to reassess trust models around AI-assisted code generation and repository vetting.