Tag: supply chain
867 articles

Atlas Menu Hack Exposes 64,000 User Records
A shocking security breach has hit Atlas Menu, a popular cheat service for Grand Theft Auto, with an attacker claiming to have fully compromised the system and leaked 64,000 user records online. The hacker also made the disturbing allegation that Atlas Menu was secretly taking screenshots of users' machines.

Flowise Flaw Exposes Servers to Full Attacker Control
A critical security flaw in Flowise, a popular open-source AI workflow platform, allows attackers to seize full control of a server by tricking a logged-in user into importing a malicious file. This vulnerability, disclosed by Obsidian Security, puts self-hosted deployments at risk, with a simple exploit capable of unleashing a devastating attack.

OpenAI Codex Tokens Exfiltrated in Malicious npm Supply Chain Attack
For a month, a malicious npm package called codexui-android secretly stole OpenAI Codex authentication tokens from over 29,000 weekly users, sending them to an attacker-controlled server. The package, masquerading as a remote web UI for OpenAI Codex, had gained user trust through active development before being compromised.

Hackers Exploit WP Maps Pro Bug to Hijack WordPress Sites
In just 24 hours, over 3,600 hacking attempts were made to exploit a critical flaw in the WP Maps Pro plugin, allowing attackers to create admin accounts and log in without a password. This vulnerability, affecting version 6.1.0 and older, puts countless WordPress sites at risk.

Linux Flaw Exposes Multiple Distributions to Root Privilege Escalation
A single misstep in the Linux CIFS subsystem, dating back nearly two decades, leaves multiple distributions vulnerable to a devastating root privilege escalation attack, dubbed CIFSwitch. This flaw allows attackers to exploit the kernel's keyring mechanism and gain control of modern Linux systems.

Kazakhstan Overhauls Military to Counter Great Power Rivalry
With global stability hanging in the balance, Kazakhstan is rapidly overhauling its military to safeguard its position as a vital link in the global supply chain. President Kassym-Jomart Tokayev has set an ambitious two-year deadline to modernize the country's armed forces and stay ahead of emerging threats.

Malicious npm Packages Target Cloud Credentials
Malicious actors are targeting cloud credentials by publishing fake npm packages that mimic popular projects, allowing them to infiltrate developer environments and gain access to sensitive AWS and Elastic credentials. In just four hours, a single attacker published 14 malicious packages using cleverly disguised names.

Threat Actors Exploit ChatGPT Sharing Feature to Deliver Malware
Malicious actors are exploiting ChatGPT's sharing feature to spread malware, using convincing fake outage messages to trick users into downloading malicious desktop applications. They even hijacked Google ads to make their scam look legit.

Docker Images Expose Hidden Vulnerabilities
Docker containers are a top target for attackers, with a recent analysis of 100 popular Docker Hub images revealing that 64 contained critical flaws due to outdated software versions. Only one in ten images was fully up to date, leaving a vast majority vulnerable to predictable and dangerous exposures.

AI-Generated Malware Exposes Operator's GitHub Token
A malicious npm package, disguised as a harmless sync utility called "mouse5212-super-formatter", was downloaded 676 times before it was caught stealing sensitive data and exposing its creator's GitHub token. This AI-generated malware cleverly hid its true intentions, uploading stolen files to a fake repository and covering its tracks.

US Weapons Stockpiles Dwindle After Iran War
The US has burned through a third of its Tomahawk missile stockpile in the recent war with Iran, and at the current production rate of just 86 missiles per year, it'll take over three years to replenish what's been lost. This alarming depletion rate raises serious concerns about the country's military readiness.

Singapore Emerges as China's Key Partner in Strategic Trade Corridor
Singapore's senior officials, including Senior Minister Lee Hsien Loong, recently visited Nanning to inspect a game-changing strategic logistics corridor that connects western China to Southeast Asia and beyond. This corridor is already making waves, with 10 million TEUs handled in 2025 and ILSTC shipments surpassing 1.4 million TEUs.

Gogs Vulnerability Exposes Remote Code Execution Risk
A newly discovered vulnerability in Gogs puts servers at risk of remote code execution, allowing any authenticated user to inject malicious code through a simple pull request. By crafting a malicious branch name, attackers can exploit the --exec flag in git rebase to run unauthorized shell commands.

Cybercriminals, Hacktivists Target 2026 World Cup Infrastructure
The 2026 FIFA World Cup is set to draw massive crowds of up to six million fans across 104 matches in 16 host cities, making its complex infrastructure a prime target for cyber threats. With its far-reaching network of stadium operations, municipal services, and independent suppliers, the tournament's technical architecture is a vulnerable web waiting to be exploited.

Malicious Packages Exploit Realistic Identities
Malicious open source packages are getting smarter, with 91% using realistic identities and naming-variant tactics to blend in with legitimate projects, making them harder to spot. This shift away from simple typosquatting tricks means developers need to be extra vigilant when adding dependencies to their workflows.

AI Agent Executes End-to-End Cyberattack in Under an Hour
In a chilling demonstration of speed and stealth, a sophisticated AI agent executed a devastating cyberattack from start to finish in under an hour, exploiting a vulnerable marimo notebook to gain code execution and ultimately exfiltrating a PostgreSQL database. This alarming intrusion highlights the lightning-fast potential of modern cyber threats.

Carnival Cruise Data Breach Exposes 6 Million Customers
A recent data breach at Carnival Cruise, affecting 6 million customers, highlights the vulnerability of traditional security controls to social engineering tactics, where a single compromised employee device can lead to devastating consequences. This incident serves as a stark reminder of the human factor in cybersecurity, where threat actors exploit trust and impersonation to gain access to sensitive information.

Jinx-0164 Targets Crypto Developers with Custom macOS Malware
Beware of fake meetings on LinkedIn - cyber attackers are using them to trick crypto developers into installing custom macOS malware called Audiofix, which can steal sensitive info like passwords, SSH keys, and cryptocurrency wallet details. This sneaky malware is disguised as an audio fix, but its real goal is to harvest your valuable data.

Malicious npm Package Targets Claude AI User Files via GitHub
Disguising itself as a harmless archive deployment sync tool, the malicious npm package mouse5212-super-formatter secretly synced local workspace files to a remote tracking tree, allowing attackers to target user files on GitHub.

CrowdStrike Disrupts GlassWorm Malware's Global Supply Chain Attack Infrastructure
In a major win for cybersecurity, CrowdStrike teamed up with Google and the Shadowserver Foundation to dismantle the global infrastructure behind the GlassWorm malware attack, crippling its ability to issue commands or deliver new payloads to infected machines. This coordinated operation targeted and neutralized the malware's command-and-control channels, protecting software developers from further exploitation.

CISA Mandates Emergency Patch for Exploited cPanel Plugin Flaw
A critical vulnerability in the LiteSpeed cPanel plugin, known as CVE-2026-48172, is being actively exploited by remote attackers, allowing them to execute arbitrary scripts with root privileges. CISA has issued an emergency patch, giving affected users just four days to update and protect themselves.

Turkey Bolsters Naval Capabilities with 100 Kamikaze USVs
Turkey is taking its naval capabilities to the next level with a bold move to acquire 100 kamikaze unmanned surface vessels (USVs), a game-changing technology that will significantly boost its military prowess. The ambitious project has been divided among three top Turkish defence teams, ensuring a competitive edge and redundancy in production.

House Panel Targets Defense Industrial Base in $1.15T Policy Bill
The House Armed Services Committee's draft defense policy bill aims to bolster the Defense Industrial Base, driven by a stark reality: the US no longer has the capacity to rapidly produce war-fighting capabilities at scale. A $1.15 trillion spending plan is on the table, but a separate $350 billion request remains a crucial wildcard.

Younger Voices Inject Urgency into Australia's National Security Debate
Young professionals are shaking up Australia's national security debate, bringing fresh perspectives to pressing issues like the alarming decline in mining engineering enrolments. At ASPI's 2026 Darwin Dialogue, emerging thinkers tackled the nation's critical minerals ambitions and supply chain challenges head-on.