Skip to main content

Tag: supply chain

867 articles

Workers assemble compact drones on a brightly-lit manufacturing floor with components stacked in the background.

Global Drone Production Entangled in Chinese Supply Chain

The Russia-Ukraine War has sparked a staggering demand for FPV drones, with both sides burning through a combined seven million units per year - and Ukraine alone using a remarkable 9,000 of these low-cost, high-impact systems every day.

Analyst 207
Sensitive documents labeled Confidential and Financial scattered on a table in a brightly-lit office setting.

MyPillow Targeted in Play Ransomware Attack

MyPillow has been hit by a ransomware attack, with hackers claiming to have stolen highly sensitive data including private documents, financial information, and employee details. The attackers are demanding a ransom and threatening to publish the stolen data unless paid.

Analyst 207
Person sitting at desk, confused, looking at smartphone with multiple push notifications.

MFA Prompt Bombing Exposes Weakness in Two-Factor Security

A shocking 2.8GB of data was stolen from Cisco after a clever attacker tricked an employee into approving a push-based MFA prompt, highlighting a disturbing vulnerability in two-factor security. This brazen hack, linked to the Yanluowang ransomware group, shows how attackers can exploit the very security measures meant to protect us.

Analyst 207
7-Eleven store interior with disorganized papers near employee.

7-Eleven Data Breach Compromises 185,000 People's Personal Info

A recent 7-Eleven data breach has put the personal info of 185,000 people at risk, exposing sensitive details like names, addresses, birthdays, and phone numbers. The breach, which occurred on April 8, 2026, is still shrouded in mystery, with 7-Eleven only confirming that certain systems storing franchisee documents were compromised.

Analyst 207
Law enforcement officers seize servers and equipment in a brightly-lit data center.

Dutch Authorities Disrupt Russian Cyber Operations, Seize 800 Servers

In a major blow to Russian cybercrime, Dutch authorities seized over 800 servers and arrested two individuals in a daring raid that cracked down on illicit online operations. The suspects, a 57-year-old Amsterdam resident and a 39-year-old from The Hague, were charged with violating sanctions law by aiding EU-sanctioned entities.

Analyst 207
Cluttered developer workstation with laptop, monitor, and notes, VS Code on screen.

Linux Flaws Expose Critical Infrastructure to Root Command Execution

GitHub confirmed that a compromised employee device, infected by a poisoned Nx Console VS Code extension, led to the theft of around 3,800 internal repositories, sparking swift action to contain the breach and protect sensitive data. The incident highlights the vulnerability of even the most secure systems to supply chain attacks.

Analyst 207
Developer workstation with laptop and monitor displaying code, surrounded by notes and empty coffee cups, in a modern…

TrapDoor Attack Spreads Credential-Stealing Malware Across Software Ecosystems

A massive supply chain attack, dubbed TrapDoor, has been spreading credential-stealing malware across three major language ecosystems, infecting over 34 malicious packages and 384 versions. The coordinated campaign began on May 22, 2026, and continues to target developers with cleverly named packages related to cryptocurrency, DeFi, Solana, and AI.

Analyst 207
Military logistics hub on a dock with shipping containers, equipment, and officers near a briefing table with a map.

US Military Grapples with Pacific Theater's Logistics Challenge

The harsh reality of the Pacific Theater's logistics challenge was summed up by Gen. Xavier Brunson: if our supply lines stretch 5,000 miles, we can't win. The daunting distances are stark: Hawaii is 3,000 miles from the US West Coast, and the critical first island chain is 1,500 miles from Guam, leaving a vast, sparsely supported ocean.

Analyst 207
Software development workspace with laptop and monitor displaying Git repository interface.

GitHub Tags Exploited to Deploy Credential-Stealing Malware

Malicious actors have manipulated hundreds of GitHub tags to spread credential-stealing malware through popular Laravel Lang localization packages, putting countless users at risk. By rewriting historical tags, attackers tricked Composer installations into downloading the malicious payload.

Analyst 207
Developer interacts with laptop in bright office, emphasizing secure package management.

GitHub Enhances npm with 2FA-Gated Publishing to Thwart Supply Chain Attacks

GitHub's new staged publishing feature on npm adds an extra layer of security, requiring maintainers to approve package releases after completing a two-factor authentication challenge, effectively preventing unauthorized publishes and reducing the risk of supply chain attacks. This human gate ensures proof of presence for every package release, safeguarding the integrity of the npm ecosystem.

Analyst 207
Cluttered desk with laptop showing PHP project, surrounded by coffee cups and coding notes in a modern office.

Malicious Laravel-Lang Packages Deliver Cross-Platform Credential Stealer

A massive wave of malicious Laravel-Lang packages, with over 700 versions released in just two days, has been used to spread a sneaky cross-platform credential stealer. Security researchers warn that multiple PHP packages from the Laravel-Lang organization were compromised, hinting at a large-scale breach of the organization's release process.

Analyst 207
Groundbreaking ceremony for new industrial facility with construction equipment in background.

Lockheed Expands Munitions Production with New Alabama Facility

Lockheed Martin is betting big on future demand, investing in a new 87,000-square-foot production facility in Troy, Alabama, that nearly doubles its current production space for THAAD interceptors. The move is a bold bet that production certainty will follow capital outlays, paving the way for a significant ramp-up in THAAD output.

Analyst 207
Ship navigates through Strait of Hormuz with a port in the background and a small boat in the foreground.

Iran Seeks Fees to Control Strait of Hormuz

Iran is in talks with Oman to introduce a fee system for vessels navigating the Strait of Hormuz, but insists it's not about imposing a traditional toll - instead, ships would pay for specific services like waste disposal. This approach would allow Iran to generate revenue while staying within international law.

Analyst 207
Laptop screen showing GitHub repository page with cityscape background and subtle CI/CD hints.

GitHub Repos Targeted in 5,500+ Malicious Commits

A shocking new campaign, dubbed Megalodon, has injected malware into over 5,500 GitHub repositories, putting sensitive credentials and tokens at risk of being stolen. This alarming attack highlights the growing threat of supply chain attacks, with experts warning that this could be just the beginning.

Analyst 207
Law enforcement officers oversee rows of partially disassembled servers in a brightly-lit data center.

Netherlands Disrupts Russian Cyber Operations with Server Seizure

Dutch authorities have struck a major blow against Russian cyber operations, seizing 800 servers and making several arrests in a crackdown on a web hosting ecosystem accused of enabling cyberattacks, disinformation campaigns, and other malicious activities. This coordinated law-enforcement action aims to disrupt the cyber threat landscape and protect democracy and security.

Analyst 207
Government office workstation with papers and supplies, email inbox blurred on screen.

Ghostwriter Exploits Ukraine Government with Prometheus Phishing Malware

Malicious actors known as Ghostwriter have launched a cunning phishing campaign targeting Ukraine's government, using emails that appear to come from trusted sources and contain links to a seemingly harmless learning platform, Prometheus. These emails contain a hidden threat that can download malware onto victims' devices.

Analyst 207
Modern bridge or transportation hub set against a clear blue sky with puffy clouds, surrounded by trees and buildings.

Europe Must Build Resilience with Physical Infrastructure

As the EU shifts its focus from efficiency to resilience, it's redefining sovereignty through deliberate, long-term investments in physical infrastructure, ensuring that critical capabilities can thrive even in turbulent times. By prioritizing resilience and strategic autonomy, Europe is building a robust foundation for a sustainable future.

Analyst 207
Dimly lit workspace with scattered screens and keyboards, featuring empty and blurred computer terminals.

GitHub Megalodon Attack Targets Repos with Malicious CI/CD Workflows

In a shocking six-hour blitz on May 18, 2026, attackers unleashed a massive supply-chain campaign dubbed "Megalodon," pushing 5,718 malicious commits to 5,561 GitHub repositories. The sneaky assault mimicked routine CI maintenance, using fake author names and convincing commit messages to deceive victims.

Analyst 207
Technician in flight suit stands beside Rafale aircraft with blended French and Indian flags in background.

France Tightens Grip on Rafale Tech, Hindering India's Defense Plans

India is on the brink of walking away from a $43 billion Rafale deal with France after Paris reportedly refused to share crucial technical details, sparking concerns over control and security. The standoff threatens to derail New Delhi's plans to acquire 114 multirole fighters and 26 naval jets.

Analyst 207
Security researcher with concerned expression working at workstation with laptop and multiple screens displaying code.

Google Exposes Unfixed Chromium Flaw Details

A security researcher just blew the whistle on a glaring Chromium flaw that Google thought was fixed - but still works, putting tens of thousands of users at risk of a botnet attack. The exploit, first reported in 2022, allows malicious websites to remotely execute JavaScript on unsuspecting devices.

Analyst 207
Developer workstation with VS Code on laptop and monitor, subtle security threat hinted in background.

GitHub Breach Exposes 3800 Repositories via Poisoned VS Code Extension

A malicious Visual Studio Code extension, Nx Console, was briefly listed on official registries and used to breach GitHub, exposing approximately 3,800 internal repositories to unauthorized access. The popular extension, with 2.2 million installs, was compromised for just 18 minutes, but long enough to cause significant damage.

Analyst 207
Cluttered coding workspace with laptop, notes, and city view.

Vulnerable Code Proliferates as AI Exploits Rise in Supply Chains

The alarming truth is that 75% of organizations are knowingly shipping vulnerable code, despite the risks, with the window from disclosure to exploit shrinking dramatically from 840 days in 2018 to just under two days today. This trend is expected to accelerate, with exploits potentially available in as little as one minute by 2028.

Analyst 207
Server rack in a data center with exposed vulnerabilities under ambient light.

Cisco Exposes New Zero-Auth Vulnerability in Secure Workload Platform

Cisco has uncovered a critical zero-auth vulnerability in its Secure Workload platform, allowing attackers to access sensitive information and make configuration changes with alarming ease and admin-level privileges. This severe flaw, scoring a perfect 10.0 on the CVSS scale, demands immediate attention to prevent exploitation.

Analyst 207
Blurred computer screen surrounded by development materials in a bright, neutral workspace.

Grafana Breach Exposed by TanStack Supply Chain Attack

Grafana Labs revealed that a supply chain attack led to an unauthorized download of its codebase, exposing a vulnerability that allowed attackers to gain access to its GitHub repositories through a missed workflow token. The breach was detected on May 11, with the company swiftly rotating tokens, but unfortunately, one was overlooked.

Analyst 207