Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 14 of 26

326–350 of 632
criticalSupply ChainActive

TeamPCP Exploits PyPI Trust Model with Steganographic Malware Distribution via Compromised Telnyx Package

TeamPCP compromised the legitimate Telnyx package on PyPI and uploaded malicious versions that extract credential-stealing malware from embedded WAV files. This represents a direct attack on Python's package supply chain affecting any developer who installed the backdoored version.

Telnyx Python package on PyPI, Python developers and applications using compromised versions
highPolicyActive

Google's 2029 PQC Migration Deadline: Crypto-Agility Crisis Looming for Enterprise Infrastructure

Google has committed to migrating its infrastructure to post-quantum cryptography by 2029, signalling that the cryptographically-relevant quantum computer threat window is closing faster than many organisations anticipated. This accelerates industry pressure to inventory and remediate legacy systems before quantum capabilities render current encryption obsolete.

Google, Enterprise organisations dependent on Google Cloud, Organisations using TLS/PKI infrastructure
highVulnerabilityEmerging

Multi-tenant SMS data exposure via parameter tampering in OpenCode messaging platform

OpenCode Systems OC Messaging and USSD Gateway versions 6.32.2 contain an insecure direct object reference (IDOR) vulnerability allowing authenticated users to access SMS messages from other tenants by manipulating company or tenant identifiers. This affects multi-tenant deployments handling sensitive communications.

CVE-2025-70614
OpenCode Systems OC Messaging 6.32.2, OpenCode Systems USSD Gateway 6.32.2
highMalwareContained

RedLine Infostealer Administrator Arrested: Law Enforcement Disrupts Malware-as-a-Service Operation

Hambardzum Minasyan, an Armenian national allegedly involved in developing and administering the RedLine infostealer, has been extradited to the United States. This arrest represents a significant enforcement action against a malware-as-a-service operation that has compromised thousands of organisations globally.

Organisations using compromised credentials, Enterprise networks, Financial institutions