RubyGems temporarily suspends new account sign-ups due to malicious attack
The organization said that more than 500 malicious packages uploaded during the campaign.
The organization said that more than 500 malicious packages uploaded during the campaign.
The brothers wiped approximately 96 government databases, including investigative files and FOIA records maintained by several federal agencies.
Organizations are strongly recommended to apply security updates ASAP.
The attackers were able to generate valid SLSA Build Level 3 provenance attestations, making the infected packages appear authentic and cryptographically verified.
TeamPCP gained access to Checkmarx GitHub repositories using credentials stolen during the March Trivy compromise.
Telemetry identified more than 2,000 attacker IP addresses involved in automated exploitation campaigns worldwide.
The Python-based exploit showed several signs of AI generation, including unusually detailed educational docstrings, and a hallucinated CVSS score.
The incident was part of a broader cyber campaign targeting nine federal, state and municipal government agencies across Mexico.
Authorities say Dmitry Novikov headed “La Compañía” aka “Lakhta” network, a covert influence operation allegedly linked to Russian intelligence and the Wagner PMC.
The rebooted marketplace gained more than 22,000 users and over 100 vendors while generating at least €3.6 million ($4.2 million) in revenue.
Showing elements 221 - 230