Tag: supply chain
1280 articles

DoD Refrigerator Outages Spark Hacking Fears
A defense official has warned of possible refrigeration disruptions at some Defense Commissary Agency commissaries, sparking concerns about the security of military food storage systems. Several bases have already reported outages, including Fort Irwin, F.E. Warren Air Force Base, and Naval Station Newport.

Mirage Kitten Unveils Node.js Malware Targeting Aviation, FinTech
Kaspersky's threat research uncovered a sneaky Node.js malware campaign targeting aviation and FinTech organizations in the Middle East and Africa, with victims initially tricked by fake job offers on LinkedIn. The malware, known as NodeRabbit, was delivered through cleverly disguised coding-challenge archives.

Australia's Economy Exposed to Digital System Failures
When Optus went down in 2023, the inconvenience was clear - no coffee, no lunch, no Uber - but what Australians laughed off as a minor annoyance actually exposed a much deeper vulnerability: the alarming dependence of Australia's economy on digital systems. The real issue wasn't just payments, but the entire economic exchange process, from ordering to delivery to settlement.

Cyber Firms' AI Defense Push Sparks Scrutiny Over Commitments
More than 200 companies, including tech giants like Microsoft and Google, have joined forces to supercharge cyber defense capabilities and shield against AI-enabled attacks. They're calling for a united front to share threat intel, track progress, and swiftly contain attacks.

Threat Actors Exploit METR API Key, Drain $600,000 in AI Credits
A staggering $600,000 in AI credits vanished in a flash when an unknown attacker exploited a stolen API key, infiltrating a publicly accessible experiment and racking up a massive bill that was thankfully waived by the model provider. The shocking breach happened after a researcher inadvertently left an EC2 instance exposed, despite having Google authentication in place.

Attackers Exploit Langflow, Rails Flaws for Credential Probing
Attackers are actively exploiting vulnerabilities in Langflow and Rails to launch credential probing attacks, using tactics like querying sensitive environment variables and reading secret keys to harvest valuable info. This alarming mix of reconnaissance and credential harvesting activities highlights the urgent need for robust security measures.

McKesson Probes Data Breach After ShinyHunters Claims 284 Million Records Stolen
McKesson is investigating a data breach after a hacking group claimed to have stolen 284 million records, prompting the healthcare giant to probe unauthorized access to its third-party applications. The breach appears to be limited to a subset of customers within two of its business units.

PaperCut Zero-Days Exploited in Data Theft Attacks
Hackers are actively exploiting two zero-day vulnerabilities in PaperCut NG and MF, using them to bypass authentication and steal sensitive data from vulnerable print management servers. Attackers have already been spotted chaining these flaws to launch data theft attacks, prompting emergency patches from PaperCut Software.

Ukraine's Intel Exposes Zircon Missile's Complex Production Chain
Ukrainian intelligence has uncovered a massive network of 70 enterprises and 84 individuals working together to produce Russia's advanced 3M22 Zircon missile, revealing a complex production chain that's raising new questions about technical and policy implications. The detailed breakdown, courtesy of the Main Directorate of Intelligence, names specific companies and components, shining a light on the intricate web of suppliers behind this cutting-edge weapon.

McKesson Discloses Data Theft After ShinyHunters Extortion Attack
McKesson has confirmed a data theft incident following a cyberattack by ShinyHunters, but has assured customers that its business and distribution centers are up and running with no ongoing unauthorized activity. The company sprang into action, activating incident response protocols and launching an investigation to minimize disruption.

Congress Urged to Act as Munitions Shortage Widens
The Pentagon's alarmingly long procurement lead times have sounded the alarm: 31 months for crucial PAC-3 interceptors, 34 months for THAAD interceptors, and a staggering 40 months for Tomahawk missiles. If Congress delays appropriations, these timelines will stretch even further, leaving our defenses vulnerable for years to come.

Microsoft Warns of TerminalFix Malware Hiding in PNGs
Microsoft researchers have uncovered a sneaky malware campaign, dubbed TerminalFix, that hides in plain sight by masquerading as harmless PNG images - only to delete them after extraction, leaving behind a trail of PowerShell commands that can compromise your system. This fresh variant of the ClickFix social-engineering trick tricks victims into pasting malicious commands into Windows Terminal or PowerShell.

ATF Cyber Breach Exposes Investigative Targets
The ATF's response to the Qilin ransomware gang's claim of a breach reveals how prepared - or unprepared - the agency was to tackle the incident. A cyber breach at the ATF potentially puts sensitive investigative targets at risk, but details on the incident remain scarce.

Hasbro Breach Compromises Employee Data
A single compromised employee account led to a massive data breach at Hasbro, exposing sensitive employee information, including Social Security numbers and financial data. The alarming incident highlights the importance of robust cybersecurity measures to prevent such breaches.

Chinese Hackers Exploit Cisco Routers for Covert Surveillance
Chinese hackers have cleverly exploited Cisco routers, transforming them from mere transit devices to covert surveillance platforms, as discovered by incident responders at Sygnia. This sinister manipulation allows hackers to secretly collect data, with one of the first clues being an unexplained GRE tunnel interface on a Cisco IOS XR router.

PaperCut Vulnerabilities Expose Enterprises to Elevated Threats
PaperCut's recent vulnerabilities, CVE-2026-82078 and CVE-2026-81578, pose a severe threat to enterprises, allowing attackers to gain remote access to sensitive information with ease - and no authentication required. This alarming weakness has security experts warning of elevated risks and potential breaches.

Berlin Hit by Rhysida Ransomware, Data Theft Confirmed
Berlin's administrative network has been hit by a massive Rhysida ransomware attack, with hackers claiming to have stolen a whopping 5.79 TB of sensitive data, including 1.44 million files, and are now threatening to publish it unless paid a ransom. The breach exposes a vast array of confidential records, from government and financial data to personal info like names, email addresses, and phone numbers.

Taiwan Approves $7.57 Billion Drone Funding in Hedgehog Strategy Boost
Taiwan's parliament has greenlit a whopping $7.57 billion drone funding package as part of a broader strategy to bolster its defenses, despite analyst warnings that the compromise could create uncertainty for local manufacturers. The approved budget allocates $40 billion annually for six years, falling short of President Lai Ching-te's request for immediate access to a larger special budget.

Microsoft Teams Targeted in Voice Phishing Campaigns
Beware of voice phishing scams on Microsoft Teams! A recent campaign, dubbed Spring Ring, used fake IT help desk accounts to trick over 150 employees across 10 organizations into granting remote access.

US Agencies Targeted in Chinese Cyber Espionage Operation
The US Department of Justice made a telling edit to their recent press release, quietly changing the wording from "victims" to "among the targets" of a China-linked hacking group that hit several high-profile US agencies. This subtle shift highlights the scope of a brazen cyber espionage operation that compromised sensitive government networks.

FulcrumSec Hack Exposes 86 GB of Manchester Airports Data
Manchester Airports Group swiftly sprang into action after a hack, reassuring customers that they've taken robust measures to safeguard their info and reaching out to those affected, including those with upcoming bookings, to offer extra support. Meanwhile, hackers FulcrumSec claimed responsibility, boasting of swiping 86 GB of sensitive data.

Malicious Chrome Extensions Expose Crypto, Browser Data Theft
Malicious Chrome extensions have been caught stealing cryptocurrency and browser data, with a recent investigation uncovering a sophisticated malware campaign that may have been active since early 2024. The attack used 16 distinct modules to deliver a modular malware framework to unsuspecting Chrome and Edge users.

Microsoft Warns of TerminalFix Backdoor Deploying via Fake Cloudflare CAPTCHAs
Beware of fake Cloudflare CAPTCHAs that can lead to a sneaky backdoor invasion, giving attackers direct access to your organization's internal network. A new variant of malware, called TerminalFix, tricks victims into executing a malicious PowerShell command, allowing hackers to gain control.

Marines Test AI-Powered Logistics Engine in Pacific Theater
The Marines are revolutionizing their logistics game with an AI-powered engine, recently tested in the Pacific Theater, which can analyze over 16 million parts and 4 million vendors to streamline sustainment planning. This cutting-edge tech, developed by defense company Tagup, is already being used by select Marine units to optimize logistics and drive efficiency.