Cybersecurity Integration Digest

Supply Chain/Breaches/NHI: Megalodon, Glassworm, CISA Credential Leak, NHI Governance, AI Coding Agent Supply Chain Vector, Hugging Face Breach, Craneware

Supply Chain/Breaches/NHI: Megalodon, Glassworm, CISA Credential Leak, NHI Governance, AI Coding Agent Supply Chain Vector, Hugging Face Breach, Craneware

Key Questions

What supply chain attacks remain active?

Megalodon has impacted over 5,500 repos while Glassworm's Unicode campaign continues across 151+ repos, with AI coding agents introducing new vectors like slopsquatting and Clinejection.

Which major breaches involved data theft or model exfiltration?

NAIC suffered a 3.1TB breach via Oracle zero-day, Novo Nordisk lost 1.3TB including AI models, Accenture confirmed a 35GB breach, and Craneware exposed data from thousands of US hospitals.

How is NHI governance evolving?

Cisco acquired Astrix and CrowdStrike launched Continuous Identity for AI Agents, while Okta extends its identity platform to AI agents amid rising concerns over ghost accounts and GitHub API abuse for reconnaissance.

Megalodon supply chain attack (5,500+ repos) remains active. Glassworm Unicode campaign (151+ repos) continues. NAIC data breach via Oracle zero-day by ShinyHunters (3.1TB). Medtronic breach (3.8M notified). Novo Nordisk breach (1.3TB, AI model theft). Accenture breach confirmed (35GB). Centers Laboratory breach (540k). NHI governance accelerating—Cisco acquires Astrix, CrowdStrike launches Continuous Identity for AI Agents. AI coding agents skipping package verification emerges as major supply chain vector (slopsquatting, Clinejection). CISA credential leak forensic report with congressional scrutiny. Okta extends identity platform to AI agents. Ghost accounts abusing GitHub API for mass recon campaign. Gitea Docker flaw (CVSS 9.8) actively probed. Vicarius survey: 79% breached by known vulns. WINDTRE fined €1.7M for social engineering breach. HelloNet APT abuses ViPNet update system via DLL sideloading. Open-source risk management article covers systemic vulnerabilities and AI agent risks. CodeTracer provides forensic tooling for backdoored code completions in AI assistants. New: Hugging Face suffered a major breach via malicious dataset and code execution, with attackers using agentic harness across thousands of sandboxes—first major breach involving autonomous AI agents, shifting incident readiness to self-hosted AI and open-weight models. New: Craneware breach exposes significant data from thousands of US hospitals and pharmacies (regulatory filing, non-sensitive data claim). New: Paidwork breach exposes 23M users.

Sources (2)
Updated Jul 21, 2026
What supply chain attacks remain active? - Cybersecurity Integration Digest | NBot | nbot.ai