supplychain
33 articles with this tag
HIGH
HIGH
MEDIUM
INFO
MEDIUM
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
HIGH
MEDIUM
HIGH
MEDIUM
CRITICAL
HIGH
CRITICAL
MEDIUM
INFO
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
LOW
INFO
INFO
MEDIUM
HIGH
INFO
INFO
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks
Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
Trust No Skill: Integrity Verification for AI Agent Supply Chains
NPM v12 to block supply-chain attacks with new security measures
The ‘Miasma’ worm source code briefly leaked on GitHub
GitHub announces npm security changes to tackle supply-chain attacks
GitHub disables Microsoft repos pushing password-stealing malware
VS Code adds 2-hour delay for extension updates to combat supply chain threats
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
New IronWorm malware hits 36 packages in npm supply-chain attack
Dozens of Red Hat packages backdoored through its offical NPM channel
In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks
Socket raises $60 million for its open-source security platform
Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem
TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension
GitHub Confirms Breach of Internal Repositories Via Malicious VS Code Extension
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
OpenAI Hit by TanStack Supply Chain Attack
Axios breach shows why software supply chains need zero trust
New Quasar Linux implant targets developers with rootkit and backdoor capabilities
Set up automated dependency scanning after the recent npm/PyPI supply chain attacks
Rethinking Security from the OS Up in the Age of AI and more RSAC 2026 Interviews - Craig Sanderson, Sachin Jade, Travis Wong, Phil Calvin, Karen Heart - ESW #456
SBOM erklärt: Was ist eine Software Bill of Materials?
STARDUST CHOLLIMA Likely Compromises Axios npm Package
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
Supply chain dependencies: Have you checked your blind spot?
Third-Party Risk Is an Intelligence Operation. It's Time We Treated It Like One.