Tag: supply chain
1280 articles

BGP Hijack Targets Virtualizor Users with Persistent Root Access Malware
A recent BGP hijack attack targeted users of Virtualizor with malware that granted persistent root access, affecting a limited number of servers that received rerouted Softaculous update traffic during a 33-hour window. The attackers cleverly obtained a valid Let's Encrypt certificate, making the malicious server appear trustworthy to clients.

Malicious Apache Modules Redirect Brazilian Government Traffic to Betting Sites
Brazilian government websites have been hijacked by malicious actors, redirecting traffic to betting sites in a sneaky campaign attributed to a Chinese-speaking cluster known as Gambling Goblin or Earth Berberoka. This multilingual scheme has been cleverly manipulating search engines and government systems since mid-2025.

AI Coding Agents Exposed to Code Execution via Malicious Git Configs
Researchers have uncovered a shocking vulnerability in seven AI coding agents, where malicious Git configurations can trick the tools into running attacker-supplied code on a developer's machine. This flaw, linked to Git's core.fsmonitor setting, has already led to eight security flaws, with four still unpatched.

Malicious Apache Modules Empower Gambling Goblin's SEO Fraud Campaign
Meet Gambling Goblin, a Chinese-speaking cybercrime cluster that's been secretly hijacking Brazilian government and education websites to fuel a massive SEO fraud campaign since mid-2025. They're using sneaky Apache modules to disguise their malicious activity and stay under the radar.

Dropbox Breach Exposes 5,000 Accounts via Lenovo Login Flaw
A security lapse in a legacy Lenovo login integration left around 5,000 Dropbox accounts vulnerable to hackers, who exploited an email verification flaw to gain unauthorized access. Dropbox has since notified affected users and confirmed the breach to reporters.

Dropbox Breach Exposes Lenovo Email Verification Flaw
Beware: a sneaky flaw in Lenovo's email verification process was exploited by hackers to hijack Dropbox accounts - no password required! Dropbox has warned users that an attacker used a legacy link between Lenovo ID and Dropbox to register fake IDs and gain unauthorized access.

Latin America Rebalances China Ties
Honduras's diplomatic shift towards China in 2023 came with a hefty price tag: its shrimp exporters lost access to Taiwan, resulting in plummeting sales, shuttered businesses, and thousands of job losses. The economic fallout has sparked domestic backlash, with the Honduran congress launching probes into Chinese business activities.

SonicWall Zero-Days Exploited in Chained Attacks
SonicWall has confirmed that two newly discovered zero-day flaws in its Secure Mobile Access (SMA) 1000 appliances are being actively exploited in chained attacks, posing significant security risks. The vendor has swiftly released fixes for the vulnerabilities, which were identified internally by its researchers.

Nutex Health Breach Exposes Patient Data to Ransomware Gang
Nutex Health revealed a devastating data breach on August 31, confirming that a ransomware gang had infiltrated its servers, compromising sensitive patient, employee, and business information. The attackers have even threatened to publicly expose the stolen data.

UK Tightens Cyber Bill Focus on Users, Not AI Vendors
The UK's Cyber Security Bill is shifting its focus towards users and operational controls, rather than targeting AI vendors, to effectively tackle potential harms and misuse by hostile actors. By doing so, the government aims to take firm action through other channels, such as supporting the AI Security Institute.

US Indicts Russian for Infecting 80,000 Freelancers with Malware
A massive phishing campaign infected 80,000 freelancers with malware, using 255 fake accounts to spread malicious Excel attachments with hidden macros that downloaded additional software onto victims' systems. The cleverly designed scam exploited a popular freelance employment platform's online messaging feature to spread its digital damage.

SonicWall Zero-Days Exploited in Wild, Firm Urges Immediate Patching
SonicWall is urging immediate patching for two zero-day vulnerabilities in its SMA1000 appliances, which are being actively exploited in the wild by hackers. The more critical flaw, CVE-2026-83548, has a severity rating of 10.0 and can be triggered without authentication, putting sensitive data at risk.

Attackers Exploit Switchvox Flaw to Deploy Reverse Shells
A critical flaw in Sangoma Switchvox SMB Edition 8.3 can let attackers execute malicious code without credentials, giving them alarming control over your system. This unauthenticated SQL injection vulnerability, tracked as CVE-2026-9586, is a serious threat that demands immediate attention.

AI-Powered Exploit Porting Threatens Industrial Control Systems
A recent exploit development stage for targeting Industrial Control Systems racked up a hefty $535.74 API usage bill over just 8 hours and 32 minutes, highlighting the costly and disturbing potential of AI-powered threat tactics. This unsettling advancement centers around CVE-2021-31886, a severe vulnerability in Nucleus FTP servers.

Germany Blames Russia for Attempted Drone Strike on Ukrainian Cargo Jet
Germany is pointing fingers at Russia for a brazen attempted drone strike on a Ukrainian cargo jet at Leipzig/Halle Airport, where a drone loaded with 1.3 pounds of military-grade explosives was mysteriously found near the aircraft. The plot was foiled when the detonator failed, but authorities warn it could have been a catastrophe.

Navy Submarine Maintenance Backlog Inflates Costs
The Navy's submarine maintenance backlog is spiraling out of control, with a staggering 41 ship-years of idle time accumulated over the past decade and a projected $3.1 billion in unnecessary operating costs on the horizon. This costly delay is set to worsen, with 15 attack submarines expected to spend over 14,000 days in inactive idle status between 2026 and 2030.

Hackers Exploit Faronics Tool to Install ScreenConnect on Compromised Endpoints
Hackers are using clever phishing lures disguised as invoices and business files to trick victims into installing malicious software, with over 457 endpoints compromised in just a month. They exploited a legitimate endpoint-management tool to gain remote control and install additional remote-access software.

Attackers Exploit JFrog Artifactory Flaw to Mint Admin Tokens
A critical flaw in JFrog Artifactory, known as CVE-2026-82329, allows attackers to easily gain admin access without needing authentication or user interaction, posing a huge risk to affected instances. This near-maximum-score vulnerability has already been patched in Artifactory version 7.161.20.

Langflow vulnerability exploited to harvest OpenAI, AWS keys
Attackers are actively exploiting a critical vulnerability in Langflow to harvest sensitive keys, including OpenAI and AWS credentials, by querying environment variables and reading secret files. This severe flaw, known as CVE-2026-0768, allows hackers to execute arbitrary Python code with root privileges, putting systems at risk.

McKesson Breach Exposes Third-Party Risks in Healthcare
A single vulnerable third-party application can spark a national patient data crisis, as seen in the recent McKesson breach, where a third-party integration led to a massive data exfiltration claim of 284 million records.

Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Seeds
Researchers uncovered 13 malicious packages on Packagist that inject JavaScript into popular Vietnamese streaming sites, unleashing a two-pronged attack that includes mobile ad-fraud and spyware installation on unpatched iPhones. This sneaky malware can steal crypto seeds and wreak havoc on unsuspecting users.

Hackers exploit BGP hijacking to deliver malicious Virtualizor updates
Malicious actors hijacked internet traffic to deliver fake Virtualizor updates to a small number of users, exploiting a vulnerability in the Border Gateway Protocol (BGP) to divert update requests to their own servers. This sneaky move allowed them to push malicious updates to unsuspecting users.

US Bolsters Water Infrastructure with Cybersecurity Pilot
The alarming number of cyber incident reports from water providers - 27 in just seven states - has prompted a swift response from the White House and Texas officials with the launch of Project Watershed 250, a six-month pilot aimed at bolstering water infrastructure cybersecurity. This innovative program will deploy top-notch cyber-defense resources to water and wastewater utilities at no cost, starting with a test run in Texas.

BGP Hijack Targets Softaculous Traffic, Delivers Malware
In a shocking 33-hour heist, a BGP hijack diverted traffic meant for Softaculous, delivering malware to unsuspecting users via a valid TLS certificate issued to the attacker. The clever hack exploited a weakness in internet routing, allowing the attacker to intercept and compromise Virtualizor installations.