ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

General News

Summary

This bulletin covers a wide range of cybersecurity threats and defensive updates affecting software teams and security buyers. It highlights supply-chain malware, credential theft, phishing against AI agents, Exchange spoofing risk, and abuse of common developer ecosystems like npm, GitHub, and WooCommerce. It also notes a Claude Code GitHub Action patch that closes a secret-exposure issue in AI-assisted CI/CD workflows. The overall theme is that attackers are increasingly targeting software supply chains, identity systems, and AI-enabled development tools. Security teams and platform vendors should treat these issues as signals to review controls around code, identity, and agent permissions.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AskAI Classifications

Labels
AI Software SaaS Developer Tools

Linked Companies

Anthropic
$10M to $25M