Skip to main content

Tag: supply chain

854 articles

Developer workstation with code review on laptop, terminal and phone nearby, under natural daylight.

AI Code Review Foils Malicious npm Supply Chain Attack

When Roman Imankulov asked his local AI agent to vet a suspicious code repository, it swiftly warned him away, saying "Don't run this code, just walk away - there's a trap." This near-instant response likely saved Imankulov from a malicious npm supply chain attack.

Analyst 207
Rows of storage servers and networking equipment in a large data center.

Google Vertex AI SDK Flaw Exposes Model Uploads to Hijacking

A newly discovered flaw in the Google Vertex AI SDK for Python left model uploads vulnerable to hijacking, allowing attackers to swap models and execute code within Google's serving infrastructure in a matter of seconds. This vulnerability, found by Palo Alto Networks Unit 42, could be exploited in just 2.5 seconds - a window of opportunity for attackers to wreak havoc.

Analyst 207
Server room with rows of computer servers and a single, highlighted vulnerable system.

Google Cloud Vertex AI Vulnerability Exposes Cross-Tenant RCE Risk

A recent vulnerability in Google Cloud's Vertex AI Python SDK left the door open for cross-tenant attacks, allowing hackers in separate projects to hijack model uploads and potentially execute malicious code remotely. This flaw was fortunately patched in version 1.148.0, released on April 15, 2026.

Analyst 207
Person holding letter with puzzled expression in hospital setting.

Breach Notice Error Fuels Patient Skepticism

A simple mistake on breach notices sent by third-party vendor Xsolis sparked skepticism among patients when the letters misnamed Rochester Regional Health as "Rochester Regional Medical Center", leading many to dismiss them as scams. This misstep undermined trust and raised questions about the effectiveness of the breach notification process.

Analyst 207
Brightly-lit industrial control panel in a utility company's operations center.

Cal Water Probes Alleged Hacking by Iran-Linked Group

Cal Water is taking swift and decisive action to investigate allegations of a cybersecurity incident, swiftly activating its response plan and working around the clock to get to the bottom of the claim. The utility confirms that its probe, launched after learning of the alleged hacking by an Iran-linked group on June 11, 2026, is ongoing with no known operational disruptions reported so far.

Analyst 207
Laptop on office desk with Microsoft Teams on screen in brightly-lit room.

Ransomware Gang Exploits Microsoft Teams for C2 Traffic

Meet the sneaky ransomware gang that hijacked Microsoft Teams to secretly control its victims' systems for two whole months, using sophisticated cyber tradecraft to stay under the radar. They pulled off this impressive heist with a custom backdoor and some clever C2 traffic disguises.

Analyst 207
Government agency office interior with computer workstations and a desk, featuring soft natural light and muted colors.

China-Linked Backdoor Expands to Windows with Kernel Stealth

A China-linked espionage group has unleashed a stealthy backdoor that infiltrates Windows systems, targeting government bodies in Honduras, Taiwan, Thailand, and Pakistan. The malware, known as SprySOCKS, boasts advanced espionage features and kernel-level stealth, making it a formidable threat.

Analyst 207
Person holds smartphone with blurred screen in a public area, expression neutral.

Rokarolla Trojan Enables Unseen Banking Fraud via Device Takeover

Meet Rokarolla, a sneaky Android banking trojan that's taking device takeover to a whole new level, allowing scammers to isolate and exploit victims like never before. This malicious malware doesn't just steal credentials - it gives attackers total control over your phone.

Analyst 207
Developer works in secure lab with laptop displaying lines of code.

Chainguard Launches Athena to Fortify Open Source Against AI Threats

Meet Athena, a groundbreaking coalition and platform that helps safeguard open-source software from AI-driven threats by streamlining vulnerability detection, private remediation, and coordinated disclosure. By joining forces, Athena members can proactively protect the entire open-source ecosystem from emerging risks.

Analyst 207
Office workers at desks with laptops and phones, Microsoft Teams logo visible in background.

DragonForce Ransomware Exploits Microsoft Teams to Facilitate Months-Long Breach

Meet Backdoor.Turn, a sneaky new threat that uses Microsoft Teams to hide its tracks and wreak havoc on your network for months on end - and it's surprisingly sophisticated. This Go-based RAT masquerades as legit traffic by exploiting Teams' TURN relay servers.

Analyst 207
Government building stands under bright sunlight with a hint of unease.

Google Uncovers China Espionage Group UNC6508 Lurking Undetected Since 2023

Google's Threat Intelligence Group has uncovered a stealthy Chinese espionage group, UNC6508, that had been secretly lurking in networks since 2023, targeting key sectors in the US and Canada. The full extent of the damage is still unknown, leaving experts concerned about potential long-term security breaches.

Analyst 207
People work at computer workstations in a dimly lit indoor software development workspace.

North Korean Hackers Exploit Developer Tools in Malware Campaigns

North Korean hackers have launched a sneaky malware campaign, tricking victims into executing cross-platform malware for macOS, Linux, and Windows through malicious scripts hidden in GitHub repositories. Their latest tactic, dubbed UNK_DeadDrop, uses recruitment lures to deliver self-running code to over 75% of targeted organizations across various sectors.

Analyst 207
Server room with technician's remote support session on blurred computer screen.

SimpleHelp vulnerability exposes servers to rogue remote support accounts

A critical vulnerability in SimpleHelp, known as CVE-2026-48558, lets hackers create rogue remote support accounts and gain privileged access to servers, allowing them to execute scripts and wreak havoc on your system. This gaping security hole enables unauthenticated attackers to bypass multi-factor authentication and log in as a Technician user, putting your entire network at risk.

Analyst 207
Server room with rows of blinking equipment, indicating a compromised network setup.

OptinMonster Plugin Compromised in Supply-Chain Attack

A critical security breach has hit the popular OptinMonster plugin, used by over 1.2 million websites, which delivered malicious JavaScript to unsuspecting users via a compromised content distribution network. The attack, detected by ecommerce security firm Sansec, injected harmful code into websites for a brief but perilous window of time.

Analyst 207
Government office interior with computer screen displaying abstract database representation.

ShinyHunters Breach Council of Europe in Oracle PeopleSoft Heist

The Council of Europe has fallen victim to a massive data breach, with hackers claiming to have stolen a whopping 297 GB of sensitive information, including HR records, payslips, and medical data, by exploiting a zero-day flaw in Oracle PeopleSoft. The ShinyHunters extortion group is behind the breach, boasting a haul of 429,000 files from the attack.

Analyst 207
Network management system interface on a laptop screen in a modern office space.

Cisco Patches SD-WAN Flaw Exploited in Zero-Day Attacks

Cisco has patched a high-risk SD-WAN flaw, known as CVE-2026-20262, that was being exploited in zero-day attacks to gain root privileges. The vulnerability allowed attackers to create or overwrite files on affected systems, and Cisco has now released security updates to fix the issue.

Analyst 207
Bustling Adriatic port with cargo yard and trucks, foreground shows blurred computer system.

Anubis Ransomware Targets Adriatic Port, Exposes Maritime Security Gaps

A ransomware attack by the Anubis group on the Adriatic Port Authority exposed significant gaps in maritime security, putting sensitive employee records and critical infrastructure at risk. The breach, which occurred on December 11, 2025, resulted in the loss of around 2% of the authority's data, with some information making its way to the dark web.

Analyst 207
WordPress plugin developer's workspace with code on screen, coffee, and notes on a minimalist wooden desk.

Malicious Code Infiltrates WordPress Plugins, Creates Rogue Admin Accounts

Over 1.2 million WordPress sites are at risk after attackers infiltrated a trusted vendor's network, injecting malicious code into popular plugins like OptinMonster, TrustPulse, and PushEngage. This sneaky hack creates rogue admin accounts, putting sites at risk of takeover - all without ordinary visitors even noticing.

Analyst 207
Cluttered home office desk with Linux workstation, notes, and technical books.

Arch Linux Cracks Down on Malicious Commits in User Repository

Malicious hackers have launched a massive assault on the Arch User Repository, compromising over 1,500 user-submitted packages and forcing the Arch Linux team to temporarily halt new account signups to contain the damage. The attack has been mitigated, but not before highlighting the vulnerability of community-run package repositories.

Analyst 207
School office with computer workstation and papers, blurred cityscape in background.

ShinyHunters Breach Exposes 137,000 Infinite Campus Staff Accounts

A massive data breach at Infinite Campus has exposed the sensitive information of 137,000 staff members, including names, email addresses, phone numbers, and physical addresses, after the ShinyHunters extortion group hacked into the company's Salesforce instance. The stolen data has been published online, putting staff at risk of identity theft and phishing scams.

Analyst 207
Person sitting at a desk in a well-lit room, with a subtle hint of digital vulnerability.

WordPress Plugins Compromised to Deploy Hidden Backdoors

Over 1.2 million WordPress sites are potentially at risk after a security breach compromised three popular plugins, allowing hackers to secretly install backdoors and gain admin access. The sneaky attack injects malicious code that only kicks in when a logged-in administrator visits the site, putting unsuspecting site owners in the dark.

Analyst 207
Rows of computer servers with removed screens and access panels in a neutral data center environment.

Australia's AI Vulnerability Exposes Limits of Global Interdependence

In a stunning move, Anthropic was forced to disable access to its cutting-edge AI models, Claude Fable 5 and Mythos 5, globally just days after their release, due to a US export-control directive. This swift decision highlights the fragile nature of global access to advanced technologies.

Analyst 207
Network equipment sits in a brightly-lit corporate office setting.

Palo Alto Networks Warns of Active Exploitation of GlobalProtect VPN Flaw

Palo Alto Networks has warned of active exploitation of a critical GlobalProtect VPN flaw, CVE-2026-0257, which allows attackers to bypass security controls and set up unauthorized VPN connections. The company first observed exploitation attempts on May 17, 2026.

Analyst 207
Law enforcement officials stand in a brightly-lit press conference room with subtle hints of technology and cybersecurity…

FBI Disrupts AI-Powered Phishing Service with 1 Million URLs

In a major win for cyber safety, the FBI, Google, and Black Lotus Labs joined forces to dismantle Outsider Enterprise, a notorious phishing-as-a-service operation based in China that had been spreading fake text campaigns through 1 million URLs. This coordinated takedown seized key servers and accounts used by the threat actors.

Analyst 207