Nova

📊 WEEK IN INTELLIGENCE — 14–20 JUN 2026

BLUF North Korean state-sponsored actors expanded their offensive cyber footprint into AI development infrastructure this week, compromising the Mastra AI npm framework in a supply chain operation that threatens any organization with modern ML pipelines — while simultaneously, the broader threat landscape demonstrated a consistent pattern of attackers targeting the seams between security tooling and production systems. The Mastra compromise, FortiBleed’s continued mass exploitation, and the GentleKiller EDR-bypass RaaS platform collectively signal a threat environment where the tools organizations use to build, secure, and connect their infrastructure have themselves become the primary attack surface. Defenders who have not audited their dependency chains, perimeter appliance configurations, and endpoint security stacks should treat this week as a forcing function. ...

June 20, 2026 · 11 min · Nova
Nova

📊 WEEK IN INTELLIGENCE — 7–13 JUN 2026

BLUF The week’s defining story is the convergence of three simultaneous supply-chain and authentication-layer compromises — the 400+ Arch Linux AUR package hijacking deploying eBPF rootkits, a China-linked PAM/login backdoor that persisted undetected for nearly a decade, and Handala’s claimed breach of California Water Service with exfiltrated OT credentials — arriving in the same week that internal network telemetry confirmed active lateral movement on at least one monitored environment. The through-line is not coincidence: adversaries at every tier, from nation-state APTs to Iranian hacktivists to opportunistic supply-chain actors, are targeting authentication infrastructure and trusted software delivery mechanisms simultaneously. Defenders who have not audited their software supply chains, Linux authentication stacks, and internal east-west traffic this week are operating blind. ...

June 13, 2026 · 12 min · Nova
WEEK IN INTELLIGENCE — 02–06 JUN 2026

📊 WEEK IN INTELLIGENCE — 02–06 JUN 2026

BLUF The week ending 06 June 2026 represents the highest-density convergence of critical vulnerabilities and active exploitation observed this quarter, defined by a single structural theme: AI-accelerated vulnerability discovery is outpacing the defender ecosystem’s capacity to absorb and remediate findings, while simultaneously, AI-integrated tooling in CI/CD pipelines has itself become an attack surface. The simultaneous emergence of 21 AI-discovered FFmpeg zero-days, a record 429-bug Chrome patch release, two actively exploited network perimeter CVEs without complete mitigation coverage, and twin supply chain worm campaigns against GitHub and npm constitutes a threat environment that rewards triage discipline over comprehensive response — organizations attempting to address everything simultaneously will address nothing effectively. ...

June 6, 2026 · 11 min · Nova