Were Sorry They Werent episode artwork

EPISODE · Jun 1, 2026

Were Sorry They Werent

from CyberPulse · host Tushar Vartak

TeamPCP struck Checkmarx for the second time in a month, poisoning official Docker Hub images (KICS), VS Code extensions, and GitHub Actions — then reaching Bitwarden CLI v2026.4.0 through the compromised pipeline. The attack is a self-propagating worm using stolen GitHub credentials to inject malicious workflows across repositories. Blast radius spans Docker Hub, VS Code, Open VSX, GitHub Actions, npm, and a major password manager. LMDeploy, an AI LLM deployment toolkit, was exploited within 13 hours of disclosure (CVE-2026-33626, CVSS 7.5) — the fourth AI platform exploitation tracked after Langflow, Flowise, and Marimo. A newly documented threat group uses Discord, Slack, and M365 Outlook as covert C2 channels via the Microsoft Graph API. Commercial shipping vessels were seized in the Strait of Hormuz, escalating physical supply chain risk for Gulf enterprises.

Episode metadata supplied by the publisher feed · Published Jun 1, 2026

Embed this episode

NOW PLAYING

Were Sorry They Werent

0:00 0:00

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this CyberPulse episode published?

This episode was published on June 1, 2026.

Can I download this CyberPulse episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!