Skip to main content

Tag: supply chain

1280 articles

Network operations center with servers and equipment, focusing on a router on a rack.

BGP Hijack Targets Virtualizor Users with Persistent Root Access Malware

A recent BGP hijack attack targeted users of Virtualizor with malware that granted persistent root access, affecting a limited number of servers that received rerouted Softaculous update traffic during a 33-hour window. The attackers cleverly obtained a valid Let's Encrypt certificate, making the malicious server appear trustworthy to clients.

Analyst 207
Brazilian government building with people walking by, subtle server room in background.

Malicious Apache Modules Redirect Brazilian Government Traffic to Betting Sites

Brazilian government websites have been hijacked by malicious actors, redirecting traffic to betting sites in a sneaky campaign attributed to a Chinese-speaking cluster known as Gambling Goblin or Earth Berberoka. This multilingual scheme has been cleverly manipulating search engines and government systems since mid-2025.

Analyst 207
Developer workstation with laptop, terminal, and papers, showing a Git config file on screen in a bright office setting.

AI Coding Agents Exposed to Code Execution via Malicious Git Configs

Researchers have uncovered a shocking vulnerability in seven AI coding agents, where malicious Git configurations can trick the tools into running attacker-supplied code on a developer's machine. This flaw, linked to Git's core.fsmonitor setting, has already led to eight security flaws, with four still unpatched.

Analyst 207
Server room with rows of computer servers and networking equipment, featuring a single Apache web server in the foreground.

Malicious Apache Modules Empower Gambling Goblin's SEO Fraud Campaign

Meet Gambling Goblin, a Chinese-speaking cybercrime cluster that's been secretly hijacking Brazilian government and education websites to fuel a massive SEO fraud campaign since mid-2025. They're using sneaky Apache modules to disguise their malicious activity and stay under the radar.

Analyst 207
Laptop on a desk with cloud storage interface and nearby mobile device.

Dropbox Breach Exposes 5,000 Accounts via Lenovo Login Flaw

A security lapse in a legacy Lenovo login integration left around 5,000 Dropbox accounts vulnerable to hackers, who exploited an email verification flaw to gain unauthorized access. Dropbox has since notified affected users and confirmed the breach to reporters.

Analyst 207
Laptop and smartphone sit on a clean, neutral surface in soft daylight.

Dropbox Breach Exposes Lenovo Email Verification Flaw

Beware: a sneaky flaw in Lenovo's email verification process was exploited by hackers to hijack Dropbox accounts - no password required! Dropbox has warned users that an attacker used a legacy link between Lenovo ID and Dropbox to register fake IDs and gain unauthorized access.

Analyst 207
Workers stand near a crate of shrimp at a Honduran port, looking concerned under a daytime sky.

Latin America Rebalances China Ties

Honduras's diplomatic shift towards China in 2023 came with a hefty price tag: its shrimp exporters lost access to Taiwan, resulting in plummeting sales, shuttered businesses, and thousands of job losses. The economic fallout has sparked domestic backlash, with the Honduran congress launching probes into Chinese business activities.

Analyst 207
Rows of network equipment and security appliances in a brightly-lit IT closet, with a generic SMA appliance centered.

SonicWall Zero-Days Exploited in Chained Attacks

SonicWall has confirmed that two newly discovered zero-day flaws in its Secure Mobile Access (SMA) 1000 appliances are being actively exploited in chained attacks, posing significant security risks. The vendor has swiftly released fixes for the vulnerabilities, which were identified internally by its researchers.

Analyst 207
Hospital corridor with papers scattered, laptop and office supplies nearby, hinting at a breach.

Nutex Health Breach Exposes Patient Data to Ransomware Gang

Nutex Health revealed a devastating data breach on August 31, confirming that a ransomware gang had infiltrated its servers, compromising sensitive patient, employee, and business information. The attackers have even threatened to publicly expose the stolen data.

Analyst 207
British government minister addresses meeting on cybersecurity regulations at podium.

UK Tightens Cyber Bill Focus on Users, Not AI Vendors

The UK's Cyber Security Bill is shifting its focus towards users and operational controls, rather than targeting AI vendors, to effectively tackle potential harms and misuse by hostile actors. By doing so, the government aims to take firm action through other channels, such as supporting the AI Security Institute.

Analyst 207
A cluttered freelance workspace with a laptop and crumpled paper on a desk.

US Indicts Russian for Infecting 80,000 Freelancers with Malware

A massive phishing campaign infected 80,000 freelancers with malware, using 255 fake accounts to spread malicious Excel attachments with hidden macros that downloaded additional software onto victims' systems. The cleverly designed scam exploited a popular freelance employment platform's online messaging feature to spread its digital damage.

Analyst 207
Industrial network device on a workbench surrounded by tools.

SonicWall Zero-Days Exploited in Wild, Firm Urges Immediate Patching

SonicWall is urging immediate patching for two zero-day vulnerabilities in its SMA1000 appliances, which are being actively exploited in the wild by hackers. The more critical flaw, CVE-2026-83548, has a severity rating of 10.0 and can be triggered without authentication, putting sensitive data at risk.

Analyst 207
Small business office with VoIP phone and computers, server room door slightly ajar.

Attackers Exploit Switchvox Flaw to Deploy Reverse Shells

A critical flaw in Sangoma Switchvox SMB Edition 8.3 can let attackers execute malicious code without credentials, giving them alarming control over your system. This unauthenticated SQL injection vulnerability, tracked as CVE-2026-9586, is a serious threat that demands immediate attention.

Analyst 207
Industrial control system equipment, including a control panel and wiring cabinet, in a neutral indoor setting.

AI-Powered Exploit Porting Threatens Industrial Control Systems

A recent exploit development stage for targeting Industrial Control Systems racked up a hefty $535.74 API usage bill over just 8 hours and 32 minutes, highlighting the costly and disturbing potential of AI-powered threat tactics. This unsettling advancement centers around CVE-2021-31886, a severe vulnerability in Nucleus FTP servers.

Analyst 207
Secure airport area at night with cargo aircraft and perimeter fence in view.

Germany Blames Russia for Attempted Drone Strike on Ukrainian Cargo Jet

Germany is pointing fingers at Russia for a brazen attempted drone strike on a Ukrainian cargo jet at Leipzig/Halle Airport, where a drone loaded with 1.3 pounds of military-grade explosives was mysteriously found near the aircraft. The plot was foiled when the detonator failed, but authorities warn it could have been a catastrophe.

Analyst 207
US Navy submarine in dry dock with open hatch and exposed systems.

Navy Submarine Maintenance Backlog Inflates Costs

The Navy's submarine maintenance backlog is spiraling out of control, with a staggering 41 ship-years of idle time accumulated over the past decade and a projected $3.1 billion in unnecessary operating costs on the horizon. This costly delay is set to worsen, with 15 attack submarines expected to spend over 14,000 days in inactive idle status between 2026 and 2030.

Analyst 207
Cluttered office cubicle with desktop computer and suspicious email nearby.

Hackers Exploit Faronics Tool to Install ScreenConnect on Compromised Endpoints

Hackers are using clever phishing lures disguised as invoices and business files to trick victims into installing malicious software, with over 457 endpoints compromised in just a month. They exploited a legitimate endpoint-management tool to gain remote control and install additional remote-access software.

Analyst 207
JFrog Artifactory server setup with laptop in a bright, daylight-filled room.

Attackers Exploit JFrog Artifactory Flaw to Mint Admin Tokens

A critical flaw in JFrog Artifactory, known as CVE-2026-82329, allows attackers to easily gain admin access without needing authentication or user interaction, posing a huge risk to affected instances. This near-maximum-score vulnerability has already been patched in Artifactory version 7.161.20.

Analyst 207
Server room with rows of equipment and one terminal with a blank screen, suggesting a breach.

Langflow vulnerability exploited to harvest OpenAI, AWS keys

Attackers are actively exploiting a critical vulnerability in Langflow to harvest sensitive keys, including OpenAI and AWS credentials, by querying environment variables and reading secret files. This severe flaw, known as CVE-2026-0768, allows hackers to execute arbitrary Python code with root privileges, putting systems at risk.

Analyst 207
Hospital supply chain management office with scattered papers and blurred computer screen.

McKesson Breach Exposes Third-Party Risks in Healthcare

A single vulnerable third-party application can spark a national patient data crisis, as seen in the recent McKesson breach, where a third-party integration led to a massive data exfiltration claim of 284 million records.

Analyst 207
Smartphone on cluttered desk in cafe with blurred webpage on screen.

Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Seeds

Researchers uncovered 13 malicious packages on Packagist that inject JavaScript into popular Vietnamese streaming sites, unleashing a two-pronged attack that includes mobile ad-fraud and spyware installation on unpatched iPhones. This sneaky malware can steal crypto seeds and wreak havoc on unsuspecting users.

Analyst 207
Network operations room with rows of routers, technicians, and a large screen displaying internet infrastructure diagram.

Hackers exploit BGP hijacking to deliver malicious Virtualizor updates

Malicious actors hijacked internet traffic to deliver fake Virtualizor updates to a small number of users, exploiting a vulnerability in the Border Gateway Protocol (BGP) to divert update requests to their own servers. This sneaky move allowed them to push malicious updates to unsuspecting users.

Analyst 207
People in business attire and utility workers stand in front of a small water treatment plant with industrial equipment.

US Bolsters Water Infrastructure with Cybersecurity Pilot

The alarming number of cyber incident reports from water providers - 27 in just seven states - has prompted a swift response from the White House and Texas officials with the launch of Project Watershed 250, a six-month pilot aimed at bolstering water infrastructure cybersecurity. This innovative program will deploy top-notch cyber-defense resources to water and wastewater utilities at no cost, starting with a test run in Texas.

Analyst 207
Network equipment rack with cables and patch cords in a data center interior.

BGP Hijack Targets Softaculous Traffic, Delivers Malware

In a shocking 33-hour heist, a BGP hijack diverted traffic meant for Softaculous, delivering malware to unsuspecting users via a valid TLS certificate issued to the attacker. The clever hack exploited a weakness in internet routing, allowing the attacker to intercept and compromise Virtualizor installations.

Analyst 207