Skip to main content

Tag: docker hub

3 articles

Software development workstation with laptop, monitor, and notes in a modern office setting.

Threat Actors Target AI Coding Tools in Software Supply Chain Compromises

Threat actors are increasingly targeting AI coding tools to compromise software supply chains, with financially motivated groups like UNC6780 using malware like Dustmaker to gain initial access to AI environments. This growing trend highlights the need for heightened security measures in modern AI development pipelines.

Analyst 207
Empty developer workstation with laptop and peripherals on a neutral background.

Developer Workstations Expose Software Supply Chain to Credential Theft

In a shocking 48-hour span, three separate cyber attacks hit major platforms, targeting sensitive secrets like API keys and cloud credentials from developer workstations and CI/CD pipelines. This new wave of supply chain threats reveals a disturbing trend: attackers are now focusing on harvesting credentials to compromise your entire software development process.

Analyst 207
Server room with rows of computer equipment and a laptop displaying code in the foreground.

Malicious Docker Images Compromise Checkmarx Supply Chain

Malicious Docker images compromised the Checkmarx supply chain by embedding a tampered KICS binary that secretly collected and sent sensitive data to an external endpoint. This sneaky data-exfiltration risk put users at risk, thanks to an altered scan report generated by the poisoned image.

Analyst 207