Inside the Box
This week's threat landscape is dominated by supply chain compromise at industrial scale. The TeamPCP campaign has claimed its first named victim in Mercor, while Mandiant estimates thousands more are affected. North Korean hackers poisoned the axios npm package — downloaded over 100 million times per week. A new malware strain called DeepLoad uses AI-generated obfuscation and survives being removed from infected machines. Hasbro and Stryker are both dealing with operational disruption from cyberattacks. And yes, a coffee machine really did cause a corporate data breach. Peter and Emily cover it all, with practical takeaways for businesses of every size. In this episode: LiteLLM supply chain attack cascades to thousands of organisations Axios npm package compromised by North Korean threat actor Trojanised Claude Code repositories spreading malware on GitHub DeepLoad: AI-powered malware with ClickFix delivery and WMI persistence Hasbro and Stryker cyberattack operational impact The coffee machine that brought down a corporate network RSAC 2026: Attribution risks and AI budget warnings User behaviour as the primary entry point for attacks Outro and action items Episode tags: supply chain attack, LiteLLM, Trivy, axios, North Korea, Claude Code, DeepLoad, ClickFix, Hasbro, Stryker, IoT security, RSAC 2026 You'll want to adjust the chapter timestamps once the audio is produced to match the actual recording, but this gives you the structure to work from.
2 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Inside the Box!