Elfsmasher, PYPI, Facebook, Glassworm, Medtronic, OpenSSH, Sararimen, Aaran Leyland - SWN #576
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Elfsmasher, PYPI, Facebook, Glassworm, Medtronic, OpenSSH, Sararimen, Aaran Leyland - SWN #576” inside PodZeus.
A major supply chain attack on the Python Package Index (PyPI) has compromised version 0.23.3 of a popular package with a backdoor info stealer, exploiting a GitHub Actions flaw to forge signed releases and distribute malware through legitimate channels. The attack, which leveraged a malicious comment in a pull request to inject shell code and steal credentials, underscores the growing sophistication of software supply chain threats. Meanwhile, the Glassworm campaign has expanded its reach by planting 73 dormant extensions on OpenVSX, with six now active and exfiltrating crypto wallet data and GitHub credentials. Medtronic confirmed a cyberattack on its corporate IT systems, though it downplayed impact—raising concerns about transparency in critical infrastructure breaches. As AI tools like GitHub Copilot shift to usage-based billing, a new 'financial threat' emerges: users addicted to free AI may face steep costs, echoing past tech lock-in traps. The episode also highlights how AI accelerates existing attack patterns—reducing dwell time to just 22 seconds—while foundational weaknesses like poor patching and over-permissive access remain the root cause of most breaches. The host warns that 'old problems are new again,' urging organizations to prioritize cyber hygiene over AI hype.
Rotate all secrets and restore from a clean snapshot if you installed PyPI package version 0.23.3 due to a forged backdoor release.
Attackers exploited a GitHub Actions flaw via malicious pull request comments to steal tokens and publish malware under official release pipelines.
Glassworm now uses dormant extensions on OpenVSX that activate later with malicious dependencies, evading detection through typo-squatting and stealthy activation.
Medtronic confirmed a cyberattack but downplayed impact—highlighting the need for transparency in critical infrastructure breaches.
AI is not replacing old threat models but accelerating them: dwell time dropped to 22 seconds in 2025, and exploit windows are now days, not weeks.
…and 3 more takeaways available in PodZeus
Welcome & 50K YouTube Milestone
Doug White celebrates reaching 50,000 YouTube subscribers, reflecting on the community's growth and the show's mission to make security discussions engaging and accessible.
PyPI Supply Chain Attack via GitHub Actions
“They posted a malicious comment on a pull request and that exploited a GitHub action script injection flaw, which caused the workflow to execute shell code.”
Glassworm’s Dormant Extension Campaign
“Nearly 100 extensions for this were found back in March along with 20 sleeper extensions that were posted but had no comments.”
Medtronic Cyberattack & Transparency Concerns
“I don't know at this point, either not much actually happened or a lot happened and they're not saying.”
The Rise of AI-Driven Financial Threats
GitHub Copilot’s shift to usage-based billing creates a new 'financial threat'—users addicted to free AI tools may face steep, unexpected costs.
“They posted a malicious comment on a pull request and that exploited a GitHub action script injection flaw, which caused the workflow to execute shell code.”
“I don't know at this point, either not much actually happened or a lot happened and they're not saying.”
“If adults want to do that, no worries. Go crazy. That's your money and your problem. But these are games that appeal to kids.”
Host
Guest
Doug White
person
PyPI
product
Glassworm
other
GitHub Actions
product
OpenVSX
product
Aaron Leland
person
Medtronic
organization
GitHub Copilot
product
Townstar
media
Elf Smasher
media
DexterBot, Darksword, Eviltokens, Tubular Bells, Claude, Drift, Gmail, Josh Marpet... - SWN #569
Security Weekly News (Audio) • 32m • 4/3/2026
Staypuft, Claude, One Pixel, deepfakes, Raccoon, BOFH, Satoshi Nakamoto, Josh Marpet. - SWN #571
Security Weekly News (Audio) • 30m • 4/10/2026
Zuckbot, Rockstar, Klaude, Browsers Galore, Microsoft 365, ATC, Kieran Human and more - Kieran Human - SWN #572
Security Weekly News (Audio) • 36m • 4/14/2026
Dougbot, RedSun, ATHR, Vishing, Cisco, Google, Chrome, Severance, Shor, Josh Marpet.. - SWN #573
Security Weekly News (Audio) • 33m • 4/17/2026
Robosawmill, Gentleman, Vercel, GitHub, Claude, RS232, Josh Marpet, and More... - SWN #574
Security Weekly News (Audio) • 32m • 4/21/2026
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “Elfsmasher, PYPI, Facebook, Glassworm, Medtronic, OpenSSH, Sararimen, Aaran Leyland - SWN #576” inside PodZeus.
Start discovering podcast insights today
Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.
No credit card required • 7-day trial • Cancel anytime
