Lapsus$ Rising: Identity-Driven Extortion’s Breakout
No zero-days, no malware — just MFA fatigue, SIM swaps, and help-desk social engineering. How Lapsus$ broke every assumption.
No zero-days, no malware — just MFA fatigue, SIM swaps, and help-desk social engineering. How Lapsus$ broke every assumption.
Two months of undetected access to managed WordPress hosting, wholesale sFTP and database credential harvesting, and SSL keys in the bargain.
Popular packages with dormant maintainers pushed info-stealers through postinstall scripts. The registry was fine; the accounts were not.
REvil turned Kaseya’s remote-management platform into a mass-encryption weapon, hitting ~60 MSPs and up to 1,500 downstream businesses days before a patch could land.
780 GB of Frostbite engine and FIFA code left EA through a purchased Slack cookie and one help-desk MFA reset. The breach that proved sessions, not passwords, are the modern front door.
A tampered Codecov Bash Uploader quietly shipped CI environment variables — cloud keys, tokens, signing material — to attackers for two months. The curl-pipe-bash trust model dissected, and how build supply-chain security was rewritten after.
No exploits, no stolen credentials — Alex Birsan’s February 2021 research got code executed inside 35+ major companies by registering their internal package names on public registries and letting version arithmetic do the rest. The incident file on the cheapest supply-chain attack ever demonstrated.
The full incident file on the SolarWinds SUNBURST supply-chain attack: how SVR-linked actors compromised the Orion build pipeline, trojanized signed updates reaching 18,000 customers, hand-picked under 100 targets including nine US federal agencies, and forged SAML tokens to persist. Includes the technical anatomy, timeline, impact numbers, and the build-pipeline hardening lessons that still define defender programs in 2026.
The two post-deployment risks in the OWASP Agentic Skills Top 10: AST07 malicious updates riding channels with no signatures, pinning or freeze mode (40,000 exposed instances in 24 hours), and AST08 scanners that structurally lag base64, zero-width, pure-natural-language and .pyc evasion. Digest pinning, PASS/FAIL/INCOMPLETE pipelines, and Unicode strip ranges — dissected.
AST02 of the OWASP Agentic Skills Top 10 maps attacks on the skill distribution layer: registry flooding, dependency confusion, config files that execute on clone (CVE-2025-59536, CVE-2026-21852), and maintainer takeover. With Trail of Bits' evidence that every marketplace scanner can be bypassed.
The OWASP Agentic Skills Top 10 maps the 10 risks of the AI-agent skill ecosystem - malicious skills, supply chain compromise, over-privileged manifests, metadata attacks, weak isolation, update drift, scanning gaps, governance failures and cross-platform reuse - with real 2026 evidence.
A deep dive into securing AI agent supply chains — MCP server vetting, dependency integrity, sandboxing, and trust anchors for AI infrastructure.