Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Priority

highSupply ChainActive

Typosquatting Alibaba npm Dependencies: 18 Malicious Packages Distribute Cross-Platform RAT

Attackers published 18 malicious npm packages impersonating Alibaba internal libraries, most notably 'lib-mtop', to distribute a cross-platform remote access trojan to Chinese-speaking developers. This is a targeted supply chain attack exploiting npm's public registry to reach a specific user demographic.

npm registry users, Alibaba tool users, Chinese-speaking developer communities

All intelligence

Showing 19 of 906
informationalToolEmerging

OpenAI's Astra Model Signals Major Leap in AI Reasoning Capability with Demonstrated Mathematical Breakthroughs

OpenAI has announced Astra, an unreleased AI model capable of solving complex, long-running tasks, with an internal version reportedly achieving ten significant advances in mathematics and theoretical computer science. This represents a meaningful capability increase in autonomous reasoning systems.

OpenAI (unreleased product), AI/ML security community
highCampaignActive

Chinese Actor's Autonomous AI Exploitation Failed While Manual Attacks Breached Targets

Unit 42 linked the aliases knaithe and KnYuan to failed autonomous exploitation using DeepSeek through Hermes Agent and to separate, successful manual attacks. Confirmed impact—three Citrix data exfiltrations and command execution on 11 Marimo endpoints—came from manual exploitation, not AI autonomy.

CVE-2026-33017CVE-2026-21858CVE-2026-3055CVE-2026-34486CVE-2026-39987CVE-2026-0300CVE-2026-33824
Citrix NetScaler ADC and Gateway, Marimo Notebook, Malaysian government entity