Skip to main content

Tag: supply chain attacks

44 articles

Person typing on laptop in modern office workspace surrounded by papers and notes.

Aurora Ransomware Operators Leverage AI Tool Cursor in Targeted Attacks

Aurora ransomware operators are using AI tool Cursor to plan and execute targeted attacks, even going so far as to instruct it in Russian to exclude certain regions and domains. This sophisticated approach has enabled the group to breach over 20 organizations across nine countries in just a few months.

Analyst 207
Two men in casual clothing stand in a neutral-colored police station with a subtle Australian Federal Police emblem in the…

Australian Police Disrupt TeamPCP Hacking Group Behind Global Supply-Chain Attacks

Australian authorities have made a major breakthrough in the fight against global supply-chain attacks, arresting two men linked to the notorious TeamPCP hacking group. The suspects, aged 21 and 23, were taken into custody after a year-long investigation into a string of devastating developer supply-chain intrusions.

Analyst 207
Two men in formal attire stand in a courtroom with electronic devices on a table, surrounded by subtle police emblems and…

Australia Charges Two in TeamPCP Cybercrime Case Tied to Supply Chain Attacks

In a major breakthrough, the Australian Federal Police charged two men with 14 offences for their alleged roles in the notorious TeamPCP cybercrime syndicate, which compromised over 1,000 organizations worldwide and stole more than 500,000 credentials. The suspects, aged 23 and 21, were arrested and appeared in court after a joint operation seized electronic devices for forensic analysis.

Analyst 207
US Treasury Department podium with empty lectern and circular seal, set against a large window with daylight streaming in.

Treasury Targets Iranian Hackers Tied to US Critical Infrastructure Breaches

The Treasury Department has taken a bold step, calling it an "economic D-Day," by imposing sanctions on five Iranian hackers linked to a string of brazen cyberattacks on US critical infrastructure, government offices, and digital assets. This move is part of a broader effort to isolate Iran and cut off its revenue streams.

Analyst 207
A cluttered office cubicle with laptop, phone, and papers, with a blurred cityscape in the background and a person's hand…

ZeroTokens Phishing Platform Enables Real-Time Attack Adaptation

Meet ZeroTokens, a sneaky phishing platform that's sending shockwaves with its real-time attack adaptation capabilities, allowing live operators to steer victims through a multi-stage scam. Over 45,000 phishing messages have already been sent to 24,000 recipients across 700 organizations, making it a threat that's hard to ignore.

Analyst 207
Typical office desk with laptop and smartphone, blurred screens, in ordinary office setting with daylight.

Mirage2FA Campaign Targets 4,500 Firms, Bypasses Microsoft 365 2FA

Thousands of companies, including 4,532 unique organizations worldwide, have been targeted by the Mirage2FA campaign, a sneaky phishing-as-a-service toolkit that cleverly bypasses Microsoft 365's two-factor authentication. US-based companies are among the hardest hit, making up 63.7% of the victims.

Analyst 207
A Linux workstation with a laptop showing a terminal window on a plain surface amidst scattered papers and a small potted…

Malicious npm Packages Deploy AI-Powered RedC2 Linux Backdoor

Beware of 14 seemingly harmless npm packages that masquerade as calendar and streak utilities, but secretly deploy an AI-powered Linux backdoor, turning your system into a vulnerable target. These trojanized packages contain a bundled native binary that launches a detached background process, allowing malware to spread undetected.

Analyst 207
Person holding smartphone with blank screen, thumb hovering, in a blurred public setting.

ToxicPanda Malware Expands Target List to 140+ Banking and Crypto Apps

Meet ToxicPanda 2.0, a sneaky new Android banking Trojan that's expanded its target list to over 140 banking and crypto apps, allowing attackers to swipe PINs, lock devices, and gain shell-level access. This upgraded malware is particularly alarming, as it operates seamlessly within Android, making it a stealthy threat.

Analyst 207
Defense sector office with computer workstation and blurred monitor screen.

Lazarus Exploits Windows Zero-Day in Targeted Defense Sector Attacks

The notorious Lazarus threat group has been exploiting a newly patched Windows zero-day vulnerability, CVE-2026-68820, to gain SYSTEM privileges and escalate their attacks on high-value targets in the defense sector. This alarming exploit has been active since early July, making it crucial for organizations to stay vigilant.

Analyst 207
A typical defense sector industrial setting with a computer workstation in the mid-ground, surrounded by ordinary activity.

Lazarus Group Exploits Microsoft Zero-Day in Global Defense Sector Attacks

North Korea's notorious Lazarus Group has been exploiting a Microsoft zero-day vulnerability, CVE-2026-68820, since early June, targeting the global defense sector with alarming precision. This high-severity flaw, patched in August, allowed attackers to execute code with SYSTEM-level privileges, putting countless systems at risk.

Analyst 207
Laptop screen displays npm package management interface amidst office workspace.

AWS Tracks North Korean Group in npm Supply Chain Attacks

AWS has uncovered a string of sneaky supply-chain attacks on popular npm libraries, and their threat intel team is pointing to a notorious North Korean group, known as Saphire Sleet, as the likely culprit. The attacks hit big-name libraries like axios, debug, and chalk, raising concerns about the security of the software supply chain.

Analyst 207
Office interior with laptop on a desk, windows and cityscape in background.

Russian Spies Expand Email Attacks to Outlook

Russian spies have set their sights on Microsoft Outlook Web Access, exploiting a cross-site scripting flaw to launch targeted email attacks, just days after being called out for their abuse of a zero-day vulnerability in Zimbra Collaboration Suite. The notorious group, tracked as TA488 or Laundry Bear, has adapted their sneaky half-click technique to compromise on-premises Exchange Servers.

Analyst 207
Laptop screen displays innocuous webpage with subtle hidden code in background.

Web Content Conceals Hidden Instructions Targeting AI Agents

As AI agents increasingly interact with the web, hidden instructions embedded in online content can be manipulated to perform unintended actions, posing a new threat to users. Researchers have uncovered real-world campaigns that use indirect prompt injection to steer AI agents into carrying out malicious tasks.

Analyst 207
Ukrainian government building interior with a computer workstation and hints of cyberattack disruption.

Gamaredon Intensifies Ukraine Cyberattacks with Novel Malware Tools

Gamaredon ramped up its cyberattack efforts in Ukraine last year, unleashing 35 targeted spear-phishing campaigns that zeroed in on government and military targets. The group's goal was to siphon off sensitive information to fuel Russian interests in the ongoing conflict.

Analyst 207
Southeast Asian cityscape with industrial control system hinted in background.

China-Linked Hackers Deploy TinyRCT Backdoor in Southeast Asian Infrastructure Attacks

For years, a stealthy China-linked hacking group has been quietly targeting critical infrastructure in Southeast Asia, with a clear strategic interest in disrupting or monitoring key regional industries. Their sophisticated attacks have zeroed in on state-owned energy and government sectors, using a potent tool called the TinyRCT backdoor.

Analyst 207
Blurred network equipment and generic devices in a brightly-lit tech infrastructure setting.

CISA Warns of Widespread FortiBleed Attacks on 86,644 Devices

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning after a massive cyberattack, dubbed FortiBleed, compromised a staggering 86,644 FortiGate devices, putting countless networks at risk. Take immediate action to protect yourself: shut down active SSL VPN and admin sessions, reset passwords, and enforce strong password policies.

Analyst 207
Security analysts work at a large workstation surrounded by screens displaying data visualizations and threat maps.

Wazuh Cloud Tackles Security Ops Complexity With AI-Driven Analysis

Tired of drowning in security ops complexity? Wazuh Cloud simplifies threat detection and response with AI-driven analysis, freeing you from infrastructure headaches and empowering you to stay ahead of evolving threats like ransomware and supply chain attacks.

Analyst 207
European city street with tech hints and blurred laptop in foreground.

Chinese Hackers Deploy Atlas RAT in Europe With Heightened Cyberattacks

Chinese hackers have significantly ramped up cyberattacks in Europe, with a financially motivated group, tracked as TA4922, launching a high volume of unique campaigns targeting countries including Germany, Italy, and the UK. This surge in activity, which began in March, has been marked by unprecedented diversity in tactics and objectives, including fraud, data theft, and network breaches.

Analyst 207
Laptop on a cluttered wooden desk in a small Ukrainian office with blurred screen.

Russia-Linked GREYVIBE Exploits AI in Ukraine Cyberattacks

Discover how the Russia-linked group GREYVIBE is using AI to launch sophisticated cyberattacks on Ukraine, leveraging tactics like spear-phishing emails and fake websites to spread malware. WithSecure researchers have tracked GREYVIBE's activities back to August 2025, revealing a pattern of attacks targeting Ukraine's military, government, and civilian sectors.

Analyst 207
Formal government building exterior with architectural columns and facade details.

China-Linked UAT-8302 Exploits Shared Malware to Target Global Governments

Meet UAT-8302, a sophisticated China-linked threat group that's been secretly targeting governments worldwide, deploying custom malware to infiltrate and gather intel. Its recent attacks have hit government entities in South America and southeastern Europe, raising global cybersecurity concerns.

Analyst 207
A cluttered office workspace with laptop and papers on a desk in a brightly-lit room.

Silver Fox APT Targets Russia, India with ABCDoor Backdoor

Over 1,600 malicious emails, disguised as tax-audit notices, were sent to targets in India and Russia between January and February 2026, aiming to trick recipients into downloading a backdoor or clicking on a malicious link. The cleverly crafted phishing campaign unfolded in two waves, using PDFs and archives to spread the ABCDoor backdoor.

Analyst 207
Worker looks concerned at laptop screen displaying fake Zoom meeting in modern office.

North Korean Hackers Exploit Crypto Firms with AI-Driven Zoom Lures

North Korean hackers launched a massive spear-phishing campaign, targeting over 100 crypto organizations worldwide with cleverly crafted Zoom lures and AI-generated deepfakes. They used fake calendar invites and typosquatted meeting links to gain access and exfiltrate sensitive data in a matter of minutes.

Analyst 207
Laptop screen shows an open email message in a brightly-lit office setting.

Zimbra Servers Targeted in Ongoing XSS Attacks

Beware of sneaky phishing emails that can hijack your Zimbra server with just a glance - no clicks or downloads required. A single malicious email can trigger a cross-site scripting attack, thanks to a recently patched vulnerability, CVE-2025-48700.

Analyst 207
A factory production line with a glowing red infection point on a circuit board amidst ominous shadows.

Malware Poisons Open Source Tools in Dual Supply Chain Attacks

Imagine trusting a tool, only to have it secretly turned against you - that's what happened in March when two massive supply chain attacks infected popular open source tools with malware, putting tens of thousands of organizations at risk. The full extent of the damage may not be known for months, but one thing is clear: the threat is real and far-reaching.

Analyst 207