Skip to main content

Tag: supply chain

854 articles

Developer workstation with VS Code on laptop and GitHub page on nearby device.

VS Code Zero-Day Vulnerability Exposes GitHub Tokens to Theft

A security researcher just revealed a shocking VS Code zero-day vulnerability that lets attackers swipe your GitHub authentication tokens with just one click, exposing your online projects to potential theft. This exploit cleverly abuses VS Code's system to run malicious code and extract sensitive tokens.

Analyst 207
Professionals in a control room discuss around a large table with empty screens.

Anthropic Expands Vulnerability Detection Program to Critical Infrastructure Firms

Anthropic's expanded Vulnerability Detection Program is helping protect critical infrastructure firms from cyber threats, having already uncovered over 10,000 high-risk software vulnerabilities since April. The program, known as Project Glasswing, now includes 150 organizations across 15 countries.

Analyst 207
Laptop screen displays ominous code in dimly lit workspace.

Red Hat npm Scope Hijacked to Spread Cloud Credential Malware

In a shocking 72 seconds, an attacker hijacked Red Hat's npm scope to spread malware, publishing 32 malicious packages that racked up nearly 10 million downloads. The sneaky move exploited the trust developers have in Red Hat's official namespace, turning it into a conduit for cloud credential malware.

Analyst 207
Campaign office with computers, phones, and papers on a desk near a window overlooking a blurred cityscape.

Cybersecurity Threats Target Election Campaign Systems

As the 2026 midterms approach, a new report warns that cybersecurity threats are increasingly targeting the online accounts, platforms, and websites used by election campaigns, donors, and voters, rather than voting machines or ballot-counting systems. This shift in focus allows attackers to exploit vulnerabilities and manipulate public perception with alarming ease and realism.

Analyst 207
Construction site with laboratory framework next to naval base.

Navy Accelerates Munitions Innovation with Maryland Hub

The Navy is revolutionizing munitions innovation with the launch of the Maryland Energetics Innovation Hub, a cutting-edge lab and pilot-scale campus in southern Maryland where government and industry experts will collaborate to drive breakthroughs. This game-changing initiative is set to propel the Naval Surface Warfare Center Indian Head Division to the forefront of energetics innovation and production.

Analyst 207
Russian truck with high-contrast dazzle camouflage paint in a flat, open area.

Russia Deploys Dazzle Camouflage On Trucks To Evade AI-Enabled Drones

Russia is countering AI-powered threats with a blast from the past - "dazzle" camouflage on its trucks, featuring eye-catching zebra stripes and swirling patterns that throw off image-matching seekers used by drones and cruise missiles. By disrupting computer vision models, this unorthodox tactic aims to keep Russian vehicles one step ahead of high-tech adversaries.

Analyst 207
Rows of computer servers and storage units in a dimly-lit server room with a single server in the foreground.

Container Escapes Fuel Supply Chain Attacks on Cloud Infrastructures

Containers can quickly become a gateway to your entire cloud infrastructure if vulnerable to attacks, with hackers exploiting flaws like CVE-2019-5736, CVE-2022-0492, and CVE-2024-21626 to break free from isolated environments and wreak havoc on your host system. There are five key entry points for container attacks, including vulnerabilities, misconfigurations, and supply chain threats.

Analyst 207
Server room with rows of computer servers and cables, laptops in foreground with some monitors displaying code or data.

Malware Worms Red Hat npm Packages, Targets Cloud Credentials

A single compromised Red Hat employee's GitHub account was used to seed dozens of Red Hat npm package releases with a self-propagating credential-stealer, putting cloud credentials at risk. The malicious packages, downloaded around 80,000 times a week, are still considered a live threat.

Analyst 207
Software development workspace with laptop and papers, subtle coding environment in background.

Red Hat npm Packages Compromised in Supply-Chain Attack

A recent supply-chain attack compromised 32 Red Hat npm packages, affecting 117,000 weekly downloads, after attackers backdoored 96 package versions under the @redhat-cloud-services namespace. The breach occurred when a Red Hat employee's GitHub account was compromised, allowing malicious commits to be pushed.

Analyst 207
Modern sports stadium with ticketing booth, broadcast control room, and concourse, set against a blurred city skyline.

World Cup Faces New Cyber Threats in AI-Driven Era

As the World Cup kicks off on June 11, it's not just a sporting spectacle - it's a high-stakes target for cyber threats, with billions of people, devices, and transactions converging online at once. This massive influx creates a perfect storm of vulnerability, exposing ticketing, payments, broadcasts, and infrastructure to unprecedented risk.

Analyst 207
WordPress website backend on a laptop in a cluttered home office setting.

WordPress Sites Targeted in Steam Profile Malware Campaign

A massive malware campaign has infected nearly 2,000 WordPress websites, using a sneaky tactic of hiding command-and-control data within Steam Community profile comments. The attack, first detected in July 2025, has left security experts scrambling to uncover its entry point.

Analyst 207
Gaming setup with computer and monitor on a desk, cityscape blurred in background.

Atlas Menu Hack Exposes 64,000 User Records

A shocking security breach has hit Atlas Menu, a popular cheat service for Grand Theft Auto, with an attacker claiming to have fully compromised the system and leaked 64,000 user records online. The hacker also made the disturbing allegation that Atlas Menu was secretly taking screenshots of users' machines.

Analyst 207
Server room with exposed computer rack and vulnerable equipment.

Flowise Flaw Exposes Servers to Full Attacker Control

A critical security flaw in Flowise, a popular open-source AI workflow platform, allows attackers to seize full control of a server by tricking a logged-in user into importing a malicious file. This vulnerability, disclosed by Obsidian Security, puts self-hosted deployments at risk, with a simple exploit capable of unleashing a devastating attack.

Analyst 207
Developer workstation with laptop, terminal, and smartphone in a brightly-lit home office setting.

OpenAI Codex Tokens Exfiltrated in Malicious npm Supply Chain Attack

For a month, a malicious npm package called codexui-android secretly stole OpenAI Codex authentication tokens from over 29,000 weekly users, sending them to an attacker-controlled server. The package, masquerading as a remote web UI for OpenAI Codex, had gained user trust through active development before being compromised.

Analyst 207
Person typing on laptop with blurred map interface on screen, symbolizing WordPress site security breach.

Hackers Exploit WP Maps Pro Bug to Hijack WordPress Sites

In just 24 hours, over 3,600 hacking attempts were made to exploit a critical flaw in the WP Maps Pro plugin, allowing attackers to create admin accounts and log in without a password. This vulnerability, affecting version 6.1.0 and older, puts countless WordPress sites at risk.

Analyst 207
A Linux workstation with an open terminal window in a modern office setting.

Linux Flaw Exposes Multiple Distributions to Root Privilege Escalation

A single misstep in the Linux CIFS subsystem, dating back nearly two decades, leaves multiple distributions vulnerable to a devastating root privilege escalation attack, dubbed CIFSwitch. This flaw allows attackers to exploit the kernel's keyring mechanism and gain control of modern Linux systems.

Analyst 207
Kazakh military personnel stands proudly in front of modern military vehicle at a base.

Kazakhstan Overhauls Military to Counter Great Power Rivalry

With global stability hanging in the balance, Kazakhstan is rapidly overhauling its military to safeguard its position as a vital link in the global supply chain. President Kassym-Jomart Tokayev has set an ambitious two-year deadline to modernize the country's armed forces and stay ahead of emerging threats.

Analyst 207
Developer workspace with laptop, terminal, and notes, hint of cloud diagram in background.

Malicious npm Packages Target Cloud Credentials

Malicious actors are targeting cloud credentials by publishing fake npm packages that mimic popular projects, allowing them to infiltrate developer environments and gain access to sensitive AWS and Elastic credentials. In just four hours, a single attacker published 14 malicious packages using cleverly disguised names.

Analyst 207
Person sitting at laptop with browser window open showing fake ChatGPT outage message.

Threat Actors Exploit ChatGPT Sharing Feature to Deliver Malware

Malicious actors are exploiting ChatGPT's sharing feature to spread malware, using convincing fake outage messages to trick users into downloading malicious desktop applications. They even hijacked Google ads to make their scam look legit.

Analyst 207
Software development workstation with Docker interface on laptop and monitor, surrounded by tools and notes.

Docker Images Expose Hidden Vulnerabilities

Docker containers are a top target for attackers, with a recent analysis of 100 popular Docker Hub images revealing that 64 contained critical flaws due to outdated software versions. Only one in ten images was fully up to date, leaving a vast majority vulnerable to predictable and dangerous exposures.

Analyst 207
Cluttered computer terminal room with cables and equipment, laptop in center, faint GitHub logo on blurred screen.

AI-Generated Malware Exposes Operator's GitHub Token

A malicious npm package, disguised as a harmless sync utility called "mouse5212-super-formatter", was downloaded 676 times before it was caught stealing sensitive data and exposing its creator's GitHub token. This AI-generated malware cleverly hid its true intentions, uploading stolen files to a fake repository and covering its tracks.

Analyst 207
Rows of partially filled shelves with military equipment and missiles convey a sense of depleted stockpiles.

US Weapons Stockpiles Dwindle After Iran War

The US has burned through a third of its Tomahawk missile stockpile in the recent war with Iran, and at the current production rate of just 86 missiles per year, it'll take over three years to replenish what's been lost. This alarming depletion rate raises serious concerns about the country's military readiness.

Analyst 207
Senior Minister Lee Hsien Loong and Chen Gang inspect a busy logistics hub with cranes and shipping containers.

Singapore Emerges as China's Key Partner in Strategic Trade Corridor

Singapore's senior officials, including Senior Minister Lee Hsien Loong, recently visited Nanning to inspect a game-changing strategic logistics corridor that connects western China to Southeast Asia and beyond. This corridor is already making waves, with 10 million TEUs handled in 2025 and ILSTC shipments surpassing 1.4 million TEUs.

Analyst 207
Developer workstation with laptop, code, and git terminal, surrounded by coffee cup and notes in soft daylight.

Gogs Vulnerability Exposes Remote Code Execution Risk

A newly discovered vulnerability in Gogs puts servers at risk of remote code execution, allowing any authenticated user to inject malicious code through a simple pull request. By crafting a malicious branch name, attackers can exploit the --exec flag in git rebase to run unauthorized shell commands.

Analyst 207