## Author: Claire Harwood

- 5th August 2026

## [Exploit Hunt: How Threat-Model-Led AI Hunting Finds Real Zero-Days — and Why It Beats Scanning and Pentesting](/content/exploit-hunt-threat-model-led-ai-zero-day-detection/index.html)

Exploit Hunt runs an adversarial three-persona pipeline inside Phoenix Purple’s knowledge graph: attacker, skeptic, exploit developer. Every reported finding ships as a runnable proof of concept, not a severity label. In one verified run, 3 target files produced 9 confirmed exploits — and the skeptic gate correctly killed every disputed finding before it reached proof.

Claire Harwood

- 4th June 2026

## [Miasma Is Back: npm Supply Chain Worm Drops binding.gyp Execution to Bypass Postinstall Monitoring](/content/miasma-wave2-npm-supply-chain-bindingyp-zero-cve-2026/index.html)

The Miasma npm worm is back with a second wave targeting 57 packages and 647,204 monthly downloads. Wave 2 drops lifecycle hooks and executes through binding.gyp, bypassing every scanner watching package.json. No CVE exists. The threat actor pivoted within 72 hours of public disclosure of Wave 1.

Claire Harwood

- 20th May 2026

## [GitHub Internal Repository Breach via Poisoned VS Code Extension (May 2026): TeamPCP Exfiltrates 3,800 Repos Through the Developer Trust Surface](/content/vs-code-extension-malware-github-breach-teampcp-2026/index.html)

TeamPCP (UNC6780) breached GitHub’s internal infrastructure on May 19–20, 2026 through a poisoned VS Code extension that ran silently on a developer’s endpoint and exfiltrated approximately 3,800 internal repositories. The attack produced no CVE. Standard CVE-feed scanners, SCA tools, and signed-provenance checks all missed it. This is exactly the zero-CVE developer trust surface gap Phoenix Blue Intelligence and Phoenix Blue Shield are built to close.

Claire Harwood
