Tag: supply chain
867 articles

Global Drone Production Entangled in Chinese Supply Chain
The Russia-Ukraine War has sparked a staggering demand for FPV drones, with both sides burning through a combined seven million units per year - and Ukraine alone using a remarkable 9,000 of these low-cost, high-impact systems every day.

MyPillow Targeted in Play Ransomware Attack
MyPillow has been hit by a ransomware attack, with hackers claiming to have stolen highly sensitive data including private documents, financial information, and employee details. The attackers are demanding a ransom and threatening to publish the stolen data unless paid.

MFA Prompt Bombing Exposes Weakness in Two-Factor Security
A shocking 2.8GB of data was stolen from Cisco after a clever attacker tricked an employee into approving a push-based MFA prompt, highlighting a disturbing vulnerability in two-factor security. This brazen hack, linked to the Yanluowang ransomware group, shows how attackers can exploit the very security measures meant to protect us.

7-Eleven Data Breach Compromises 185,000 People's Personal Info
A recent 7-Eleven data breach has put the personal info of 185,000 people at risk, exposing sensitive details like names, addresses, birthdays, and phone numbers. The breach, which occurred on April 8, 2026, is still shrouded in mystery, with 7-Eleven only confirming that certain systems storing franchisee documents were compromised.

Dutch Authorities Disrupt Russian Cyber Operations, Seize 800 Servers
In a major blow to Russian cybercrime, Dutch authorities seized over 800 servers and arrested two individuals in a daring raid that cracked down on illicit online operations. The suspects, a 57-year-old Amsterdam resident and a 39-year-old from The Hague, were charged with violating sanctions law by aiding EU-sanctioned entities.

Linux Flaws Expose Critical Infrastructure to Root Command Execution
GitHub confirmed that a compromised employee device, infected by a poisoned Nx Console VS Code extension, led to the theft of around 3,800 internal repositories, sparking swift action to contain the breach and protect sensitive data. The incident highlights the vulnerability of even the most secure systems to supply chain attacks.

TrapDoor Attack Spreads Credential-Stealing Malware Across Software Ecosystems
A massive supply chain attack, dubbed TrapDoor, has been spreading credential-stealing malware across three major language ecosystems, infecting over 34 malicious packages and 384 versions. The coordinated campaign began on May 22, 2026, and continues to target developers with cleverly named packages related to cryptocurrency, DeFi, Solana, and AI.

US Military Grapples with Pacific Theater's Logistics Challenge
The harsh reality of the Pacific Theater's logistics challenge was summed up by Gen. Xavier Brunson: if our supply lines stretch 5,000 miles, we can't win. The daunting distances are stark: Hawaii is 3,000 miles from the US West Coast, and the critical first island chain is 1,500 miles from Guam, leaving a vast, sparsely supported ocean.

GitHub Tags Exploited to Deploy Credential-Stealing Malware
Malicious actors have manipulated hundreds of GitHub tags to spread credential-stealing malware through popular Laravel Lang localization packages, putting countless users at risk. By rewriting historical tags, attackers tricked Composer installations into downloading the malicious payload.

GitHub Enhances npm with 2FA-Gated Publishing to Thwart Supply Chain Attacks
GitHub's new staged publishing feature on npm adds an extra layer of security, requiring maintainers to approve package releases after completing a two-factor authentication challenge, effectively preventing unauthorized publishes and reducing the risk of supply chain attacks. This human gate ensures proof of presence for every package release, safeguarding the integrity of the npm ecosystem.

Malicious Laravel-Lang Packages Deliver Cross-Platform Credential Stealer
A massive wave of malicious Laravel-Lang packages, with over 700 versions released in just two days, has been used to spread a sneaky cross-platform credential stealer. Security researchers warn that multiple PHP packages from the Laravel-Lang organization were compromised, hinting at a large-scale breach of the organization's release process.

Lockheed Expands Munitions Production with New Alabama Facility
Lockheed Martin is betting big on future demand, investing in a new 87,000-square-foot production facility in Troy, Alabama, that nearly doubles its current production space for THAAD interceptors. The move is a bold bet that production certainty will follow capital outlays, paving the way for a significant ramp-up in THAAD output.

Iran Seeks Fees to Control Strait of Hormuz
Iran is in talks with Oman to introduce a fee system for vessels navigating the Strait of Hormuz, but insists it's not about imposing a traditional toll - instead, ships would pay for specific services like waste disposal. This approach would allow Iran to generate revenue while staying within international law.

GitHub Repos Targeted in 5,500+ Malicious Commits
A shocking new campaign, dubbed Megalodon, has injected malware into over 5,500 GitHub repositories, putting sensitive credentials and tokens at risk of being stolen. This alarming attack highlights the growing threat of supply chain attacks, with experts warning that this could be just the beginning.

Netherlands Disrupts Russian Cyber Operations with Server Seizure
Dutch authorities have struck a major blow against Russian cyber operations, seizing 800 servers and making several arrests in a crackdown on a web hosting ecosystem accused of enabling cyberattacks, disinformation campaigns, and other malicious activities. This coordinated law-enforcement action aims to disrupt the cyber threat landscape and protect democracy and security.

Ghostwriter Exploits Ukraine Government with Prometheus Phishing Malware
Malicious actors known as Ghostwriter have launched a cunning phishing campaign targeting Ukraine's government, using emails that appear to come from trusted sources and contain links to a seemingly harmless learning platform, Prometheus. These emails contain a hidden threat that can download malware onto victims' devices.

Europe Must Build Resilience with Physical Infrastructure
As the EU shifts its focus from efficiency to resilience, it's redefining sovereignty through deliberate, long-term investments in physical infrastructure, ensuring that critical capabilities can thrive even in turbulent times. By prioritizing resilience and strategic autonomy, Europe is building a robust foundation for a sustainable future.

GitHub Megalodon Attack Targets Repos with Malicious CI/CD Workflows
In a shocking six-hour blitz on May 18, 2026, attackers unleashed a massive supply-chain campaign dubbed "Megalodon," pushing 5,718 malicious commits to 5,561 GitHub repositories. The sneaky assault mimicked routine CI maintenance, using fake author names and convincing commit messages to deceive victims.

France Tightens Grip on Rafale Tech, Hindering India's Defense Plans
India is on the brink of walking away from a $43 billion Rafale deal with France after Paris reportedly refused to share crucial technical details, sparking concerns over control and security. The standoff threatens to derail New Delhi's plans to acquire 114 multirole fighters and 26 naval jets.

Google Exposes Unfixed Chromium Flaw Details
A security researcher just blew the whistle on a glaring Chromium flaw that Google thought was fixed - but still works, putting tens of thousands of users at risk of a botnet attack. The exploit, first reported in 2022, allows malicious websites to remotely execute JavaScript on unsuspecting devices.

GitHub Breach Exposes 3800 Repositories via Poisoned VS Code Extension
A malicious Visual Studio Code extension, Nx Console, was briefly listed on official registries and used to breach GitHub, exposing approximately 3,800 internal repositories to unauthorized access. The popular extension, with 2.2 million installs, was compromised for just 18 minutes, but long enough to cause significant damage.

Vulnerable Code Proliferates as AI Exploits Rise in Supply Chains
The alarming truth is that 75% of organizations are knowingly shipping vulnerable code, despite the risks, with the window from disclosure to exploit shrinking dramatically from 840 days in 2018 to just under two days today. This trend is expected to accelerate, with exploits potentially available in as little as one minute by 2028.

Cisco Exposes New Zero-Auth Vulnerability in Secure Workload Platform
Cisco has uncovered a critical zero-auth vulnerability in its Secure Workload platform, allowing attackers to access sensitive information and make configuration changes with alarming ease and admin-level privileges. This severe flaw, scoring a perfect 10.0 on the CVSS scale, demands immediate attention to prevent exploitation.

Grafana Breach Exposed by TanStack Supply Chain Attack
Grafana Labs revealed that a supply chain attack led to an unauthorized download of its codebase, exposing a vulnerability that allowed attackers to gain access to its GitHub repositories through a missed workflow token. The breach was detected on May 11, with the company swiftly rotating tokens, but unfortunately, one was overlooked.