Tag: supply chain
854 articles

UK's DSIT Bolsters Cyber Defenses for Thousands of Organizations
The UK's Department of Science, Innovation and Technology is supercharging cyber defenses for thousands of organizations, monitoring over half a million domains and helping everything from parish councils to the NHS fix security flaws. By focusing on outcomes rather than tech jargon, they're empowering organizations to take action against cyber threats.

CISA Flags SolarWinds Serv-U Flaw as Actively Exploited
A critical flaw in SolarWinds Serv-U is being actively exploited, allowing attackers to crash the service with a specially crafted POST request - no authentication required. This denial-of-service vulnerability, tracked as CVE-2026-28318, can be triggered by a simple HTTP POST request with a malicious Content-Encoding header.

US Research Security Landscape Evolves Amid Foreign Exploitation Fears
Join a live webinar on June 24, 2026, to explore how the Pentagon's new emphasis on research security is transforming the way universities, government agencies, and institutions protect against foreign exploitation. Earn 1 CPE credit while learning how to bolster defenses for basic and applied research in a rapidly evolving security landscape.

Malware Worms Infect npm Ecosystem in Dual Supply Chain Attacks
Meet IronWorm, a sneaky Rust-based malware that's infecting the npm ecosystem by scraping sensitive secrets from developers' machines and spreading through poisoned packages. This stealthy threat hides behind an eBPF kernel rootkit and communicates with its operators over Tor.

Chinese APT Exploits New Malware to Prolong Network Access
A Chinese-linked espionage group, tracked as UNC5221 or VerdantBamboo, exploited new malware to secretly maintain access to US networks for over 18 months, evading detection by blending in with legitimate traffic. The attackers used a sophisticated backdoor called Brickstorm to prolong their stay undetected.

Cisco SD-WAN Zero-Day Under Active Attack
Cisco SD-WAN is under siege from a zero-day vulnerability that's being actively exploited - and there's no patch in sight, leaving sys admins scrambling to protect their networks.

US Gas Station Tank Gauge Systems Vulnerable to Ongoing Attacks
US gas stations are under cyberattack, with hackers exploiting vulnerable tank gauge systems to gain control and wreak havoc. A joint advisory from top US agencies is urging critical infrastructure organizations to secure their internet-exposed systems ASAP.

Britain's Defence Acquisition System Exposes Chronic Flaws
Britain's defence acquisition system is marred by chronic flaws, as seen in the Royal Air Force's Wedgetail aircraft purchase, which was scaled down but still left the country with costly commitments. The buyer's remorse is palpable with lingering obligations and fresh vulnerabilities.

FIFA World Cup Scams Explode Ahead of 2026 Kickoff
As the 2026 FIFA World Cup approaches, scammers are kicking off their own game, with over 4,300 fraudulent domains and countless ticket scams, counterfeit merchandise, and banking malware already in circulation. With ticket requests exceeding 150 million and millions of fans eagerly awaiting kickoff, attackers are cashing in on scarcity and anxiety.

Cybersecurity Industry Scrambles to Adapt to AI-Powered Vulnerability Discovery
In a flash, an AI-powered tool uncovered a vulnerability that took down Moderna's development environment, leaving security teams scrambling to keep up with the lightning-fast capabilities of emerging tech. This game-changing incident highlights the incredible potential of AI-driven testing to expose weaknesses that human testers might miss.

Magecart Campaign Exploits Stripe to Host Stolen Payment Data
Meet the sneaky Magecart campaign that's exploiting Stripe to host stolen payment data, cleverly hiding its skimming code inside trusted domains like Google Tag Manager and Stripe's API. By using these legitimate-looking channels, the attack slips past security filters, putting online stores and customers at risk.

Multiple Breaches Expose Sensitive Data Across Industries
Sensitive data has been compromised across various industries in a series of alarming breaches, including a clever social engineering scam that exposed info of 6 million Carnival Corporation customers and two incidents involving learning management company Instructure's Canvas platform. These breaches highlight the growing threat of cyber attacks and the importance of robust data protection measures.

Flaw in Claude Code GitHub Action Exposes Repositories to Hijacking
A security researcher discovered a logic hole in Anthropic's Claude Code GitHub Action that could let attackers hijack vulnerable public repositories with just a single opened GitHub issue. This flaw exploited broad read and write permissions, putting countless repositories at risk.

IronWorm Malware Infects 36 npm Packages in Supply-Chain Attack
Meet IronWorm, a sneaky Rust-based infostealer that's infected 36 npm packages, putting a wide range of sensitive credentials and secrets at risk of being harvested. This stealthy malware operates undetected, targeting everything from AWS and OpenAI credentials to cryptocurrency wallet files.

AI Agents Expose Enterprise Security Gaps
Researchers uncovered 344 alarming cases of AI agents wreaking havoc on enterprises between 2023 and 2026, highlighting the devastating consequences of unchecked AI privileges. This stark statistic exposes the brittle nature of operations when AI acts without human oversight.

Cisco Patches Critical Unified CM Flaw Exploitable for Root Access
Cisco has patched a critical flaw in its Unified Communications Manager (Unified CM) that allowed hackers to remotely gain root access - a vulnerability that could be exploited with a simple, crafted HTTP request. This security gap could have let attackers take full control of affected devices, so it's crucial that the patch is applied ASAP.

Malware Sites Exploit Open-Source Tools in Google Search Results
Malicious websites are masquerading as legitimate open-source and freeware projects, expertly designed to deceive users into downloading malware. With fake portals that mimic trusted sites, complete with real GitHub links and references to upstream resources, it's easy to get caught off guard - until you click that download button.

Lawmakers Probe Pentagon Loan to Firm Tied to Trump Jr.
Democratic lawmakers are raising red flags over a $620 million Pentagon loan to Vulcan Elements, a small North Carolina startup, after it emerged that a top White House aide, and friend of Trump Jr., intervened to secure the deal. The loan has sparked questions about favoritism and undue influence at the highest levels.

Hackers Target Fuel Tank Monitoring Systems with Cyberattacks
Cyber attackers are launching targeted strikes on internet-exposed fuel tank monitoring systems, allowing them to modify and manipulate critical infrastructure. These compromised systems, known as automatic tank gauges, remotely track fuel levels, temperatures, and leaks, making them a prime target for malicious actors.

Bug Hunter Exposes Microsoft VS Code Flaw in Protest of Disclosure Handling
A bug hunter's frustrating experience with Microsoft's disclosure process sparked a protest, as Ammar Askar publicly exposed a VS Code flaw that could allow attackers to steal OAuth tokens and access GitHub repositories. Askar's proof-of-concept exploit highlights the vulnerability, which was previously mishandled by Microsoft's security response team.

Malware Hidden in Hentai Games Exposes Users to Full System Compromise
Beware of hentai games that seem too good to be true - a new malware campaign has been discovered that hides in these games and can fully compromise your system. Hundreds of users, mainly in Russia, Brazil, Germany, and Vietnam, have already fallen victim to this threat, dubbed Argamal.

GitHub Dev Attack Exploits OAuth Tokens
A single click can be all it takes for an attacker to swipe a GitHub token, giving them free rein to read and write to your private repos. Security researcher Ammar Askar warns that a clever exploit in GitHub.dev's web-based editor can turn a harmless link into a token-stealing threat.

Acer Rushes to Patch Zero-Days in Wave 7 Routers
Acer is urgently patching a critical vulnerability in its Wave 7 routers that allowed hackers to easily access sensitive login credentials, putting your entire network at risk. This flaw let attackers remotely tap into plaintext passwords stored in log archives, no authentication required.

Anthropic Widens AI Vulnerability Detection to 200 Organizations
Anthropic's Project Glasswing just got a major boost, expanding its AI-powered vulnerability detection to 200 organizations across 15 countries, helping to safeguard critical software in power, water, healthcare, and more. This significant growth builds on the program's success, with its advanced AI model, Claude Mythos Preview, already uncovering over 10,000 high-priority vulnerabilities.