Supply Chain Attack Targets AI Startup Mercor
Attack originated from GitHub Actions misconfig in Trivy (Aqua Security).
Mandiant CTO estimates 1,000+ SaaS environments impacted.
Lapsus$ claims data breach at Mercor, but no customer data confirmed.
TeamPCP partners with CipherForce and Vect for data extortion.
2 weeks ago