Skip to main content

Tag: supply chain

853 articles

Office setting with a laptop on a plain desk, surrounded by neutral decor, under soft daylight.

Nintendo Data Breach Exposes Employee Survey Information

Nintendo of America recently experienced a data breach through a third-party survey service, exposing limited employee survey information, but fortunately, no customer or financial data was compromised. The company is working to resolve the issue and has confirmed that its own systems remain secure.

Analyst 207
Brightly-lit coding workspace with interconnected nodes in the foreground.

TeamPCP Exploits Open-Source Trust Model in Mass Software Compromise

In a shocking display of cunning, TeamPCP has compromised over 1,000 software packages in under four months, injecting malicious code and redefining the notion of trust in open-source supply chains. This brazen attack has left a trail of destruction, with roughly 500 million weekly downloads affected across major registries like npm, PyPI, and GitHub.

Analyst 207
Rare earth processing facility with industrial equipment and heavy machinery.

Pentagon Bolsters Rare Earth Supply with $1.2 Billion in Loans

The Pentagon is investing $1.2 billion to boost the US rare earth supply, with $725 million going to Energy Fuels and $500 million to Phoenix Tailings to enhance domestic processing and magnet production. This significant move aims to strengthen America's foothold in the critical rare earths sector.

Analyst 207
Person sits at laptop in coffee shop with blurred cityscape behind, face neutral and unfocused.

Cyber Trust Erodes as AI, Tools Enable New Attacks

Trust is crumbling in the digital world as hackers exploit AI and tools to launch devastating attacks, turning trusted platforms into malware delivery mechanisms. The latest threat: hijacked Google Ads and AI developer tools used to funnel over 2,000 victims to malicious download pages.

Analyst 207
Rack of networking equipment in a brightly-lit municipal network closet.

Fortinet and Ivanti Exploits Fuel LATAM Infrastructure Attacks

In a shocking revelation, a coordinated campaign dubbed Operation Escaneo has been exposed, targeting critical infrastructure across Mexico, Ecuador, and Portugal, with a staggering 3,708 sessions recorded over just 13 days. The attackers exploited vulnerabilities in Fortinet and Ivanti perimeter appliances to gain entry into government, tax authorities, utilities, transport, telecoms, and banks.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit data center with technicians working in the background.

F5 Dispatched Patches for Critical NGINX Flaws

F5 has urgently released patches to fix two critical vulnerabilities in NGINX modules that can be exploited by remote attackers to cause denial-of-service or even execute remote code. Admins are advised to install the updates ASAP to protect NGINX Plus, Open Source, Gateway Fabric, and Instance Manager from potential attacks.

Analyst 207
Laptop screen shows retail website checkout page with multiple scripts loading in the background.

New PCI DSS Rules Target Script Security on Checkout Pages

Did you know that over 100,000 sites have fallen victim to web skimming and supply-chain attacks, with Magecart-style attacks often sneaking in through third-party scripts on crowded checkout pages? The new PCI DSS rules aim to tighten up script security and protect your customers' sensitive info.

Analyst 207
Aerospace manufacturing facility worker in safety gear amidst industrial equipment.

Honeywell Aerospace Targets Growing CCA Market with Strategic Positioning

As the global market for Collaborative Combat Aircraft takes off, Honeywell Aerospace is strategically positioning itself to meet the surging demand for critical components that will enable loyal wingman drones to fly alongside manned aircraft. With the CCA market poised for dramatic growth, suppliers will face mounting pressure to deliver the parts and systems that unlock the full potential of these game-changing aircraft.

Analyst 207
Patriot missile defense system component on display in a neutral setting.

Congress Probes Pentagon's Ability to Supply Ukraine with Patriot Interceptors

The Senate Armed Services Committee is pressing the Pentagon for answers on whether it can ramp up deliveries of crucial Patriot interceptors to Ukraine, following concerning cutbacks in supplies. Ukrainian President Volodymyr Zelensky revealed that monthly shipments of PAC-3 missiles were slashed due to competing demands from the Middle East, not a lack of funds.

Analyst 207
Laptop screen on a desk in a brightly-lit indoor setting with blurred smartphones and tablets in the background.

Malware Campaign Exploits Fake Reviews to Spread Crypto Clipper

A single threat actor cleverly mimicked legitimate brands to spread Crypto Clipper Malware, using fake reviews, tutorial videos, and promotions on trusted platforms to manufacture credibility for a malicious crypto tool. They created a convincing illusion of a trusted product, complete with inflated download counts and coordinated five-star reviews.

Analyst 207
Network equipment and servers in a server room with blinking lights and laptop screens in the foreground.

Fortinet Firewalls Compromised in Massive Password-Stealing Attack

A massive password-stealing attack has compromised around 75,000 Fortinet firewall devices, putting credentials of major corporations across 194 countries at risk and leaving a trail of full network compromises in its wake. The breach, dubbed FortiBleed, has created a verified database of working credentials for some of the world's largest enterprises, threatening nearly every sector of the global economy.

Analyst 207
Rows of computer servers and storage equipment in a modern, well-maintained data center with daylight visible through…

Europe's Digital Sovereignty Drive Needs New Operating Model

Europe's reliance on just a few major cloud providers is sparking concerns about digital sovereignty, with policymakers worried that over-dependency on foreign technology can compromise national resilience. This concentrated market - where just 3 providers hold around 70% of the market - is driving the urgent need for a new operating model that prioritizes European control and flexibility.

Analyst 207
Rows of equipment racks and networking gear in a brightly-lit server room.

FortiBleed Exposes 73,000 Fortinet VPN Credentials Worldwide

A massive security breach has exposed a whopping 73,000 Fortinet VPN credentials worldwide, putting tens of thousands of firewall endpoints at risk, including those of major companies like Chevron, Samsung, and Mercedes-Benz. The alarming leak, discovered by security researcher Bob Diachenko, contains sensitive information like usernames, email addresses, and plaintext passwords.

Analyst 207
Rows of network equipment in a brightly-lit data center or network operations room.

Cisco Expands SD-WAN Warning on Max-Severity Bug

Cisco has urgently warned organizations using its Catalyst SD-WAN products to investigate their exposure to network compromise and hunt for malicious activity following a maximum-severity bug. This critical alert was issued after Cisco expanded its advisory to include the Cisco Catalyst SD-WAN Validator, which is vulnerable to a 10.0 improper-authentication exploit.

Analyst 207
Developer workstation with laptop, monitor, and coding materials, surrounded by a potted plant and papers, with a JetBrains…

Malicious Plugins Exfiltrate AI API Keys

Beware of malicious AI plugins masquerading as coding assistants on the JetBrains Marketplace - they might just steal your AI API keys. These 15 sneaky plugins, active since October 2025, cleverly exfiltrate API keys to attacker-controlled servers, all while functioning as promised.

Analyst 207
Developer workstation with laptop, monitor, and notes in a bright office setting.

Malicious Plugins Exfiltrate AI API Keys on JetBrains Marketplace

Beware of malicious AI plugins on the JetBrains Marketplace that masquerade as helpful coding assistants but secretly steal your AI API keys. Over 70,000 installations have been recorded from at least 15 compromised plugins that have surprisingly evaded the marketplace's security checks.

Analyst 207
Cluttered developer workstation with code on laptop and notes on desk.

AI Code Review Foils Malicious Backdoor in Python Project

When Roman Imankulov analyzed a suspicious Python project with his AI agent, it quickly flagged a malicious backdoor, saving him from a potentially disastrous mistake. The AI code review proved to be a crucial safeguard, alerting Imankulov to walk away from the tainted code.

Analyst 207
Institutional building entrance with subtle tech elements, hinting at digital breach.

Kodak Breach Exposes Sensitive Data After ShinyHunters Hack

Kodak recently suffered a data breach at the hands of hackers known as ShinyHunters, who gained temporary access to sensitive company data. The company has launched a swift investigation with external cybersecurity experts and is working closely with law enforcement to mitigate the impact.

Analyst 207
Government building in Canberra with a laptop on a surface in the foreground.

Australia Shifts Cybersecurity Focus to Resilience Over Compliance

Australia is taking a bold step in cybersecurity, shifting its focus from mere compliance to building operational resilience, with a AU$89.3 million investment over four years to drive this change. The Horizon 2 Action Plan is set to boost the nation's cyber posture with 19 key actions and 64 initiatives.

Analyst 207
Lockheed and GM representatives meet in a conference room with industrial equipment and munitions components in the…

Lockheed, GM Forge Partnership to Boost Munitions Production

Imagine a partnership that brings together the might of Lockheed Martin's defense expertise and General Motors' manufacturing prowess to supercharge US munitions production - and it all starts with an unlikely duo: the THAAD air defense interceptor and the Corvette. Lockheed and GM are joining forces to strengthen supply chains, advance manufacturing, and boost production capacity.

Analyst 207
Government official stands near military equipment crates at munitions factory.

Pentagon Invokes Defense Production Act to Boost Munitions Output

The Pentagon is turning to the Defense Production Act to supercharge munitions production, allowing it to bring suppliers together to tackle bottlenecks and boost output. By invoking the Act, the department can facilitate collaborative agreements among suppliers that would otherwise be off-limits due to antitrust concerns.

Analyst 207
Workers stand in a sugarcane field with industrial equipment in the foreground under a clear Australian sky.

Cyberattack Disrupts Australian Sugar Production

Mackay Sugar is making a sweet recovery after a cyberattack halted operations, with significant progress made over the weekend in restoring systems and a staged restart of crushing operations on the horizon. The company is getting back on track, with manual crushing already underway at its Farleigh Mill and harvesting expected to resume soon.

Analyst 207
Developer workstation with laptop and monitor, surrounded by notes and coffee cups, in a modern office with natural light.

Malicious JetBrains plugins steal AI API keys

Beware of malicious JetBrains plugins masquerading as helpful tools - at least 15 have been detected stealing AI API keys from unsuspecting developers, with a staggering 70,000 installations. These fake plugins have been secretly siphoning off sensitive information since October 2025.

Analyst 207
Developer workstation with code review on laptop, terminal and phone nearby, under natural daylight.

AI Code Review Foils Malicious npm Supply Chain Attack

When Roman Imankulov asked his local AI agent to vet a suspicious code repository, it swiftly warned him away, saying "Don't run this code, just walk away - there's a trap." This near-instant response likely saved Imankulov from a malicious npm supply chain attack.

Analyst 207