Cybersecurity Integration Digest

Supply Chain/Breaches/NHI: Megalodon, Glassworm, CISA Credential Leak, NHI Governance, AI Coding Agent Supply Chain Vector, Hugging Face Breach

Supply Chain/Breaches/NHI: Megalodon, Glassworm, CISA Credential Leak, NHI Governance, AI Coding Agent Supply Chain Vector, Hugging Face Breach

Key Questions

What is the status of the Megalodon supply chain attack?

The Megalodon attack affecting over 5,500 repositories remains active and continues to pose risks to open-source ecosystems.

How did the Hugging Face breach occur?

Attackers used a malicious dataset and code execution via an agentic harness across thousands of sandboxes, marking the first major breach involving autonomous AI agents.

What new supply chain vector involves AI coding agents?

AI coding agents skipping package verification has emerged as a major vector, enabling slopsquatting and Clinejection attacks.

Which organizations experienced major data breaches recently?

NAIC (3.1TB via Oracle zero-day), Medtronic (3.8M records), Novo Nordisk (1.3TB including AI model theft), and Accenture (35GB) suffered significant breaches.

What NHI governance developments are underway?

Cisco acquired Astrix and CrowdStrike launched Continuous Identity for AI Agents to address non-human identity risks.

What forensic tool addresses backdoored AI code completions?

CodeTracer provides forensic tooling to detect and attribute poisoned training data in AI coding assistants after incidents.

What fine did Italy impose on WINDTRE?

Italy's data protection authority fined WINDTRE €1.7 million for failures related to social engineering breaches.

How is CISA responding to the May credential leak?

CISA is strengthening protections for sensitive credentials following a major leak under congressional scrutiny.

Megalodon supply chain attack (5,500+ repos) remains active. Glassworm Unicode campaign (151+ repos) continues. NAIC data breach via Oracle zero-day by ShinyHunters (3.1TB). Medtronic breach (3.8M notified). Novo Nordisk breach (1.3TB, AI model theft). Accenture breach confirmed (35GB). Centers Laboratory breach (540k). NHI governance accelerating—Cisco acquires Astrix, CrowdStrike launches Continuous Identity for AI Agents. AI coding agents skipping package verification emerges as major supply chain vector (slopsquatting, Clinejection). CISA credential leak forensic report with congressional scrutiny. Okta extends identity platform to AI agents. Ghost accounts abusing GitHub API for mass recon campaign. Gitea Docker flaw (CVSS 9.8) actively probed. Vicarius survey: 79% breached by known vulns. New: WINDTRE fined €1.7M for social engineering breach. New: HelloNet APT abuses ViPNet update system via DLL sideloading. New: Open-source risk management article covers systemic vulnerabilities and AI agent risks. New: CodeTracer provides forensic tooling for backdoored code completions in AI assistants, enabling post-incident attribution of poisoned training data. New: Hugging Face suffered a major breach via malicious dataset and code execution, with attackers using agentic harness across thousands of sandboxes—first major breach involving autonomous AI agents, shifting incident readiness to self-hosted AI and open-weight models.

Sources (8)
Updated Jul 20, 2026
What is the status of the Megalodon supply chain attack? - Cybersecurity Integration Digest | NBot | nbot.ai