Github got Hacked by CATS

Github got Hacked by CATS

Source: YouTube · John Hammond · published Jun 24, 2026 · 17:18

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The cybersecurity industry is facing a massive surge in software supply chain attacks, driven by hacker groups like Team PCP who are poisoning open-source code at an unprecedented scale 0:00.

Key Takeaways:
• Team PCP has been actively poisoning open-source code, as highlighted in a recent Wired article, with one of their recent attacks even impacting GitHub directly 0:10.
• These attacks are particularly dangerous because threat actors inject malware into legitimate software applications and dependencies that organizations already trust and use 0:32.
• This current wave of supply chain compromises mirrors the devastating impact of past notorious incidents like SolarWinds, 3CX, and Axios 0:45.

As these malicious campaigns grow in scale, organizations must critically evaluate the security of their software dependencies to avoid becoming collateral damage 0:05.

Sources:

  • 0:00 Introduction to the recent rampage of software supply chain attacks
  • 0:10 Details on Team PCP poisoning open-source code and affecting GitHub
  • 0:32 Explanation of why supply chain attacks are sinister and effective
  • 0:45 Mention of historical supply chain attacks like SolarWinds and 3CX

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

In May of 2026 and some time leading up to it, the cyber security industry has seen an absolute rampage of software supply chain attacks. There was a recent news article and headline from Wired that says a hacker group is poisoning open-source code at an unprecedented scale. And this hacker group is called Team PCP. One of their most recent attacks actually affected GitHub themsel. But I'm sure you have seen the headlines. You've heard the news. Software supply chain attacks are super duper sinister because the threat actor is taking legitimate software applications and programs that you might already use or depend on for software that you write in your organization and they inject their own malware. You can think of some very well-known incidents in the past like Solar Winds or 3CX or Axi…