Skip to main content

Tag: supply chain

854 articles

Developer workstation with laptop, notes, and coding books under indoor lighting.

GitHub Overhauls npm Defaults to Thwart Script-Based Attacks

GitHub is taking a major step to boost npm security by changing its default settings to block automatic execution of install-time lifecycle scripts, a common vulnerability exploited in script-based attacks. Starting with npm 12, these scripts will require explicit permission to run, unless explicitly allowed via a new allowlist mechanism.

Analyst 207
Mining equipment and excavation site in a remote Australian landscape.

China Warns Australia on Critical Minerals Push

China is hitting back at Australia's critical minerals push, slamming Treasurer Jim Chalmers' decision to force China-linked investors to sell their stakes in rare earths developer Northern Minerals as "irrational de-sinicisation". This move has significant implications for Australia's defence, manufacturing, and renewable energy sectors.

Analyst 207
Secure mobile gateway appliance on a plain surface with a clean, minimalist background.

Ivanti Patches Zero-Day Flaw Allowing Root Code Execution

Ivanti has patched a high-risk zero-day flaw that could let hackers run malicious code with root access, and fortunately, there are no known cases of exploitation so far. The vulnerability, tracked as CVE-2026-10520, affects the company's Sentry secure mobile gateway and allows for OS command injection permitting root execution.

Analyst 207
Military JLTV vehicle on open terrain with industrial facilities in background.

Oshkosh Seeks to Fill Marine JLTV Readiness Gaps with New Bid

Oshkosh Defense is stepping up to help the Marine Corps bridge critical readiness gaps with its combat-proven JLTV A1, a production-ready vehicle that can be delivered quickly. By leveraging its existing production capabilities, Oshkosh aims to provide a reliable solution to the Marines' urgent need for a trusted vehicle.

Analyst 207
Federal officials gather around a conference table with screens displaying risk assessment data and charts.

CISA Overhauls Risk Prioritization Approach for Federal Agencies, Private Sector

CISA is shaking up its approach to risk prioritization, urging a smarter strategy for applying patches and tackling vulnerabilities. Acting director Nick Andersen emphasizes the need to focus on what matters most, rather than rushing to apply every patch as soon as it's released.

Analyst 207
Dimly lit server room with a single brightly lit computer terminal in the foreground.

Veeam Patches Backup Flaw That Enables Remote Code Execution

Veeam has urgently patched a critical backup flaw, CVE-2026-44963, that allowed remote code execution with just domain user credentials, scoring a severe 9.4 out of 10 in severity. The update to version 12.3.2.4854 fixes this vulnerability, preventing attackers from running malicious code on the Backup Server.

Analyst 207
Programmers work at desks in an open-plan office, some looking concerned at their computer screens.

Miasma Worm Spreads as Open-Source Toolkit Compromises GitHub Repos

A newly discovered open-source toolkit, known as Miasma Worm, is wreaking havoc on GitHub repositories, allowing attackers to execute a range of malicious activities via stolen credentials. This powerful supply chain attack toolkit can compromise multiple platforms, including PyPI, npm, and RubyGems, and even spread through AI coding tools and SSH-based lateral movement.

Analyst 207
A modern office interior with a laptop and papers, conveying a tech workspace ambiance.

GitHub Disrupts Microsoft Repos Hosting Password-Stealing Malware

In a lightning-fast response, GitHub and Microsoft swiftly contained a malware incident on June 5, removing 73 repositories and restoring disrupted developer workflows in a mere 105 seconds. The quick takedown prevented password-stealing malware from causing further harm, showcasing the companies' commitment to protecting their platforms.

Analyst 207
Rack-mounted backup server in a data center with front panel facing forward.

Veeam Vulnerability Enables RCE Attacks on Backup Servers

A newly discovered vulnerability in Veeam Backup & Replication could allow an authenticated domain user to launch a remote code execution attack on your backup server - a critical target for hackers. Patch now to protect your data: update to version 12.3.2.4854 or later to fix the flaw.

Analyst 207
Worn computer workstation in a cluttered Ukrainian office with outdated software visible on the monitor.

Russia-Aligned Groups Exploit WinRAR Flaw to Deploy Stealers in Ukraine

Despite a July 2025 patch, a vulnerability in WinRAR, known as CVE-2025-8088, continues to be exploited by Russia-aligned groups, including SHADOW-EARTH-066, to deploy stealers in Ukraine. This highlights the risks of unmanaged software leaving exploited entry points open long after a fix is released.

Analyst 207
Developer workstation with laptop and blurred terminal screen, highlighting supply chain security concerns.

PyPI Packages Poisoned in Hades Supply Chain Attack

Malicious actors have launched a supply-chain attack on the Python Package Index (PyPI), infecting 19 packages with 37 tainted versions that can download and execute a hidden JavaScript payload. This sneaky Hades campaign uses poisoned Python packages to spread its reach, putting developers and users at risk.

Analyst 207
Shipping yard with cargo containers, trucks, and cranes under a clear daytime sky.

Australia Shifts to Just-in-Case Logistics Amid Contested Indo-Pacific

Australia is transforming its logistics strategy from efficient but fragile just-in-time systems to a more resilient just-in-case approach, prioritizing redundancy and preparedness to withstand disruption and conflict in the increasingly contested Indo-Pacific region. This shift means embracing higher costs and complexity to ensure endurance in the face of coercion and uncertainty.

Analyst 207
Qilin Ransomware Breach Tally Grows with Essex Trust Confirmation

Qilin Ransomware Breach Tally Grows with Essex Trust Confirmation

Two years after a devastating ransomware attack, the NHS breach count continues to grow, with an Essex trust now confirming that sensitive patient records were stolen by the notorious Qilin gang. The incident serves as a stark reminder that the impact of this cyberattack is still being felt, with hospitals working tirelessly to identify and warn affected patients.

Analyst 207
Network operations center with a laptop showing a blurred VPN configuration screen amidst office equipment.

CISA Mandates Patching of Exploited Check Point VPN Bug

A critical vulnerability in Check Point VPNs, known as CVE-2026-50751, has been exploited in dozens of organizations worldwide, with one incident linked to Qilin ransomware. This bug allows hackers to bypass authentication and establish remote access, putting targeted organizations at risk.

Analyst 207
Brightly-lit office setting with server room in background and blurred computer terminal hinting at third-party vendor…

SoFi Hong Kong Breach Exposes Customer Data at Third-Party Vendor

SoFi Hong Kong recently discovered a data breach at a third-party vendor that exposed customer information, with unauthorized access detected on April 30, 2026. The company's investigation is ongoing, but it confirmed the breach originated from a vendor, not its internal systems.

Analyst 207
A sleek, modern fighter jet sits idle in a dimly lit industrial setting.

FCAS Fighter Program Implodes Amid Industrial Dispute

The €100 billion FCAS Fighter Program, a joint effort between France, Germany, and Spain to develop a next-generation fighter jet, has reportedly collapsed due to irreconcilable differences between industry giants Dassault and Airbus. The program's demise comes after failed mediation efforts and a final decision by the German government to pull the plug.

Analyst 207
Empty shipping yard with rows of containers and mineral ore piles.

China's Demand-Chain Strategy Upends Australia's Mineral Market Leverage

Can Australia's rich mineral resources still guarantee its economic clout, or will China's demand-chain strategy shake up the global market and redefine who holds the power? The answer lies in whether owning the resources or controlling the demand will ultimately capture the most value.

Analyst 207
Laptop and workstation setup with a blank screen amidst a clean environment.

Shai-Hulud Malware Targets Python Packages, Exposes Developer Secrets

Hundreds of thousands of downloads of 19 popular Python packages were compromised in a massive supply-chain attack that stole developer secrets, courtesy of the Shai-Hulud malware. The malicious packages, disguised as useful bioinformatics and science tools, were actually designed to expose sensitive information.

Analyst 207
Person browsing on a laptop in a busy coffee shop with blurred background.

China Exploits Job Sites for Spying on Five Eyes Targets

Be cautious on job sites - Chinese spies are posing as recruiters on LinkedIn, Indeed, and Upwork to trick Five Eyes targets into divulging sensitive information. They're using clever social engineering tactics to make their scams seem all too believable.

Analyst 207
Remote access VPN setup with laptop and router in foreground and blurred office background.

Check Point Discloses Zero-Day Flaw Exploited by Ransomware Groups

Check Point has uncovered a zero-day flaw, CVE-2026-50751, that allowed ransomware groups to exploit a critical authentication bypass in Remote Access and Mobile Access deployments, prompting an emergency fix. The vulnerability enabled attackers to establish a remote access VPN connection without proper authentication.

Analyst 207
Rows of computer servers and racks in a server room with a researcher in the background.

Gogs Fixes Zero-Day Flaw Enabling Remote Code Execution

A critical vulnerability in Gogs allows attackers to execute remote code, putting Internet-facing instances at risk of full compromise - and it's easily exploitable by anyone who can create an account. This flaw enables attackers to wreak havoc without needing admin privileges, making swift action a must.

Analyst 207
GitHub office interior with developer workstation, server racks, and city view.

GitHub Disrupts Microsoft Repos Amid Suspected Worm Infections

GitHub took drastic action, removing over 70 Microsoft repositories and disrupting critical code pipelines, after detecting suspected worm infections. This swift move has left many automated builds and deployments in limbo.

Analyst 207
Dimly-lit data center with rows of computer workstations and server racks.

Open Source Faces Hard Fork Amid AI-Fueled Security Crisis

The open source community is facing a daunting security crisis fueled by AI, giving rise to a new category of threat dubbed "Mythos" - a complex chain of low-level issues that can be combined to create devastating attacks. This emerging threat is not just a single bug or false positive, but a game-changing phenomenon that demands immediate attention.

Analyst 207
Negotiating table with Su-57 and Rafale models, empty chairs, and South Asia map in background.

Pakistan's Defence Woes Stem from Failed Bargaining Tactics

Pakistan's defence struggles aren't about money, but about negotiation skills - a crucial lesson can be learned from India's recent dealings with Russia over the Su-57, where flexibility and leverage led to better offers. By offering co-production and supply-chain integration, Russia is showing how a bit of generosity can go a long way in securing a favourable deal.

Analyst 207