supply-chain
638 articles with this tag
HIGH
HIGH
INFO
HIGH
MEDIUM
HIGH
MEDIUM
CRITICAL
CRITICAL
CRITICAL
CRITICAL
INFO
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
INFO
INFO
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
INFO
INFO
HIGH
HIGH
INFO
HIGH
INFO
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
INFO
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
LOW
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
CRITICAL
MEDIUM
LOW
MEDIUM
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
INFO
CRITICAL
MEDIUM
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
INFO
CRITICAL
CRITICAL
HIGH
INFO
MEDIUM
MEDIUM
INFO
INFO
INFO
INFO
CRITICAL
HIGH
MEDIUM
CRITICAL
MEDIUM
INFO
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
INFO
HIGH
Crypto customers targeted by scammers after email marketing provider breach
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Secure by default is your only way forward
CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
Shai-Hulud npm worm resurfaces, bypassing security scans
Trezor Supply Chain Breach Now Impacts 81,000 Customers
UK food supply chain at risk from hostile attacks
Self-hosted Coder: check whether you pulled a registry module on Aug 31. no CVE, so nothing will flag it for you
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant
Secure by default is your only way forward
Trusted Chrome, Edge extensions weaponized in supply chain campaign
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Authorities arrest 2 alleged members of prolific hacking group TeamPCP
Australian cops cuff alleged TeamPCP masterminds
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
Australia Arrests 2 Alleged TeamPCP Hackers
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
ICYMI: July 2026 @AWS Security
The cybercrime supply chain has five stages, each with a price
Code Execution via Text Template Files | Playbook & Detection
Hackers poison popular Rust crates to steal developers' credentials
Rust Supply Chain Attack Linked to North Korean Hackers
Backdoored Rust packages hit crates.io, exposing developers to malware at build time
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
Inside the fourth wave of the Shai-Hulud npm worm
[NEU] [hoch] Oracle Supply Chain: Mehrere Schwachstellen
Security Hub Extended adds Supply Chain Security as its tenth category
Make zero CVEs your new default
ChainDrop worm crawls into npm supply chain, evades standard defenses
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Packer v1.16.0 brings verifiable provenance to machine images
153GB of stolen credentials surface after LiteLLM supply chain attack
Inc: The U.S. Just Banned Foreign-Made Robots Over Security Fears. 1 Expert Says the Real Risk Runs Much Deeper
LiteLLM supply chain attack impacted over 2,500 organizations
Terabytes of credentials leaked in massive supply-chain attack
Ceva Logistics Operations Disrupted by Cyberattack
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Six npm Packages Read C2 Addresses From Ethereum Wallet
GitHub already has an EDR. You just have to listen to it
Logistics Giant Ceva Suffers Data Breach Impacting European Clients
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
LexisNexis services offline due to unusual activity on third-party vendor servers
Attackers exploit AI skills registry for credential theft
WordPress Plugins Compromised Without a Single File Change
Chainloop: Open-source evidence store and policy engine for the software supply chain
PSA: Supply Chain Compromise in BdThemes Ecosystem via Poisoned API Response
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Trojanized AI skills gain 1.7M installs in agent-targeted attack
In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
Python package security in 2026: How supply chain attacks are targeting your AI development environment
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
US reportedly drafting ban on Chinese optical transceivers
Nautgripastofn Bandaríkjanna sá minnsti í 75 ár
Suppliers, logins, and AI tools are all becoming attack paths
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
QuickFox VPN targeted in long-standing supply chain attack delivering FDMTP backdoor
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
New npm packages deliver remote access trojan targeting Alibaba developers
Keyv, cacheable npm supply chain attack hits 400-plus packages
The Software Supply Chain Is Under Siege. Devs Are Still the First Line of Defense
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
Google dev kit spurs first-ever agent-on-agent violence
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Adform supply-chain attack replaced crypto wallet addresses
Arch Linux temporarily disables AUR package adoption amid malicious takeover surge
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Amazon attributes axios, debug, chalk NPM attacks to DPRK’s Sapphire Sleet
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
A little-known npm package was North Korea’s warm-up act for the axios hack
Supply chain challenges loom large in quantum race, White House official says
When AppSec Scanners Become a Supply Chain Attack Vector
Secure your npm and pip package updates in Amazon Linux
2026 Minimum Elements for a Software Bill of Materials (SBOM)
Accuris uses AI to improve BOM decisions and supply chain resilience
Infoblox enters EASM market with attack surface and supply chain risk tools
America bans imported robots due to supply chain and security risks
Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
GitHub and PyPI implement new security measures against supply-chain attacks
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk
GitHub, PyPI add time-absed defenses against supply chain attacks
Ransomware gangs go after EMEA healthcare’s supply chain
NuGet typosquat targets Digitain game results
Malware is targeting AI tools in software development environments
[NEU] [hoch] Oracle Supply Chain: Mehrere Schwachstellen
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Ask Gemini for a "Walmart MCP" and the first result is malware. try it.
Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
20th July – Threat Intelligence Report
Sequel to ChainVeil npm Malware Targets Vite Ecosystem
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
BTS #78 - Patching: The Race Against Time
Suno AI music generator reportedly hacked, source code allegedly reveals data scraping