mitre-t1195
512 articles with this tag
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
MEDIUM
CRITICAL
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
MEDIUM
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
HIGH
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Shai-Hulud npm worm resurfaces, bypassing security scans
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Coder platform targeted by attackers delivering malicious Terraform modules
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
Exploited JFrog Artifactory bug puts software supply chain on alert
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant
Trusted Chrome, Edge extensions weaponized in supply chain campaign
Authorities arrest 2 alleged members of prolific hacking group TeamPCP
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Australian cops cuff alleged TeamPCP masterminds
Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos
Two alleged TeamPCP hackers arrested over global supply chain attacks
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
'HTTP Terminator' Hunts for Novel Desync Attacks
You could've applied all 1,449 Oracle patches and still been hit by this attack
Iran-linked cyberattack shut down a UK power plant
Hackers poison popular Rust crates to steal developers' credentials
North Korean Hackers Tied to Rust Supply Chain Attack
Rust Supply Chain Attack Linked to North Korean Hackers
Backdoored Rust packages hit crates.io, exposing developers to malware at build time
Hackers compromise Rust crate arrayref to inject malware
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
JFrog Artifactory Flaws Enable Software Supply Chain Attacks
Hackers Using AI to Target Siemens PLCs in Critical US Sectors
153GB of stolen credentials surface after LiteLLM supply chain attack
LiteLLM supply chain attack impacted over 2,500 organizations
Terabytes of credentials leaked in massive supply-chain attack
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
LexisNexis services offline due to unusual activity on third-party vendor servers
Attackers exploit AI skills registry for credential theft
Coruna, DarkSword iOS Exploits Proliferate Globally
PSA: Supply Chain Compromise in BdThemes Ecosystem via Poisoned API Response
QuickFox Supply Chain Attack
Trojanized AI skills gain 1.7M installs in agent-targeted attack
Python package security in 2026: How supply chain attacks are targeting your AI development environment
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
Flaws in Google APK for Python Unlock Agent-to-Agent Attack
QuickFox VPN targeted in long-standing supply chain attack delivering FDMTP backdoor
Open-source software’s archenemy TeamPCP goes back further than anyone thought
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
ChainDrop credential stealing worm infects over 400 npm packages
Massive supply-chain attack compromises 440 packages under four hours
Keyv, cacheable npm supply chain attack hits 400-plus packages
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
Google dev kit spurs first-ever agent-on-agent violence
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Adform supply-chain attack replaced crypto wallet addresses
Arch Linux temporarily disables AUR package adoption amid malicious takeover surge
AI is 'both the weapon and the target' in latest wave of cyberattacks
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Amazon attributes axios, debug, chalk NPM attacks to DPRK’s Sapphire Sleet
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks
AI Harnesses Burst With Potential Exploit Opps
Amazon identifies North Korean hacker group behind open-source supply chain attacks
A little-known npm package was North Korea’s warm-up act for the axios hack
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
NuGet typosquat targets Digitain game results
SharePoint vulnerability steals machine keys; fourth recent exploit
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
SleeperGem attack targets Ruby ecosystem with malicious gems
New npm malware cluster targets Vite ecosystem
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Suno AI music generator reportedly hacked, source code allegedly reveals data scraping
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
NPM ecosystem hit with two new supply chain compromises
The serpent’s tongue: Luring the Python out of its den
Multiple Jscrambler Packages Impacted by Supply Chain Attack
Jscrambler npm package version 8.14.0 contained a malicious infostealer
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
OpenMandriva Linux project reportedly targeted in attempted sabotage after contributor dispute
Injective Labs SDK npm package compromised to steal cryptocurrency keys
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
VU#734812: Xerte Online Toolkit contains an authentication bypass that allows for RCE
North Korean PolinRider supply chain attack targets 108 unique repos
North Korean Hackers Target Open Source Developers in Supply Chain Attacks
Warning Over “Industrialized” Cyber-Attacks After Ransomware Gang Partners With TeamPCP
Vect and TeamPCP partner for ransomware campaigns
Polymarket customers lose $3 million in supply-chain attack
More Klue Breach Victims Identified as Hackers Get Hacked
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Ransomware gangs find Europe’s weakest link in third-party suppliers
More Malicious OpenClaw Skills Threaten AI Supply Chain
TanStack npm compromise: 42 packages published with valid SLSA provenance via OIDC token theft from runner memory
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
Github got Hacked by CATS
Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking
LastPass customer data exposed through Klue supply chain attack
Lookalike npm Package Hides a Multi-Stage Windows RAT
What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials