Top Story — The Race at Agentic Speed: Two things happened in the same week that belong in the same sentence.
TeamPCP releases Shai-Hulud source code, launches BreachForums "supply chain challenge.": The group posted the complete worm framework to GitHub (since removed, but forked) with detailed deployment instructions, and announced a contest on BreachForums offering $1,000 in Monero to anyone who uses it to compromise open-source packages.
TanStack CI cache poisoned, hitting OpenAI and Mistral AI.: A pull request from a throwaway fork (attributed to TeamPCP's ongoing supply-chain campaign) triggered a workflow that wrote to the shared CI cache.
node-ipc compromised via inactive maintainer account (690K weekly downloads).: Three malicious versions exfiltrate credentials and secrets via DNS TXT queries to a fake Azure-themed domain — same package that shipped protestware in 2022, different attacker, far more capable.
Palo Alto Networks' first AI-driven "Patch Wednesday" produced 26 CVEs — versus their typical fewer than five.: As part of Project Glasswing and the Trusted Access for Cyber program, Palo Alto ran frontier models (Mythos, Claude Opus 4.7, GPT-5.5-Cyber) against their own 130+ products.
XBOW independently benchmarks Anthropic's Mythos for offensive security.: Confirmed: Mythos is "a significant step up over all existing models" for finding vulnerability candidates from source code.
Akamai acquires LayerX for $205M (all-cash).: AI and browser security platform providing shadow AI discovery, gen-AI data loss prevention, and protection for AI browsers and plugins.
OpenAI in talks with EU regulators to provide access to a cyber-focused GPT-5.5 model: that can identify and exploit software vulnerabilities, after EU cybersecurity agencies were unable to gain access to Anthropic's Mythos.