mitre-ta0043
89 articles with this tag
CRITICAL
HIGH
CRITICAL
MEDIUM
HIGH
LOW
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
MEDIUM
MEDIUM
HIGH
CRITICAL
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
MEDIUM
CRITICAL
HIGH
MEDIUM
HIGH
MEDIUM
HIGH
LOW
MEDIUM
Why supply chain attacks work and what detection can actually do about it
Red Hat npm packages compromised to steal developer credentials
Dozens of Red Hat packages backdoored through its offical NPM channel
A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.)
Russia-linked threat group put ChatGPT to work from lure to payload
What scanners are actually trying against AI infrastructure
CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain
Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign
Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested
GitHub internal repositories breached
GitHub links repo breach to TanStack npm supply-chain attack
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
The IBM X-Force Index 2026 explains all three in one finding.
GitHub Confirms Hack Impacting 3,800 Internal Repositories
AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks
Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool
FIFA World Cup scams target fans and businesses
201 arrested in INTERPOL disruption of phishing and fraud networks
TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code
Hunting the Behavior Behind npm Supply Chain Attacks
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack
RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
Small Defense Firms Lack Network Data to Stop Nation-State Hackers, Analyst Says
Social Engineering Leveled Up. Has Your Security Program?
Ubuntu infrastructure has been down for more than a day
PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials
'Mini Shai-Hulud' supply chain attack targets SAP npm packages
Kuse Web App Abused to Host Phishing Document
More fake extensions linked to GlassWorm found in Open VSX code marketplace
Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers
Tradecraft Tuesday Recap: axios npm Supply Chain Compromise
Supply chain attacks hit Checkmarx and Bitwarden developer tools
Anthropic probes alleged third-party breach of Claude Mythos
A dozen allied agencies say China is building covert hacker networks out of everyday routers
Malicious pgserve, automagik developer tools found in npm registry
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
The LiteLLM attack was a warning shot for Agentic AI supply chains
After Bluesky, Mastodon Targeted in DDoS Attack
Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
Why the Axios attack proves AI is mandatory for supply chain security
How attackers automate social media reconnaissance to craft personalized phishing emails in 2026
Python Supply-Chain Compromise
Supply Chain Compromise of axios npm Package
Software supply chain hacks trigger wave of intrusions, data theft
Mercor Hit by LiteLLM Supply Chain Attack
AI recruiting biz Mercor says it was 'one of thousands' hit in LiteLLM supply-chain attack
How we caught the Axios supply chain attack
Mitigating the Axios npm supply chain compromise
Axios npm Supply Chain Compromise
Supply chain attack on Axios npm package: Scope, impact, and remediations
Emergency Webcast Briefing: Axios NPM Supply Chain Compromise
Supply chain blast: Top npm package backdoored to drop dirty RAT on dev machines
Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT
Axios npm package compromised in supply chain attack. Downloads malware dropper package
Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug
Risky Business #830 -- LiteLLM and security scanner supply chains compromised
1K+ cloud environments infected following Trivy supply chain attack
Trivy supply-chain attack spreads to Docker, GitHub repos
Trivy Supply Chain Attack Expands With New Compromised Docker Images
Trivy Supply Chain Attack: What Happened and What You Need to Know
FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks
Trivy vulnerability scanner backdoored with credential stealer in supply chain attack
The espionage reality: Your infrastructure is already in the collection path
Cybercrime has skyrocketed 245% since the start of the Iran war
FBI Calls for Help to Track Steam Malware Campaign
Supply-chain attack using invisible code hits GitHub and other repositories
The Future of Supply Chain Backdoor Detections
Hackers may have breached FBI wiretap network via supply chain
Internet Infrastructure TLD .arpa Abused in Phishing Attacks
From Ukraine to Iran, Hacking Security Cameras Is Now Part of War’s ‘Playbook’
[NEU] [mittel] cPanel/WHM: Schwachstelle ermöglicht Offenlegung von Informationen
Hacker knackt 600 Firewalls in einem Monat – mit KI
Know the red flags: Business email compromise signs to look out for
How to prevent business email compromise
The Art of Deception: How Threat Actors Master Typosquatting Campaigns to Bypass Detection
Attackers Use New Tool to Scan for React2Shell Exposure
Google: state-backed hackers exploit Gemini AI for cyber recon and attacks
Google: State-backed hackers using Gemini AI at every stage of attacks
Reconnaissance Has Begun for the New BeyondTrust RCE (CVE-2026-1731): Here's What We See So Far
Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support
Google: China's APT31 used Gemini to plan cyberattacks against US orgs
State actor targets 155 countries in 'Shadow Campaigns' espionage op
The Shadow Campaigns: Uncovering Global Espionage
Wave of Citrix NetScaler scans use thousands of residential proxies
Scanning for exposed Anthropic Models, (Mon, Feb 2nd)
Scanning Webserver with /$(pwd)/ as a Starting Path, (Sun, Jan 25th)