Risky Business #839 -- TeamPCP stole GitHub's internal repos
Developer platform security model faces scrutiny as internal repository compromise demonstrates critical trust boundaries in software development infrastructure.
Summary written by editorial AI · Source link below
On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:
TeamPCP breached GitHub’s internal repos. Now what? Some absolute plonker glued Coruna to a hijacked npm package CISA is worried about about open source and wants third party submissions for KEV AI infrastructure is “systemically” insecure Much, much more
This week’s episode is sponsored by allowlisting vendor Airlock Digital. Airlock’s founders David Cottingham and Da
External link — opens at Risky Business in a new tab.
More from the Threat Intel Desk
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul