Week in review: Rail transport cybersecurity, “verified” OAuth apps used to infiltrate organizations
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant says an attacker hijacked an AI coding-assistant session at a SaaS provider and spread the Shai-Hulud worm across roughly 100 repositories, stealing secrets.
Mandiant's September 2026 report describes an attacker hijacking an active AI coding-assistant session at an unnamed SaaS provider, then getting a poisoned package recommendation accepted and installing an infostealer via a malicious PyPI package. The attacker stole GitHub OAuth tokens, deployed the self-spreading Shai-Hulud worm across approximately 100 internal repositories, and stole repository secrets and product source code. Poisoning a package in the company's official namespace caused a second employee to pull the compromised version and become infected. Mandiant recommends verifying AI-recommended dependencies against checksums and allowlists, keeping secrets out of extension reach, and routing dependency traffic through internal repositories.
KlueセキュリティインシデントとRecorded Futureへの影響
Recorded Future disclosed a Klue incident that exposed some Salesforce business data, including contacts and emails, via a compromised OAuth token.
Recorded Future disclosed that unauthorized activity in marketing vendor Klue's integration layer, starting June 12, 2026 and contained the same day, affected some of its Salesforce data through a compromised OAuth token in the Salesforce-Klue integration. Impacted fields are limited to business data such as customer contact names, email addresses, and possibly business contract information. No evidence indicates Recorded Future's core platform, Intelligence Graph, internal databases, or customer platform data were accessed. The company revoked all relevant OAuth tokens, coordinated with Salesforce and law enforcement, and began reviewing all third-party Salesforce integrations.