Attackers can register it first. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
Zero Trust Weekly

This week in Zero Trust

Verify the user, device, software, and source

Estimated reading time: 4–5 minutes

 

In this issue:

  • Portable apps can create a blind spot in patch management
  • How AI is making package supply chain attacks harder to spot
  • Why device identity matters after authentication
  • Threats: AI coding assistant in SaaS platform hijacked, critical GitLab vulnerability under active exploitation
View in browser

Manage preferences

From the CEO

Credential theft shouldn't lead to data theft

 

"Turns out the Florida DMV breach that resulted in the theft of more than 200,000 records was run-of-the-mill credential theft. It kills me when this happens because it doesn't need to. If you authenticate the machine in addition to the user, stolen credentials become irrelevant." - Danny Jenkins

From the ThreatLocker blog

 

How AI is changing package supply chain risk

Why you should treat every package name as untrusted input

 

Typosquatting relies on imitation. An attacker may add, remove, or replace characters in the name of a popular package or use misleading prefixes or metadata to make an unrelated package appear connected to a trusted project. Slopsquatting removes the need to imitate an existing package. Attackers register package names that AI coding tools are likely to hallucinate and wait for those nonexistent packages to appear in AI-generated code.

 

In a 2025 study of more than half a million AI-generated code samples, more than 200,000 were unique hallucinated package names. 

How to reduce npm and PyPI package risk

User identity is not enough 

A valid login does not always come from a trusted device

 

An employee can successfully complete MFA from a personal device or attackers can replay stolen session tokens from unknown hardware. User identity only tells you who the person or service requesting access is. Device identity tells you what is connecting, adding another condition a threat actor would need to satisfy even when they already have valid credentials or tokens. 

How to verify the user and the device

How to patch portable apps without losing control

Portable apps can sit outside where many patching tools expect to search

 

Many patching tools search installation records for vulnerable apps, but many portable apps do not appear in those records. So how can administrators find this vulnerable code before it is exploited? According to ThreatLocker CPO Rob Allen, looking for file signatures rather than relying solely on installation records is the first step. 

 

Read what Rob has to say about finding portable apps, patching them, and how to verify the risk has been reduced.

Three steps to patching portable apps
Register now: Debunking the cybersecurity myths that leave you exposed | Sept. 29, 11 a.m. EDT

Threats you need to know

 

Attackers hijack AI coding assistant and spread Shai-Hulud across 100 repositories

Mandiant disclosed the incident in September but did not say when it occurred

  • What's happening: An AI assistant with access to a development environment became part of the attack path through an organization. Mandiant says attackers were able to hijack an AI coding assistant session at an undisclosed SaaS provider and later spread the Shai-Hulud worm across about 100 internal code repositories. The compromise exposed source code and repository secrets.

  • What defenders need to know: AI-generated package recommendations should not be trusted blindly. Validate against approved allowlists before execution and restrict access to OAuth tokens, secrets, and other sensitive credentials.

CISA warns attackers are actively exploiting critical GitLab vulnerability

Unauthenticated attackers could access sensitive files on GitLab servers

  • What's happening: CISA has added vulnerability CVE-2026-85706 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The critical GitLab flaw can allow unauthenticated attackers to read files from vulnerable servers, potentially exposing secrets and configurations. GitLab released a patch last week, while researchers have already observed in-the-wild probing for vulnerable servers.

  • What defenders need to know: Continuously identify and patch vulnerable software, especially internet-facing systems, because attackers are actively scanning for opportunities to exploit newly disclosed flaws.

Meet ThreatLocker near you next week

 

Atlanta | Netherlands | London | Barcelona | Montreal | Chicago | San Diego

See all upcoming events
ThreatLocker: Zero Trust Platform | Zero Trust Weekly

ThreatLocker, 1901 Summit Tower Blvd, Orlando, Florida 32810, United States

Manage preferences

Connect with us

                             

©2026 ThreatLocker Inc., All Rights Reserved