Tag: supply chain
854 articles

VS Code Zero-Day Vulnerability Exposes GitHub Tokens to Theft
A security researcher just revealed a shocking VS Code zero-day vulnerability that lets attackers swipe your GitHub authentication tokens with just one click, exposing your online projects to potential theft. This exploit cleverly abuses VS Code's system to run malicious code and extract sensitive tokens.

Anthropic Expands Vulnerability Detection Program to Critical Infrastructure Firms
Anthropic's expanded Vulnerability Detection Program is helping protect critical infrastructure firms from cyber threats, having already uncovered over 10,000 high-risk software vulnerabilities since April. The program, known as Project Glasswing, now includes 150 organizations across 15 countries.

Red Hat npm Scope Hijacked to Spread Cloud Credential Malware
In a shocking 72 seconds, an attacker hijacked Red Hat's npm scope to spread malware, publishing 32 malicious packages that racked up nearly 10 million downloads. The sneaky move exploited the trust developers have in Red Hat's official namespace, turning it into a conduit for cloud credential malware.

Cybersecurity Threats Target Election Campaign Systems
As the 2026 midterms approach, a new report warns that cybersecurity threats are increasingly targeting the online accounts, platforms, and websites used by election campaigns, donors, and voters, rather than voting machines or ballot-counting systems. This shift in focus allows attackers to exploit vulnerabilities and manipulate public perception with alarming ease and realism.

Navy Accelerates Munitions Innovation with Maryland Hub
The Navy is revolutionizing munitions innovation with the launch of the Maryland Energetics Innovation Hub, a cutting-edge lab and pilot-scale campus in southern Maryland where government and industry experts will collaborate to drive breakthroughs. This game-changing initiative is set to propel the Naval Surface Warfare Center Indian Head Division to the forefront of energetics innovation and production.

Russia Deploys Dazzle Camouflage On Trucks To Evade AI-Enabled Drones
Russia is countering AI-powered threats with a blast from the past - "dazzle" camouflage on its trucks, featuring eye-catching zebra stripes and swirling patterns that throw off image-matching seekers used by drones and cruise missiles. By disrupting computer vision models, this unorthodox tactic aims to keep Russian vehicles one step ahead of high-tech adversaries.

Container Escapes Fuel Supply Chain Attacks on Cloud Infrastructures
Containers can quickly become a gateway to your entire cloud infrastructure if vulnerable to attacks, with hackers exploiting flaws like CVE-2019-5736, CVE-2022-0492, and CVE-2024-21626 to break free from isolated environments and wreak havoc on your host system. There are five key entry points for container attacks, including vulnerabilities, misconfigurations, and supply chain threats.

Malware Worms Red Hat npm Packages, Targets Cloud Credentials
A single compromised Red Hat employee's GitHub account was used to seed dozens of Red Hat npm package releases with a self-propagating credential-stealer, putting cloud credentials at risk. The malicious packages, downloaded around 80,000 times a week, are still considered a live threat.

Red Hat npm Packages Compromised in Supply-Chain Attack
A recent supply-chain attack compromised 32 Red Hat npm packages, affecting 117,000 weekly downloads, after attackers backdoored 96 package versions under the @redhat-cloud-services namespace. The breach occurred when a Red Hat employee's GitHub account was compromised, allowing malicious commits to be pushed.

World Cup Faces New Cyber Threats in AI-Driven Era
As the World Cup kicks off on June 11, it's not just a sporting spectacle - it's a high-stakes target for cyber threats, with billions of people, devices, and transactions converging online at once. This massive influx creates a perfect storm of vulnerability, exposing ticketing, payments, broadcasts, and infrastructure to unprecedented risk.

WordPress Sites Targeted in Steam Profile Malware Campaign
A massive malware campaign has infected nearly 2,000 WordPress websites, using a sneaky tactic of hiding command-and-control data within Steam Community profile comments. The attack, first detected in July 2025, has left security experts scrambling to uncover its entry point.

Atlas Menu Hack Exposes 64,000 User Records
A shocking security breach has hit Atlas Menu, a popular cheat service for Grand Theft Auto, with an attacker claiming to have fully compromised the system and leaked 64,000 user records online. The hacker also made the disturbing allegation that Atlas Menu was secretly taking screenshots of users' machines.

Flowise Flaw Exposes Servers to Full Attacker Control
A critical security flaw in Flowise, a popular open-source AI workflow platform, allows attackers to seize full control of a server by tricking a logged-in user into importing a malicious file. This vulnerability, disclosed by Obsidian Security, puts self-hosted deployments at risk, with a simple exploit capable of unleashing a devastating attack.

OpenAI Codex Tokens Exfiltrated in Malicious npm Supply Chain Attack
For a month, a malicious npm package called codexui-android secretly stole OpenAI Codex authentication tokens from over 29,000 weekly users, sending them to an attacker-controlled server. The package, masquerading as a remote web UI for OpenAI Codex, had gained user trust through active development before being compromised.

Hackers Exploit WP Maps Pro Bug to Hijack WordPress Sites
In just 24 hours, over 3,600 hacking attempts were made to exploit a critical flaw in the WP Maps Pro plugin, allowing attackers to create admin accounts and log in without a password. This vulnerability, affecting version 6.1.0 and older, puts countless WordPress sites at risk.

Linux Flaw Exposes Multiple Distributions to Root Privilege Escalation
A single misstep in the Linux CIFS subsystem, dating back nearly two decades, leaves multiple distributions vulnerable to a devastating root privilege escalation attack, dubbed CIFSwitch. This flaw allows attackers to exploit the kernel's keyring mechanism and gain control of modern Linux systems.

Kazakhstan Overhauls Military to Counter Great Power Rivalry
With global stability hanging in the balance, Kazakhstan is rapidly overhauling its military to safeguard its position as a vital link in the global supply chain. President Kassym-Jomart Tokayev has set an ambitious two-year deadline to modernize the country's armed forces and stay ahead of emerging threats.

Malicious npm Packages Target Cloud Credentials
Malicious actors are targeting cloud credentials by publishing fake npm packages that mimic popular projects, allowing them to infiltrate developer environments and gain access to sensitive AWS and Elastic credentials. In just four hours, a single attacker published 14 malicious packages using cleverly disguised names.

Threat Actors Exploit ChatGPT Sharing Feature to Deliver Malware
Malicious actors are exploiting ChatGPT's sharing feature to spread malware, using convincing fake outage messages to trick users into downloading malicious desktop applications. They even hijacked Google ads to make their scam look legit.

Docker Images Expose Hidden Vulnerabilities
Docker containers are a top target for attackers, with a recent analysis of 100 popular Docker Hub images revealing that 64 contained critical flaws due to outdated software versions. Only one in ten images was fully up to date, leaving a vast majority vulnerable to predictable and dangerous exposures.

AI-Generated Malware Exposes Operator's GitHub Token
A malicious npm package, disguised as a harmless sync utility called "mouse5212-super-formatter", was downloaded 676 times before it was caught stealing sensitive data and exposing its creator's GitHub token. This AI-generated malware cleverly hid its true intentions, uploading stolen files to a fake repository and covering its tracks.

US Weapons Stockpiles Dwindle After Iran War
The US has burned through a third of its Tomahawk missile stockpile in the recent war with Iran, and at the current production rate of just 86 missiles per year, it'll take over three years to replenish what's been lost. This alarming depletion rate raises serious concerns about the country's military readiness.

Singapore Emerges as China's Key Partner in Strategic Trade Corridor
Singapore's senior officials, including Senior Minister Lee Hsien Loong, recently visited Nanning to inspect a game-changing strategic logistics corridor that connects western China to Southeast Asia and beyond. This corridor is already making waves, with 10 million TEUs handled in 2025 and ILSTC shipments surpassing 1.4 million TEUs.

Gogs Vulnerability Exposes Remote Code Execution Risk
A newly discovered vulnerability in Gogs puts servers at risk of remote code execution, allowing any authenticated user to inject malicious code through a simple pull request. By crafting a malicious branch name, attackers can exploit the --exec flag in git rebase to run unauthorized shell commands.