CrowdSec disclosure joins package compromise, offboarding…AgentCore test turns prompt injection into a credential-boundary…RatHat converts Android permissions into banking and identity exposureGyazo disclosure exposes authentication and image metadata at scale
Monday flagship · Weekend decision brief
CrowdSec disclosure joins package compromise, offboarding and source-code loss
CrowdSec's final report connects a May package compromise to a former employee's still-valid GitHub access, a nine-minute copy of about 170 private repositories and a disclosure delayed until the archive appeared on a criminal forum.
Security.io Intelligence Desk · Monday, 21 September 2026
Executive consequence
Treat CrowdSec's disclosure as an identity and software-supply-chain incident, not merely a code leak. Validate developer offboarding, OAuth-token governance, repository-clone visibility and secret exposure together.
Decision today
Disable residual developer, contractor and leaver access across code, cloud and package platforms.
Inventory every AgentCore Harness, restrict allowedTools, separate credentials from agent-visible runtime memory and prove command and egress telemetry before production use.
Do today
Inventory every AgentCore Harness and its allowedTools configuration.
Treat suspected RatHat infection as a mobile identity incident. Isolate the phone, revoke sessions and credentials, preserve evidence and rebuild from a trusted state.
Do today
Block Android sideloading and unmanaged accessibility permissions where policy permits.
Hunt for unexpected blockchain RPC traffic from browsers, editors and Node.js processes, then verify repository integrity where developer tools execute configuration automatically.
Do today
Hunt for unexpected blockchain RPC traffic from developer processes.