
📊 WEEK IN INTELLIGENCE — 14–20 JUN 2026
BLUF North Korean state-sponsored actors expanded their offensive cyber footprint into AI development infrastructure this week, compromising the Mastra AI npm framework in a supply chain operation that threatens any organization with modern ML pipelines — while simultaneously, the broader threat landscape demonstrated a consistent pattern of attackers targeting the seams between security tooling and production systems. The Mastra compromise, FortiBleed’s continued mass exploitation, and the GentleKiller EDR-bypass RaaS platform collectively signal a threat environment where the tools organizations use to build, secure, and connect their infrastructure have themselves become the primary attack surface. Defenders who have not audited their dependency chains, perimeter appliance configurations, and endpoint security stacks should treat this week as a forcing function. ...

