mitre-t1195
447 articles with this tag
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
MEDIUM
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
NuGet typosquat targets Digitain game results
SharePoint vulnerability steals machine keys; fourth recent exploit
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
SleeperGem attack targets Ruby ecosystem with malicious gems
New npm malware cluster targets Vite ecosystem
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Suno AI music generator reportedly hacked, source code allegedly reveals data scraping
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
NPM ecosystem hit with two new supply chain compromises
The serpent’s tongue: Luring the Python out of its den
Multiple Jscrambler Packages Impacted by Supply Chain Attack
Jscrambler npm package version 8.14.0 contained a malicious infostealer
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
OpenMandriva Linux project reportedly targeted in attempted sabotage after contributor dispute
Injective Labs SDK npm package compromised to steal cryptocurrency keys
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
VU#734812: Xerte Online Toolkit contains an authentication bypass that allows for RCE
North Korean PolinRider supply chain attack targets 108 unique repos
North Korean Hackers Target Open Source Developers in Supply Chain Attacks
Warning Over “Industrialized” Cyber-Attacks After Ransomware Gang Partners With TeamPCP
Vect and TeamPCP partner for ransomware campaigns
Polymarket customers lose $3 million in supply-chain attack
More Klue Breach Victims Identified as Hackers Get Hacked
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Ransomware gangs find Europe’s weakest link in third-party suppliers
More Malicious OpenClaw Skills Threaten AI Supply Chain
TanStack npm compromise: 42 packages published with valid SLSA provenance via OIDC token theft from runner memory
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
Github got Hacked by CATS
Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking
LastPass customer data exposed through Klue supply chain attack
Lookalike npm Package Hides a Multi-Stage Windows RAT
What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
Security shops among the 'hundreds' of Klue hack victims
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Microsoft Attributes Mastra AI Supply Chain Attack to North Korea
North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
More Cybersecurity Firms Disclose Impact From Klue Hack
Microsoft links Mastra AI supply chain attack to North Korean hackers
ShapedPlugin update flow hacked to infect WordPress sites
Mastra npm packages compromised in 'easy-day-js' supply chain attack
Malicious JetBrains plugins steal AI API keys from developers
AUR suspends new registrations as 1,500-plus malicious packages flood repository
Securing CI/CD in an agentic world: Claude Code Github action case
A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope
Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
144 Mastra npm Packages Compromised via Hijacked Contributor Account
npm Supply Chain Cryptocurrency Malware
PSA: Supply Chain Compromise Targets ShapedPlugin, Backdoored Pro Plugins Distributed via Official Channels
Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
OptinMonster WordPress plugin hacked in CDN supply-chain attack
Attackers Hijack Popular WordPress Plugins to Deploy Backdoors
China-linked spies backdoored authentication stack to stay hidden for years
Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer
Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
Malicious npm packages abuse dependency confusion to profile developer environments
Interpol Dismantles SniperDz Phishing-as-a-Service Platform
OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
The ‘Miasma’ worm source code briefly leaked on GitHub
Mini Shai-Hulud ‘Hades’ variant affects 23 PyPI package versions
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
Microsoft investigates breach of open-source projects after malware injection
Miasma worms its way onto GitHub as attack kit goes open source
GitHub disables Microsoft repos pushing password-stealing malware
Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud
⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections
Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack
IronWorm malware, similar to Shai-Hulud, hits 57 projects across 9 organizations
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
Securing CI/CD in an agentic world: Claude Code Github action case
Hola browser supply chain attack delivers cryptocurrency miner
Rust-Written IronWorm Hits NPM Supply Chain
Hola Browser for Windows compromised to deliver cryptominer
New IronWorm malware hits 36 packages in npm supply-chain attack
Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp
Typosquatted npm packages used to steal cloud and CI/CD secrets
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
Why supply chain attacks work and what detection can actually do about it
Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes
Infected Red Hat npm packages expose developer credentials
Supply Chain Attack Hits 32 Red Hat NPM Packages
Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets
Red Hat npm packages compromised to steal developer credentials
Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week
Dozens of Red Hat packages backdoored through its offical NPM channel
Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
Containers on fire: from container escapes to supply chain attacks
Malicious npm packages abuse dependency confusion to profile developer environments
Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries
A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.)