Tag: supply chain attack
96 articles

Cronos Restarts After $74 Million Tectonic Exploit
Cronos is back online after a swift restart, restoring its chain state to before the $74 million Tectonic exploit and resuming block production from block 90,896,189. The network had temporarily halted activity to protect users from a rapid price-manipulation attack on a major DeFi lending protocol.

Rust Crates Targeted in Supply Chain Attack to Steal Developer Credentials
For a brief but alarming period, a widely-used Rust package was compromised, funneling malicious code into developer machines and putting sensitive credentials at risk. The attack was launched through a cleverly hidden payload in the build script of a popular crate called proc-macro1.

Manic Malware Exploits Offline Phones via Nearby Infected Devices
Meet Manic, a potent Android banking malware that can infect offline phones by exploiting nearby infected devices, putting financial institutions and users at risk. This sneaky threat combines financial fraud with advanced surveillance and device control features, making it a major concern for banks, governments, and fintech services worldwide.

ChainDrop Worm Infiltrates npm Supply Chain, Evades Defenses
A sneaky new worm called ChainDrop has infiltrated the npm supply chain, infecting 444 packages that are downloaded a whopping 2 billion times each month. This stealthy attack uses a clever tactic, targeting package tarballs rather than repository source commits to evade defenses.

Armored Likho Expands Cyber-Espionage Arsenal
Meet the Armored Likho group, a cyber-espionage mastermind that's just leveled up its game with a suite of sneaky new implants that can hijack Telegram sessions and eavesdrop on conversations. The latest campaign, uncovered in May 2026, uses a cunning fake donation app to infiltrate targets across Russia.

Lazarus Exploits Windows Zero-Day with Post-Quantum Key Exchange Tactics
Lazarus hackers have taken a cutting-edge approach, using a post-quantum key exchange to secure their command channel before exploiting a Windows zero-day vulnerability in a targeted campaign against defense and aerospace companies. They leveraged Kyber/ML-KEM, a key encapsulation scheme designed to withstand quantum computer attacks, to generate fresh key material and evade detection.

BdThemes Plugins Targeted in Supply Chain Attack
A sneaky supply chain attack used a BdThemes plugin component to secretly inject malicious code into WordPress dashboards, creating backdoors and deploying stealthy modules without ever touching the plugin files on disk. This clever compromise exploited a vulnerability in the Biggopti library to poison JSON data and trigger an XSS flaw.

Go-Based Malware Targets macOS Crypto Wallets
Beware of a sneaky new scam targeting macOS crypto wallets: a fake CAPTCHA prompt tricks you into copying and pasting a malicious command that can download malware and compromise your wallet. One wrong click is all it takes to put your crypto at risk.

Oracle Exploited: Attackers Turn SQL Injection into Windows SYSTEM Access
Attackers have successfully exploited a SQL injection vulnerability to gain unprecedented access to Oracle databases, converting it into a Windows SYSTEM-level access with alarming ease. This rare and sophisticated technique has allowed hackers to deploy a custom toolkit, dubbed khunt, that turns database-stored Java into a powerful post-exploitation tool.

Mustang Panda Exploits QuickFox Supply Chain to Deploy FDMTP Backdoor
Meet the sneaky Mustang Panda hackers, who've exploited a popular VPN tool's supply chain to slip a nasty FDMTP backdoor onto unsuspecting users' devices. They pulled it off with just two lines of JavaScript hidden in a tampered installer.

Phishing Campaign Exploits Microsoft Authentication
Cyber attackers have found a sneaky new way to steal corporate accounts by exploiting Microsoft's authentication process, making it harder to spot fake requests. They've been sending emails that look like Microsoft Teams notifications, leading victims to a legitimate Microsoft URL that tricks them into granting access.

Hackers Exploit FastJson Zero-Day in Targeted US Firm Attacks
US-based organizations are being targeted in a series of attacks exploiting a critical zero-day flaw in the FastJson Java library, with researchers warning that the threat is likely to spread globally. The vulnerability, CVE-2026-16723, allows hackers to execute remote code without user interaction or elevated privileges.

Hermes AI Agent Fuels Automated Attack on Thai Finance Ministry
Security researchers uncovered a massive 470MB trove of 585 files detailing an automated cyberattack on Thailand's Ministry of Finance, led by the malicious Hermes AI Agent. The stolen data reveals a sophisticated operation, complete with web shells, exploit code, and logs that expose the attack's inner workings.

Russian Hackers Exploit Zimbra Webmail in Global Espionage Campaign
Russian hackers have launched a global espionage campaign, exploiting a vulnerability in Zimbra Webmail since July 2025, with a sneaky zero-click phishing attack that tricks victims into handing over sensitive info. The clever tactic uses fake news headlines and hidden code to inject malware into browsers, all without requiring a single click.

Hackers Exploit Notepad++ Plugins to Install Stealthy Malware
Beware of a sneaky malware attack that's using a harmless-looking PDF to trick victims into installing stealthy malware through a fake Notepad++ plugin. The malware is delivered through a cleverly disguised ZIP file that sets off a chain of events, ultimately leading to a malicious DLL being installed on your device.

Malicious Json Library Targets Online Betting Platform
A sneaky trojanized Json library has been targeting online betting platform Digitain, secretly rigging game results and sending them to an attacker-controlled server. This malicious code was hidden in a fake version of the popular Newtonsoft.Json library, downloaded around 1,200 times.

SonicWall SMA Zero-Days Exploited to Gain Root Access
A newly identified threat actor, UTA0533, has been caught exploiting zero-day vulnerabilities in SonicWall SMA VPN appliances to gain root access, using custom malware and other sophisticated tactics. This alarming attack was uncovered during an incident response in July, with two compromised appliances detected in a single environment.

Armenian National Pleads Guilty to Ryuk Ransomware Conspiracy
Karen Serobovich Vardanyan, an Armenian national, has pleaded guilty to conspiracy charges for his role in a massive Ryuk ransomware scheme that raked in over $15 million in ransom payments from US-based organizations. The guilty plea marks a major win in the fight against cybercrime, as Vardanyan admitted to his part in the global extortion plot.

Malicious SDKs Target Paysafe, Skrill Users with Credential Theft
Beware of malicious software development kits (SDKs) masquerading as legitimate Paysafe, Skrill, and Neteller tools, designed to secretly steal your credentials. Researchers uncovered 17 fake packages on popular platforms, putting users at risk of credential theft.

AI Coding Assistants Exposed to HalluSquatting Botnet Attack
Researchers have uncovered a sneaky new attack method called HalluSquatting that targets AI coding assistants, exploiting their tendency to invent names and run code with minimal human oversight. This clever tactic chains together AI behaviors like hallucination and prompt injection to deliver malware efficiently.

US Government Entity Pays $1 Million to Thwart Data Leak
A US government entity was forced to pay a hefty $1 million ransom to prevent a massive data leak, after a group called Kairos threatened to release 1.6 million files unless their demand was met. The payment was the culmination of a month-long negotiation that began with a $3 million opening demand.

Hackers Inject Malicious Script in Polymarket Supply-Chain Attack
Polymarket has pledged to fully reimburse customers who lost around $3 million in a shocking supply-chain attack that injected malicious JavaScript into the platform's frontend via a third-party vendor breach. The incident highlights the vulnerability of even major players to these types of attacks.
UK Cyber Monitoring Centre Probes Canvas Breach Impact
The UK's Cyber Monitoring Centre is investigating a massive breach of Canvas, a popular learning management system, that exposed sensitive data at nearly 160 UK universities and colleges, as part of a global incident affecting around 9,000 educational institutions. The breach was caused by a notorious cybercrime group that exploited vulnerabilities on April 29 and again on May 7.

GitHub Phishing Kit Targets Mexican Banks via Cloud Services
A sneaky GitHub phishing kit called "GitBait" has been targeting customers of 12 Mexican banks for three years, cleverly using cloud services like GitHub Pages and Google Sheets to stay under the radar. This cunning operation relied on over 100 GitHub-hosted domains to steal credentials, making it a challenging case for investigators.