This week’s roundup covers malware, supply chain abuse, exposed infrastructure, and high-profile criminal cases, including PoeLLM, GhostAction, and a compromised Tensorlake npm SDK. It also highlights notable developments involving CISA, Nvidia DCGM Exporter, South Korean bank attacks, and the sentencing of the Empire Market co-founder. #PoeLLM #GhostAction #Tensorlake #CISA #Nvidia #DCGMExporter #EmpireMarket
Keypoints
- PoeLLM hides its command-and-control server in a GitHub-hosted poem.
- GhostAction spread to 772 more GitHub repositories and stole thousands of secrets.
- A jury convicted Jonathan Spalletta for the Uranium Finance hacks and laundering stolen funds.
- Researchers found exposed Nvidia DCGM Exporter instances leaking telemetry from more than 12,000 GPUs.
- The Tensorlake npm SDK was compromised to deploy a Shai-Hulud-style credential-stealing worm.