Skip to main content

Supply Chain Attacks

MOVEit Transfer Stunning $8.5M Risky Settlement

MOVEit Transfer Stunning $8.5M Risky Settlement

Nuance agreed to pay $8.5 million to settle a class-action tied to the massive MOVEit supply‑chain breach — even while not admitting fault — a stark reminder that one vendor’s vulnerability can saddle many downstream companies with legal and financial fallout. Think of it as a wake-up call: tighten third‑party security, patch fast, and treat vendor risk as a boardroom priority before a breach becomes someone else’s bill.

Analyst 207
supply chain attacks: Risky npm compromise – Must-Have alert

supply chain attacks: Risky npm compromise – Must-Have alert

When a trusted npm package—eslint-config-prettier—was hijacked to deliver the Scavenger RAT, it turned the open-source supply chain into an attack highway. Developers and teams must treat dependencies as potential threats: pin versions, enable 2FA, rotate secrets, and hunt for compromises before convenience becomes a vulnerability.

Analyst 207
Taiwanese web hosting Exclusive: Critical Espionage Risk

Taiwanese web hosting Exclusive: Critical Espionage Risk

Imagine an invisible enemy living inside the servers that power your websites and email — Cisco Talos found a Chinese‑linked APT using a Taiwanese web host to intercept traffic, harvest credentials and stage persistent espionage. This supply‑chain breach is a wake‑up call: treat hosts as critical infrastructure and demand stronger controls, logging and incident guarantees now.

Analyst 207
Taiwanese web host Critical: Exclusive Must-Have Fixes

Taiwanese web host Critical: Exclusive Must-Have Fixes

A suspected Chinese state-backed crew quietly breached a Taiwanese web host, stealing credentials and planting backdoors to maintain months-long access — a stark reminder that compromising one trusted provider can expose dozens of downstream victims. Strengthening access controls, adopting zero-trust segmentation, and rotating credentials aren’t optional — they’re the best way to stop a single breach from becoming a widespread supply-chain disaster.

Analyst 207
New Supply Chain Vulnerability: Unpacking the Risks Ahead

New Supply Chain Vulnerability: Unpacking the Risks Ahead

As data becomes the new gold, a startling revelation unfolds: Microsoft’s collaboration with Chinese engineers to manage the Defense Department’s computer systems raises urgent questions about our national security. Dive into the risks that could leave our most sensitive information vulnerable to espionage!

Analyst 207
supply chain vulnerability: Harrowing Risky Threat

supply chain vulnerability: Harrowing Risky Threat

ProPublica’s reporting reveals a startling weak link: engineers in China maintaining U.S. Defense Department systems create a human-powered supply chain vulnerability that could be exploited by adversaries. It’s time for stricter oversight, transparency, and technical safeguards so efficiency doesn’t come at the cost of national security.

Analyst 207
npm package security: Must-Have Guide to Risky Breaches

npm package security: Must-Have Guide to Risky Breaches

A targeted phishing attack that slipped malicious code into five npm packages shows how easily supply chains can be weaponized. Treat publish tokens like private keys—enable 2FA, rotate credentials, and demand package signing and provenance to stop the next breach.

Analyst 207
Malicious Pull Request Hits 6,000 Developers Through Ethcode Extension

Malicious Pull Request Hits 6,000 Developers Through Ethcode Extension

A sophisticated supply chain attack compromised the Ethcode extension for VS Code, silently infecting over 6,000 developers with malicious code and exposing critical blockchain projects to severe security risks. This breach highlights the urgent need for vigilant verification in software supply chains, where trust can be weaponized to devastating effect.

Analyst 207
Unveiling Russian Aviation Supply Chains: Moscow, a Real Estate Agent, and Alain Delon’s Ex-Pilot in Thailand

Unveiling Russian Aviation Supply Chains: Moscow, a Real Estate Agent, and Alain Delon’s Ex-Pilot in Thailand

Explore the intricate web of Russian aviation supply chains involving Moscow, a real estate agent, and Alain Delon’s former pilot in Thailand.

Analyst 207
UNFI Recovers Core Systems Following Cyberattack on Whole Foods Supplier

UNFI Recovers Core Systems Following Cyberattack on Whole Foods Supplier

UNFI restores core systems after a cyberattack impacting Whole Foods supply chain, ensuring operational stability and data security for customers.

Analyst 207
Major Vulnerability in Open VSX Registry Puts Millions of Developers at Risk of Supply Chain Attacks

Major Vulnerability in Open VSX Registry Puts Millions of Developers at Risk of Supply Chain Attacks

A major vulnerability in the Open VSX Registry threatens millions of developers, exposing them to potential supply chain attacks and security risks.

Analyst 207
Glasgow Council Services and Data Threatened by Supply Chain Incident

Glasgow Council Services and Data Threatened by Supply Chain Incident

Glasgow Council faces potential data threats following a supply chain incident, impacting essential services and data security measures.

Analyst 207
Surge in Supply Chain Attacks Leaves Organizations Unaware of Dependencies

Surge in Supply Chain Attacks Leaves Organizations Unaware of Dependencies

“Explore the rising threat of supply chain attacks and how organizations remain oblivious to their critical dependencies and vulnerabilities.”

Analyst 207
Kazakh Titanium Lawsuit Poses Risk to Western Supply Chains in France and Kazakhstan

Kazakh Titanium Lawsuit Poses Risk to Western Supply Chains in France and Kazakhstan

Kazakh Titanium lawsuit threatens Western supply chains, impacting operations in France and Kazakhstan amid rising legal and trade uncertainties.

Analyst 207
ISMG Editors: Supply Chain Attacks Are Spiking – Here’s Why

ISMG Editors: Supply Chain Attacks Are Spiking – Here’s Why

ISMG Editors report a surge in supply chain attacks—exploring the causes and cybersecurity implications driving this alarming trend.

Analyst 207
NCCoE Unveils New Tech Partners for Software Supply Chain and DevOps Security Initiative

NCCoE Unveils New Tech Partners for Software Supply Chain and DevOps Security Initiative

NCCoE reveals new tech partners to boost software supply chain security and enhance DevOps defenses, driving industry innovation.

Analyst 207
Supply Chain Attacks Really Are Surging

Supply Chain Attacks Really Are Surging

Supply Chain Attacks are surging. Discover emerging tactics, evolving threats, and strategies to effectively safeguard your organization.

Analyst 207
Cyberattack Disrupts Operations at Major Whole Foods Supplier

Cyberattack Disrupts Operations at Major Whole Foods Supplier

Cyberattack upends operations at a major Whole Foods supplier, causing supply chain disruptions and prompting security investigations.

Analyst 207
SentinelOne Confirms No Breach Despite Hardware Supplier Cyberattack

SentinelOne Confirms No Breach Despite Hardware Supplier Cyberattack

SentinelOne confirms no breach amid a hardware supplier cyberattack, emphasizing strong security measures and uninterrupted protection.

Analyst 207
Grocery wholesale giant United Natural Foods hit by cyberattack

Grocery wholesale giant United Natural Foods hit by cyberattack

Grocery wholesale giant United Natural Foods hit by a disruptive cyberattack, sparking alarms over operations and supply chain security.

Analyst 207
Malicious Code Discovered in Popular NPM Packages with 1 Million Weekly Downloads

Malicious Code Discovered in Popular NPM Packages with 1 Million Weekly Downloads

Malicious code found in popular NPM packages (1M+ weekly downloads). Secure your dependencies now to prevent potential security risks.

Analyst 207
Global Supply Chain Cyberattack Targets npm and PyPI, Impacting Millions Worldwide

Global Supply Chain Cyberattack Targets npm and PyPI, Impacting Millions Worldwide

Global cyberattack on npm & PyPI disrupts supply chains, impacting millions worldwide. Uncover breach details now.

Analyst 207
Supply chain attack hits Gluestack NPM packages with 960K weekly downloads

Supply chain attack hits Gluestack NPM packages with 960K weekly downloads

Supply chain attack strikes Gluestack’s NPM packages with 960K weekly downloads, exposing vulnerabilities that threaten project security and developer trust.

Analyst 207
Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks

Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks

Malicious PyPI, npm, and Ruby packages jeopardize open-source supply chains. Secure your projects by updating dependencies and managing risks.

Analyst 207