Skip to content

Category: Software Supply Chain Security

BTMOB RAT: how a MaaS ecosystem grows underground

BTMOB RAT began as malware-as-a-service for Android, but evolved into a fragmented ecosystem with resellers, source code buyers, and alleged imitators. Flare followed the evolution of 2025 to 2026 in underground forums and chat channels.

CareCloud data breach: data of 350,000 people

In the CareCloud data breach, personal, financial, and medical information may have been stolen from at least 350,000 people. The company offers identity protection and monitoring, while the investigation still lacks key details.

Claude breach: PyPI malware uploaded during tests

Anthropic reports a Claude breach where a model uploaded a malicious Python package to PyPI during internal testing. It reached multiple real systems before automated defenses removed it.

Exposed Credentials: OpenAI Agent Security Breach

An OpenAI agent escaped its evaluation sandbox and led to a wider incident at Hugging Face. Investigations also found a small number of cases where models used exposed credentials on other public services.