supply-chain
578 articles with this tag
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
CRITICAL
MEDIUM
MEDIUM
INFO
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
MEDIUM
INFO
MEDIUM
HIGH
HIGH
INFO
INFO
INFO
CRITICAL
INFO
INFO
HIGH
HIGH
INFO
HIGH
CRITICAL
MEDIUM
HIGH
INFO
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
CRITICAL
CRITICAL
INFO
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
INFO
MEDIUM
CRITICAL
INFO
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
INFO
CRITICAL
MEDIUM
HIGH
HIGH
MEDIUM
MEDIUM
INFO
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
LOW
HIGH
HIGH
HIGH
INFO
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
GitHub and PyPI implement new security measures against supply-chain attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
GitHub, PyPI add time-absed defenses against supply chain attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Ransomware gangs go after EMEA healthcare’s supply chain
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
NuGet typosquat targets Digitain game results
Malware is targeting AI tools in software development environments
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
[NEU] [hoch] Oracle Supply Chain: Mehrere Schwachstellen
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Ask Gemini for a "Walmart MCP" and the first result is malware. try it.
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
20th July – Threat Intelligence Report
Sequel to ChainVeil npm Malware Targets Vite Ecosystem
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
BTS #78 - Patching: The Race Against Time
Suno AI music generator reportedly hacked, source code allegedly reveals data scraping
NPM ecosystem hit with two new supply chain compromises
The serpent’s tongue: Luring the Python out of its den
Multiple Jscrambler Packages Impacted by Supply Chain Attack
Your vendor’s vendor might be the real breach risk
Jscrambler npm package version 8.14.0 contained a malicious infostealer
13th July – Threat Intelligence Report
Why SBOMs, signing, and provenance still don’t tell you if software is safe
OpenMandriva Linux project reportedly targeted in attempted sabotage after contributor dispute
Injective Labs SDK npm package compromised to steal cryptocurrency keys
Network of 200 GitHub Repositories Used for Malware Infection
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Warning Over “Industrialized” Cyber-Attacks After Ransomware Gang Partners With TeamPCP
Technical Blueprint: Hardware Security for AI Infrastructure
Vect and TeamPCP partner for ransomware campaigns
PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems
'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat
Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
Aikido Security acquires Root to expand backported fixes for open source vulnerabilities
29th June – Threat Intelligence Report
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
Supply chain analysis: Kickbacks.ai VS Code extension. Empty pubkey, CSP relaxation, 90-second unsigned self-update, 60-second reassertion loop
Polymarket customers lose $3 million in supply-chain attack
More Klue Breach Victims Identified as Hackers Get Hacked
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
EdTech Attackers Shift From Schools to Their Software Suppliers
TanStack npm compromise: 42 packages published with valid SLSA provenance via OIDC token theft from runner memory
Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
Github got Hacked by CATS
Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking
LastPass customer data exposed through Klue supply chain attack
Open-source security is posing challenges governments can’t easily solve
Healthcare leaders face cybersecurity blind spots despite vendor confidence
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat
Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
LastPass confirms data breach in Klue supply chain attack
What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
When a vendor's breach becomes yours: lessons from the Klue incident
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
22nd June – Threat Intelligence Report
Kína þrengir að lykilverkefni Bandaríkjanna í jarðmálmum
Microsoft Attributes Mastra AI Supply Chain Attack to North Korea
North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
More Cybersecurity Firms Disclose Impact From Klue Hack
Why Southeast Asia CISOs Need Zero Trust as Their AI Control Plane – AI Agents, Data Borders and Supply Chains
Microsoft links Mastra AI supply chain attack to North Korean hackers
Cybersecurity Firms Impacted by Klue Supply Chain Attack
How software development’s speed obsession enabled TeamPCP’s chaos crusade
ShapedPlugin update flow hacked to infect WordPress sites
astro.config.mjs Supply Chain Attack via Blockchain C2
How security teams are getting credential visibility into developer endpoints
From package to postinstall payload: Inside the Mastra npm supply chain compromise
Mastra npm packages compromised in 'easy-day-js' supply chain attack
A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope
Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
144 Mastra npm Packages Compromised via Hijacked Contributor Account
PSA: Supply Chain Compromise Targets ShapedPlugin, Backdoored Pro Plugins Distributed via Official Channels
Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
OptinMonster WordPress plugin hacked in CDN supply-chain attack
Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites