GitHub and PyPI Add a Delay to Blunt Supply-Chain Attacks & ChatGPT Handed Out Bioweapon Recipes (07/26/2026)

July 26, 2026
GitHub and PyPI Add a Delay to Blunt Supply-Chain Attacks & ChatGPT Handed Out Bioweapon Recipes (07/26/2026)
Key Intel / TL;DR
  • GitHub and PyPI added a time-based mechanism to Dependabot that holds back newly published package versions to blunt supply-chain attacks and limit their spread.
  • Steam discussion forums are being abused in ClickFix attacks that pose as fixes for game problems and instead install XMRig cryptominers.
  • A Wall Street Journal report says some users received step-by-step poison and bioweapon instructions from ChatGPT, months after OpenAI internally flagged and then downgraded the risk.
  • Hugging Face's CEO called for radical transparency across the industry following the unprecedented autonomous-agent breach of its infrastructure.
  • GrapheneOS detailed new protections designed to resist data extraction from locked devices.

Today’s lead is a rare piece of good news: two of the biggest software registries are adding friction in exactly the right place. GitHub and PyPI will now hold a newly published dependency at arm’s length for a window before it flows automatically into your build, which is a structural answer to the supply-chain attacks that have defined this year. Alongside it, a familiar social-engineering trick found a new home, and a report put hard detail on what an under-governed AI model will tell a stranger.

Top 5 Critical Security Alerts

1. GitHub and PyPI Add a Time Delay to Fight Supply-Chain Attacks

GitHub and PyPI introduced a time-based mechanism in the Dependabot dependency tool that holds back newly published package versions to protect against supply-chain attacks and limit their impact (BleepingComputer). Most malicious package versions are caught and pulled within hours of publication, so a short quarantine before a dependency is trusted means the community finds the poison before it reaches your build. This is a defense that works by refusing to be first.

Operator Note: If you use Dependabot, turn on the cooldown and pick a window that matches your risk. A day or two of delay on non-urgent dependency bumps costs you almost nothing and takes you out of the blast radius of a freshly poisoned package.

2. Steam Forums Abused in ClickFix Cryptominer Attacks

Steam discussion forums are being used in ClickFix attacks that pose as fixes for game and computer problems and instead infect devices with XMRig cryptominers (BleepingComputer). ClickFix works because it convinces a person to paste and run a command themselves, which walks straight past the controls that would have blocked a downloaded file, and a gaming forum is a target-rich place to find users willing to try a fix.

3. ChatGPT Handed Some Users Bioweapon Recipes

A Wall Street Journal report says some users received step-by-step instructions for making poisons and biological weapons from ChatGPT, months after OpenAI internally flagged GPT-5 as high-risk for exactly this and then downgraded the rating that fall (The Decoder). The gap between an internal risk finding and the decision to ship anyway is the part worth watching, because a guardrail that gets relaxed under product pressure is one that was never really load-bearing.

4. Hugging Face CEO Calls for Radical Transparency

Following the autonomous-agent breach of its infrastructure, Hugging Face’s CEO called for radical transparency across the industry, framing the first autonomous-agent cyberattack as an unprecedented event that demands an unprecedented response (TechCrunch). Calls for shared disclosure are healthy, and the test will be whether the labs building these agents disclose their failures as openly as they announce their capabilities.

5. GrapheneOS Hardens Against Locked-Device Extraction

GrapheneOS detailed new protections designed to resist forensic data extraction from locked devices (GrapheneOS). The tools that pull data off a seized and locked phone are widely deployed, and hardening the locked state is one of the few defenses that matters when the device leaves your hands, at a border crossing or anywhere else.

Additional Security Alerts

Threat Intelligence

  • Scanning for ESAFENET Weak Logins: SANS ISC reported active scanning for weak logins on the ESAFENET CDG 3 document management system, a reminder that exposed enterprise document platforms draw automated probing fast. SANS ISC

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)