Skip to main content

Tag: supply chain attack

96 articles

Blockchain network operations center with large screen displaying visualization.

Cronos Restarts After $74 Million Tectonic Exploit

Cronos is back online after a swift restart, restoring its chain state to before the $74 million Tectonic exploit and resuming block production from block 90,896,189. The network had temporarily halted activity to protect users from a rapid price-manipulation attack on a major DeFi lending protocol.

Analyst 207
Cluttered software development workspace with laptop, monitor, and papers, amidst a blurred city or office background.

Rust Crates Targeted in Supply Chain Attack to Steal Developer Credentials

For a brief but alarming period, a widely-used Rust package was compromised, funneling malicious code into developer machines and putting sensitive credentials at risk. The attack was launched through a cleverly hidden payload in the build script of a popular crate called proc-macro1.

Analyst 207
Crowded public transportation platform with people in background and two smartphones in foreground.

Manic Malware Exploits Offline Phones via Nearby Infected Devices

Meet Manic, a potent Android banking malware that can infect offline phones by exploiting nearby infected devices, putting financial institutions and users at risk. This sneaky threat combines financial fraud with advanced surveillance and device control features, making it a major concern for banks, governments, and fintech services worldwide.

Analyst 207
Software development workspace with laptop, papers, and coffee cups, surrounded by technical books and equipment.

ChainDrop Worm Infiltrates npm Supply Chain, Evades Defenses

A sneaky new worm called ChainDrop has infiltrated the npm supply chain, infecting 444 packages that are downloaded a whopping 2 billion times each month. This stealthy attack uses a clever tactic, targeting package tarballs rather than repository source commits to evade defenses.

Analyst 207
Smartphone lies on a park bench with cracked screen, near a faint shadow of a hand.

Armored Likho Expands Cyber-Espionage Arsenal

Meet the Armored Likho group, a cyber-espionage mastermind that's just leveled up its game with a suite of sneaky new implants that can hijack Telegram sessions and eavesdrop on conversations. The latest campaign, uncovered in May 2026, uses a cunning fake donation app to infiltrate targets across Russia.

Analyst 207
Modern office workspace with laptop, papers, and pen, hinting at secure networking setup.

Lazarus Exploits Windows Zero-Day with Post-Quantum Key Exchange Tactics

Lazarus hackers have taken a cutting-edge approach, using a post-quantum key exchange to secure their command channel before exploiting a Windows zero-day vulnerability in a targeted campaign against defense and aerospace companies. They leveraged Kyber/ML-KEM, a key encapsulation scheme designed to withstand quantum computer attacks, to generate fresh key material and evade detection.

Analyst 207
WordPress admin dashboard on a laptop screen with a cityscape background and office items nearby.

BdThemes Plugins Targeted in Supply Chain Attack

A sneaky supply chain attack used a BdThemes plugin component to secretly inject malicious code into WordPress dashboards, creating backdoors and deploying stealthy modules without ever touching the plugin files on disk. This clever compromise exploited a vulnerability in the Biggopti library to poison JSON data and trigger an XSS flaw.

Analyst 207
Cluttered home office desk with MacBook displaying suspicious popup window.

Go-Based Malware Targets macOS Crypto Wallets

Beware of a sneaky new scam targeting macOS crypto wallets: a fake CAPTCHA prompt tricks you into copying and pasting a malicious command that can download malware and compromise your wallet. One wrong click is all it takes to put your crypto at risk.

Analyst 207
Rows of computer servers in a brightly-lit data center with a single unoccupied workstation in the foreground.

Oracle Exploited: Attackers Turn SQL Injection into Windows SYSTEM Access

Attackers have successfully exploited a SQL injection vulnerability to gain unprecedented access to Oracle databases, converting it into a Windows SYSTEM-level access with alarming ease. This rare and sophisticated technique has allowed hackers to deploy a custom toolkit, dubbed khunt, that turns database-stored Java into a powerful post-exploitation tool.

Analyst 207
Dimly lit warehouse storage room with stacked cardboard boxes and electronics equipment.

Mustang Panda Exploits QuickFox Supply Chain to Deploy FDMTP Backdoor

Meet the sneaky Mustang Panda hackers, who've exploited a popular VPN tool's supply chain to slip a nasty FDMTP backdoor onto unsuspecting users' devices. They pulled it off with just two lines of JavaScript hidden in a tampered installer.

Analyst 207
Laptop on a desk in a bright office setting displays a notification on a Microsoft Teams interface.

Phishing Campaign Exploits Microsoft Authentication

Cyber attackers have found a sneaky new way to steal corporate accounts by exploiting Microsoft's authentication process, making it harder to spot fake requests. They've been sending emails that look like Microsoft Teams notifications, leading victims to a legitimate Microsoft URL that tricks them into granting access.

Analyst 207
Brightly-lit office workstation with laptop and router in background.

Hackers Exploit FastJson Zero-Day in Targeted US Firm Attacks

US-based organizations are being targeted in a series of attacks exploiting a critical zero-day flaw in the FastJson Java library, with researchers warning that the threat is likely to spread globally. The vulnerability, CVE-2026-16723, allows hackers to execute remote code without user interaction or elevated privileges.

Analyst 207
Server room with rows of computer equipment and exposed cables, featuring a prominent AI agent interface in the foreground.

Hermes AI Agent Fuels Automated Attack on Thai Finance Ministry

Security researchers uncovered a massive 470MB trove of 585 files detailing an automated cyberattack on Thailand's Ministry of Finance, led by the malicious Hermes AI Agent. The stolen data reveals a sophisticated operation, complete with web shells, exploit code, and logs that expose the attack's inner workings.

Analyst 207
Person sitting at desk with laptop displaying blurred webmail interface.

Russian Hackers Exploit Zimbra Webmail in Global Espionage Campaign

Russian hackers have launched a global espionage campaign, exploiting a vulnerability in Zimbra Webmail since July 2025, with a sneaky zero-click phishing attack that tricks victims into handing over sensitive info. The clever tactic uses fake news headlines and hidden code to inject malware into browsers, all without requiring a single click.

Analyst 207
Notepad++ installation package and archive files on a cluttered office desk surrounded by papers and supplies.

Hackers Exploit Notepad++ Plugins to Install Stealthy Malware

Beware of a sneaky malware attack that's using a harmless-looking PDF to trick victims into installing stealthy malware through a fake Notepad++ plugin. The malware is delivered through a cleverly disguised ZIP file that sets off a chain of events, ultimately leading to a malicious DLL being installed on your device.

Analyst 207
Dimly lit coding environment with blurred code on screen and scattered tech items nearby.

Malicious Json Library Targets Online Betting Platform

A sneaky trojanized Json library has been targeting online betting platform Digitain, secretly rigging game results and sending them to an attacker-controlled server. This malicious code was hidden in a fake version of the popular Newtonsoft.Json library, downloaded around 1,200 times.

Analyst 207
Network device with multiple cables on a rack in a brightly-lit operations room.

SonicWall SMA Zero-Days Exploited to Gain Root Access

A newly identified threat actor, UTA0533, has been caught exploiting zero-day vulnerabilities in SonicWall SMA VPN appliances to gain root access, using custom malware and other sophisticated tactics. This alarming attack was uncovered during an incident response in July, with two compromised appliances detected in a single environment.

Analyst 207
Man sits somberly in a courtroom or government agency setting, hands clasped or holding a document.

Armenian National Pleads Guilty to Ryuk Ransomware Conspiracy

Karen Serobovich Vardanyan, an Armenian national, has pleaded guilty to conspiracy charges for his role in a massive Ryuk ransomware scheme that raked in over $15 million in ransom payments from US-based organizations. The guilty plea marks a major win in the fight against cybercrime, as Vardanyan admitted to his part in the global extortion plot.

Analyst 207
Developer workstation with laptop and coding items, hinting at vulnerability with faint shadow and ajar window.

Malicious SDKs Target Paysafe, Skrill Users with Credential Theft

Beware of malicious software development kits (SDKs) masquerading as legitimate Paysafe, Skrill, and Neteller tools, designed to secretly steal your credentials. Researchers uncovered 17 fake packages on popular platforms, putting users at risk of credential theft.

Analyst 207
Developer workstation with coding interface on laptop amidst office surroundings.

AI Coding Assistants Exposed to HalluSquatting Botnet Attack

Researchers have uncovered a sneaky new attack method called HalluSquatting that targets AI coding assistants, exploiting their tendency to invent names and run code with minimal human oversight. This clever tactic chains together AI behaviors like hallucination and prompt injection to deliver malware efficiently.

Analyst 207
Secure facility interior with a symbolic payment terminal or encrypted data storage device.

US Government Entity Pays $1 Million to Thwart Data Leak

A US government entity was forced to pay a hefty $1 million ransom to prevent a massive data leak, after a group called Kairos threatened to release 1.6 million files unless their demand was met. The payment was the culmination of a month-long negotiation that began with a $3 million opening demand.

Analyst 207
Brightly-lit office with rows of computer servers and a large screen displaying a blurred image.

Hackers Inject Malicious Script in Polymarket Supply-Chain Attack

Polymarket has pledged to fully reimburse customers who lost around $3 million in a shocking supply-chain attack that injected malicious JavaScript into the platform's frontend via a third-party vendor breach. The incident highlights the vulnerability of even major players to these types of attacks.

Analyst 207

UK Cyber Monitoring Centre Probes Canvas Breach Impact

The UK's Cyber Monitoring Centre is investigating a massive breach of Canvas, a popular learning management system, that exposed sensitive data at nearly 160 UK universities and colleges, as part of a global incident affecting around 9,000 educational institutions. The breach was caused by a notorious cybercrime group that exploited vulnerabilities on April 29 and again on May 7.

Analyst 207
Cloud computing setup with laptop and servers in a bright office, hint of phishing activity.

GitHub Phishing Kit Targets Mexican Banks via Cloud Services

A sneaky GitHub phishing kit called "GitBait" has been targeting customers of 12 Mexican banks for three years, cleverly using cloud services like GitHub Pages and Google Sheets to stay under the radar. This cunning operation relied on over 100 GitHub-hosted domains to steal credentials, making it a challenging case for investigators.

Analyst 207