Dutch Cybersecurity Act: is your organisation secure online? →

Loki Intelligence — Security Briefs · Published

Daily Brief: Dependency Update Delays and Telegram-Based C2

Today’s brief highlights new supply chain safeguards designed to slow the spread of malicious package releases through automated dependency updates. It also covers reported espionage activity using Telegram infrastructure for command-and-control against government targets in the Middle East.

Signal 01 · BleepingComputer

GitHub, PyPI add time-based defenses against supply chain attacks

BleepingComputer reports that GitHub and PyPI are adding time-based protections to Dependabot so teams can avoid immediately adopting newly released packages that may later prove malicious.

Why it matters: Engineering teams should review dependency automation settings and consider update delay windows for ecosystems with frequent package churn or elevated supply chain risk.

Source: BleepingComputer

Signal 02 · The Hacker News

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

The Hacker News says GitHub’s new Dependabot cooldown can wait at least three days after a package release before opening an update pull request, giving maintainers and scanners more time to detect abuse.

Why it matters: Security and platform teams should align cooldown policies with patch SLAs, ensuring critical security fixes are not unnecessarily delayed while routine updates get added scrutiny.

Source: The Hacker News

Signal 03 · The Hacker News

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

The Hacker News reports that an East Asia-linked threat actor targeted Middle East government entities with newly documented malware families, including TELESHIM, which uses Telegram for command-and-control activity.

Why it matters: Defenders in government and regulated sectors should monitor unusual Telegram-related network patterns, tighten endpoint telemetry coverage, and validate detections for novel malware families.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.