Tag: supply chain
853 articles

Tool Exposes Stale AI Overrides in JavaScript Ecosystem
Discover how a simple oversight in your JavaScript ecosystem can leave you vulnerable to security threats, and learn how the CVE Lite CLI tool can help you identify and fix stale AI overrides. This free, OWASP-endorsed dependency scanner provides actionable vulnerability fixes and keeps your projects secure.

FortiBleed Campaign Exploits FortiGate Devices to Harvest Credentials
A massive cyber operation, known as FortiBleed, has been secretly targeting over 430,000 FortiGate firewalls worldwide since February 2026, allowing hackers to harvest and crack sensitive VPN and authentication credentials on a huge scale. This alarming campaign has enabled large-scale credential harvesting, putting countless online security systems at risk.

WordPress Plugins Backdoored in ShapedPlugin Supply Chain Attack
A recent supply chain attack on ShapedPlugin compromised the updates for several WordPress plugins, including Product Slider Pro for WooCommerce, injecting backdoor code that could give attackers full control of affected sites. This severe vulnerability, rated 10.0 on the CVSS scale, highlights the importance of staying vigilant about plugin updates and security.

Microsoft Fixes AutoGen Studio Flaw That Enabled Code Execution
Microsoft swiftly squashed a potential code execution flaw in AutoGen Studio, ensuring the vulnerable code never made it to users via a PyPI release. The fix addressed a sneaky three-part vulnerability chain, dubbed AutoJack, that could have been exploited to run malicious code.

Australia's Food Security Prepares for Stress Test
A year of global turmoil has put Australia's food security to the test, proving that ensuring a steady food supply is crucial to national resilience. Recent events, from the Iran-Israel missile exchange to Strait of Hormuz pressures, have highlighted the need for governments to address vulnerabilities in the country's food system before it's too late.

Dify Vulnerabilities Expose AI Chats Across Tenants
Researchers have uncovered four critical vulnerabilities in Dify, a popular AI platform with over 146,000 GitHub stars, that could allow attackers to read sensitive AI conversations across different customer applications without needing authentication. These flaws, collectively known as DifyTap, expose a broad attack surface due to Dify's default multi-tenant setup.

Unpatchable Apple BootROM Flaw Targets A12, A13 Chips
A newly discovered Apple BootROM flaw affecting A12 and A13 chips poses a lifelong security risk to affected devices, as the issue is embedded in unchangeable code that can't be fixed with a simple software update. This vulnerability, known as usbliter8, is a complex combination of hardware and firmware flaws that creates a pathway to compromise the boot chain on impacted Apple systems.

Malicious Google Ads Deliver CastleStealer via New OXLOADER Malware
Beware of malicious Google ads that can deliver CastleStealer via the new OXLOADER malware, which has shown impressive engineering skills and is worth keeping an eye on. Victims are tricked into downloading fake Node.js versions through ads masquerading as legitimate sources.

FortiBleed Campaign Exposes 80K Targets Worldwide
A massive cybersecurity threat, dubbed FortiBleed, has exposed over 80,000 Fortinet FortiGate devices worldwide, with alarming ease, by exploiting weak passwords and reused credentials. The US Cybersecurity agency is urging affected customers to secure their appliances immediately to prevent a potential breach.

Legacy Infrastructure Exposes AI Agents to Hijacking Risks
Legacy infrastructure can put your AI agents at risk of hijacking, as seen with CVE-2025-24813, a remote code execution flaw that lets attackers turn a routine server compromise into a full takeover. An unpatched Internet-facing Apache Tomcat server is all it takes to expose your enterprise to this threat.

Microsoft Links North Korea to Mastra AI Supply Chain Compromise
Microsoft has uncovered a massive supply chain attack on the npm registry, where over 140 packages were compromised, and has linked the operation with high confidence to Sapphire Sleet, a notorious North Korean state actor known for targeting the financial sector. This large-scale attack highlights the growing threat of North Korean hacking groups.

Klue Breach Exposes Cybersecurity Firms to OAuth Token Abuse
A single compromised credential led to a massive security breach at Klue, allowing an unauthorized actor to exploit OAuth tokens and gain access to sensitive customer data on third-party platforms like Salesforce. This incident highlights the growing threat of OAuth token abuse and the need for robust cybersecurity measures.

NCSC Warns Fortinet Customers of Credential Theft Fallout
A massive database of 75,000 stolen credentials, including usernames, email addresses, and passwords, has been discovered, putting organisations like Oracle, Spotify, and AT&T at risk. The leak, dubbed "FortiBleed," affects customers in 194 countries and over 21,000 domains, with nearly half of all internet-accessible Fortinet firewalls potentially exposed.

Australia Urged to Rapidly Develop Cheap Drone Interceptors
In a chilling display of modern warfare, Russia's 900-strong drone assault on Ukraine in 2026 has sounded alarm bells - will Australia be prepared to counter the threat of cheap, destructive drones? Shahed-class drones, with their 50kg high-explosive warheads, have proven capable of devastating effects, from leveling apartment blocks to crippling critical infrastructure.

Microsoft attributes Mastra AI supply chain attack to North Korean hackers Sapphire Sleet
Microsoft warns that a recent supply chain attack on the Mastra AI npm environment was carried out by Sapphire Sleet, a notorious North Korean hacking group known for targeting the financial sector. This latest incident is part of a larger pattern of attacks that exploit open-source distribution channels.

Klue OAuth Breach Expands as Icarus Hackers Claim Multiple Victims
Klue's CEO Jason Smith revealed that on June 12, unauthorized activity was detected in their integration infrastructure, prompting a thorough investigation with cybersecurity experts to understand the breach and support affected customers. The incident allowed hackers to steal OAuth tokens through a compromised legacy credential, impacting connections to third-party platforms like Salesforce.

Pakistan Taps Private Sector to Accelerate Drone Development
Pakistan is taking a giant leap in drone technology, bringing together the country's top defence officials and private sector innovators to revolutionize its unmanned capabilities. By joining forces, they're set to supercharge the development of homegrown drones for warfare and surveillance.

Texas Data Breach Exposes 3 Million Driver's Licenses
A massive data breach has hit Texas, exposing the driver's license information of over 3 million hunting and fishing license customers, leaving them vulnerable to identity theft and other cyber threats. The breach occurred through a third-party license system used by the Texas Parks and Wildlife Department.

Texas Breach Exposes 3 Million Records
A massive data breach at a Texas vendor has exposed the personal information of over 3 million Texans, prompting swift action from the Texas Parks and Wildlife Department to bolster security measures and protect customer data. The breach, which affected 3,087,721 individuals, highlights the importance of robust safeguards in today's digital landscape.

Pentagon Invokes Defense Production Act to Bolster Munitions Supply Chain
The Pentagon is taking a proactive approach to strengthening its munitions supply chain, leveraging the Defense Production Act to foster long-term industrial coordination through voluntary agreements. It’s a carefully planned move that’s taken nine months to come to fruition, according to Michael Cadenazzi, the Pentagon’s industrial base policy chief.

US Air Defenses Face Munitions Stockpile Challenges
The US air defense systems have proven effective, but their success relies on a dwindling stockpile of crucial components like solid rocket motors, leaving the nation with fewer interceptors and limited options to defend against threats. A balanced approach, or "high-low mix," is urgently needed to address the pressing issue of munitions shortages.

Accenture Bolsters Industrial Cybersecurity with $4.18B Acquisition Spree
As Robert M. Lee aptly puts it, our critical infrastructure, from energy and water systems to manufacturing plants, is crying out for robust cybersecurity that can stay one step ahead of evolving threats - and failing to deliver it could have disastrous societal consequences. Accenture is answering the call with a whopping $4.18 billion investment to bolster industrial cybersecurity.

Embraer Accelerates KC-390 Production Amid Growing Global Demand
Embraer is ramping up production of its KC-390 Millennium aircraft to meet surging global demand, with plans to build six this year and ten by the end of the decade. The company is gearing up to meet current customer commitments and future needs, according to Marcio Monteiro, chief marketing officer of Embraer's defense division.

NetNut Exposed in Massive Popa Botnet Operation
Meet Popa, a sneaky Android-based plugin that's been secretly infiltrating over 1.4 million internet addresses via unofficial streaming apps and set-top devices, researchers have uncovered. This stealthy operation is linked to the notorious Vo1d botnet family, which has been targeting vulnerable Android TV boxes.