supply-chain
606 articles with this tag
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
MEDIUM
INFO
MEDIUM
MEDIUM
HIGH
MEDIUM
CRITICAL
CRITICAL
HIGH
HIGH
INFO
MEDIUM
MEDIUM
INFO
MEDIUM
INFO
INFO
INFO
MEDIUM
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
CRITICAL
MEDIUM
MEDIUM
INFO
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
MEDIUM
INFO
MEDIUM
HIGH
HIGH
INFO
INFO
INFO
CRITICAL
INFO
INFO
HIGH
HIGH
INFO
HIGH
CRITICAL
MEDIUM
HIGH
INFO
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
CRITICAL
CRITICAL
INFO
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
INFO
MEDIUM
CRITICAL
INFO
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
INFO
CRITICAL
MEDIUM
HIGH
HIGH
MEDIUM
MEDIUM
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Amazon attributes axios, debug, chalk NPM attacks to DPRK’s Sapphire Sleet
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
A little-known npm package was North Korea’s warm-up act for the axios hack
Supply chain challenges loom large in quantum race, White House official says
When AppSec Scanners Become a Supply Chain Attack Vector
Secure your npm and pip package updates in Amazon Linux
2026 Minimum Elements for a Software Bill of Materials (SBOM)
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Accuris uses AI to improve BOM decisions and supply chain resilience
Infoblox enters EASM market with attack surface and supply chain risk tools
America bans imported robots due to supply chain and security risks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
GitHub and PyPI implement new security measures against supply-chain attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
GitHub, PyPI add time-absed defenses against supply chain attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Ransomware gangs go after EMEA healthcare’s supply chain
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
NuGet typosquat targets Digitain game results
Malware is targeting AI tools in software development environments
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
[NEU] [hoch] Oracle Supply Chain: Mehrere Schwachstellen
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Ask Gemini for a "Walmart MCP" and the first result is malware. try it.
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
20th July – Threat Intelligence Report
Sequel to ChainVeil npm Malware Targets Vite Ecosystem
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
BTS #78 - Patching: The Race Against Time
Suno AI music generator reportedly hacked, source code allegedly reveals data scraping
NPM ecosystem hit with two new supply chain compromises
The serpent’s tongue: Luring the Python out of its den
Multiple Jscrambler Packages Impacted by Supply Chain Attack
Your vendor’s vendor might be the real breach risk
Jscrambler npm package version 8.14.0 contained a malicious infostealer
13th July – Threat Intelligence Report
Why SBOMs, signing, and provenance still don’t tell you if software is safe
OpenMandriva Linux project reportedly targeted in attempted sabotage after contributor dispute
Injective Labs SDK npm package compromised to steal cryptocurrency keys
Network of 200 GitHub Repositories Used for Malware Infection
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Warning Over “Industrialized” Cyber-Attacks After Ransomware Gang Partners With TeamPCP
Technical Blueprint: Hardware Security for AI Infrastructure
Vect and TeamPCP partner for ransomware campaigns
PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems
'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat
Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
Aikido Security acquires Root to expand backported fixes for open source vulnerabilities
29th June – Threat Intelligence Report
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
Supply chain analysis: Kickbacks.ai VS Code extension. Empty pubkey, CSP relaxation, 90-second unsigned self-update, 60-second reassertion loop
Polymarket customers lose $3 million in supply-chain attack
More Klue Breach Victims Identified as Hackers Get Hacked
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
EdTech Attackers Shift From Schools to Their Software Suppliers
TanStack npm compromise: 42 packages published with valid SLSA provenance via OIDC token theft from runner memory
Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
Github got Hacked by CATS
Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking
LastPass customer data exposed through Klue supply chain attack
Open-source security is posing challenges governments can’t easily solve
Healthcare leaders face cybersecurity blind spots despite vendor confidence