Skip to main content

Tag: supply chain

1280 articles

Refrigerated case with doors ajar, shelves stocked with food and drinks, digital display blank or out of focus.

DoD Refrigerator Outages Spark Hacking Fears

A defense official has warned of possible refrigeration disruptions at some Defense Commissary Agency commissaries, sparking concerns about the security of military food storage systems. Several bases have already reported outages, including Fort Irwin, F.E. Warren Air Force Base, and Naval Station Newport.

Analyst 207
Blurred laptop on airport security counter amidst muted colors.

Mirage Kitten Unveils Node.js Malware Targeting Aviation, FinTech

Kaspersky's threat research uncovered a sneaky Node.js malware campaign targeting aviation and FinTech organizations in the Middle East and Africa, with victims initially tricked by fake job offers on LinkedIn. The malware, known as NodeRabbit, was delivered through cleverly disguised coding-challenge archives.

Analyst 207
Quiet Australian supermarket checkout lane with concerned cashier and customer in background holding mobile phone.

Australia's Economy Exposed to Digital System Failures

When Optus went down in 2023, the inconvenience was clear - no coffee, no lunch, no Uber - but what Australians laughed off as a minor annoyance actually exposed a much deeper vulnerability: the alarming dependence of Australia's economy on digital systems. The real issue wasn't just payments, but the entire economic exchange process, from ordering to delivery to settlement.

Analyst 207
Diverse group of people gathered around a large whiteboard in a modern conference room.

Cyber Firms' AI Defense Push Sparks Scrutiny Over Commitments

More than 200 companies, including tech giants like Microsoft and Google, have joined forces to supercharge cyber defense capabilities and shield against AI-enabled attacks. They're calling for a united front to share threat intel, track progress, and swiftly contain attacks.

Analyst 207
Empty tech company data center with servers and workstation in foreground.

Threat Actors Exploit METR API Key, Drain $600,000 in AI Credits

A staggering $600,000 in AI credits vanished in a flash when an unknown attacker exploited a stolen API key, infiltrating a publicly accessible experiment and racking up a massive bill that was thankfully waived by the model provider. The shocking breach happened after a researcher inadvertently left an EC2 instance exposed, despite having Google authentication in place.

Analyst 207
Rows of rack-mounted servers and cables in a brightly-lit data center facility.

Attackers Exploit Langflow, Rails Flaws for Credential Probing

Attackers are actively exploiting vulnerabilities in Langflow and Rails to launch credential probing attacks, using tactics like querying sensitive environment variables and reading secret keys to harvest valuable info. This alarming mix of reconnaissance and credential harvesting activities highlights the urgent need for robust security measures.

Analyst 207
Dimly lit hospital corridor with blurred laptop on a surface amidst medical carts and shelves.

McKesson Probes Data Breach After ShinyHunters Claims 284 Million Records Stolen

McKesson is investigating a data breach after a hacking group claimed to have stolen 284 million records, prompting the healthcare giant to probe unauthorized access to its third-party applications. The breach appears to be limited to a subset of customers within two of its business units.

Analyst 207
Rows of computer servers and network equipment in a brightly-lit office server room.

PaperCut Zero-Days Exploited in Data Theft Attacks

Hackers are actively exploiting two zero-day vulnerabilities in PaperCut NG and MF, using them to bypass authentication and steal sensitive data from vulnerable print management servers. Attackers have already been spotted chaining these flaws to launch data theft attacks, prompting emergency patches from PaperCut Software.

Analyst 207
Dimly lit workshop with machinery, tools, and missile components surrounded by technical drawings.

Ukraine's Intel Exposes Zircon Missile's Complex Production Chain

Ukrainian intelligence has uncovered a massive network of 70 enterprises and 84 individuals working together to produce Russia's advanced 3M22 Zircon missile, revealing a complex production chain that's raising new questions about technical and policy implications. The detailed breakdown, courtesy of the Main Directorate of Intelligence, names specific companies and components, shining a light on the intricate web of suppliers behind this cutting-edge weapon.

Analyst 207
Rows of shelved medical supplies in a distribution center with employees checking a laptop.

McKesson Discloses Data Theft After ShinyHunters Extortion Attack

McKesson has confirmed a data theft incident following a cyberattack by ShinyHunters, but has assured customers that its business and distribution centers are up and running with no ongoing unauthorized activity. The company sprang into action, activating incident response protocols and launching an investigation to minimize disruption.

Analyst 207
Rows of shelves in a military storage facility hold crates and containers, with some empty spaces visible.

Congress Urged to Act as Munitions Shortage Widens

The Pentagon's alarmingly long procurement lead times have sounded the alarm: 31 months for crucial PAC-3 interceptors, 34 months for THAAD interceptors, and a staggering 40 months for Tomahawk missiles. If Congress delays appropriations, these timelines will stretch even further, leaving our defenses vulnerable for years to come.

Analyst 207
Windows Terminal or PowerShell window on a laptop screen with office background.

Microsoft Warns of TerminalFix Malware Hiding in PNGs

Microsoft researchers have uncovered a sneaky malware campaign, dubbed TerminalFix, that hides in plain sight by masquerading as harmless PNG images - only to delete them after extraction, leaving behind a trail of PowerShell commands that can compromise your system. This fresh variant of the ClickFix social-engineering trick tricks victims into pasting malicious commands into Windows Terminal or PowerShell.

Analyst 207
Federal law enforcement facility interior shows signs of concern and disruption.

ATF Cyber Breach Exposes Investigative Targets

The ATF's response to the Qilin ransomware gang's claim of a breach reveals how prepared - or unprepared - the agency was to tackle the incident. A cyber breach at the ATF potentially puts sensitive investigative targets at risk, but details on the incident remain scarce.

Analyst 207
Empty office cubicle with computer and papers, suggesting recent use.

Hasbro Breach Compromises Employee Data

A single compromised employee account led to a massive data breach at Hasbro, exposing sensitive employee information, including Social Security numbers and financial data. The alarming incident highlights the importance of robust cybersecurity measures to prevent such breaches.

Analyst 207
Network devices and cables in a data center with a Cisco router and a single cable leading to a patch panel.

Chinese Hackers Exploit Cisco Routers for Covert Surveillance

Chinese hackers have cleverly exploited Cisco routers, transforming them from mere transit devices to covert surveillance platforms, as discovered by incident responders at Sygnia. This sinister manipulation allows hackers to secretly collect data, with one of the first clues being an unexplained GRE tunnel interface on a Cisco IOS XR router.

Analyst 207
Multifunction printer on office shelf, surrounded by computers and chairs.

PaperCut Vulnerabilities Expose Enterprises to Elevated Threats

PaperCut's recent vulnerabilities, CVE-2026-82078 and CVE-2026-81578, pose a severe threat to enterprises, allowing attackers to gain remote access to sensitive information with ease - and no authentication required. This alarming weakness has security experts warning of elevated risks and potential breaches.

Analyst 207
Municipal office interior with rows of desks, computers, and scattered papers.

Berlin Hit by Rhysida Ransomware, Data Theft Confirmed

Berlin's administrative network has been hit by a massive Rhysida ransomware attack, with hackers claiming to have stolen a whopping 5.79 TB of sensitive data, including 1.44 million files, and are now threatening to publish it unless paid a ransom. The breach exposes a vast array of confidential records, from government and financial data to personal info like names, email addresses, and phone numbers.

Analyst 207
Taiwanese government building with subtle drone technology hints in foreground.

Taiwan Approves $7.57 Billion Drone Funding in Hedgehog Strategy Boost

Taiwan's parliament has greenlit a whopping $7.57 billion drone funding package as part of a broader strategy to bolster its defenses, despite analyst warnings that the compromise could create uncertainty for local manufacturers. The approved budget allocates $40 billion annually for six years, falling short of President Lai Ching-te's request for immediate access to a larger special budget.

Analyst 207
Person sits at cluttered desk, looking concerned while on video conference on computer with Microsoft Teams on screen.

Microsoft Teams Targeted in Voice Phishing Campaigns

Beware of voice phishing scams on Microsoft Teams! A recent campaign, dubbed Spring Ring, used fake IT help desk accounts to trick over 150 employees across 10 organizations into granting remote access.

Analyst 207
US government agency headquarters building exterior in daytime.

US Agencies Targeted in Chinese Cyber Espionage Operation

The US Department of Justice made a telling edit to their recent press release, quietly changing the wording from "victims" to "among the targets" of a China-linked hacking group that hit several high-profile US agencies. This subtle shift highlights the scope of a brazen cyber espionage operation that compromised sensitive government networks.

Analyst 207
Airport terminal interior with passengers and blurred check-in counter.

FulcrumSec Hack Exposes 86 GB of Manchester Airports Data

Manchester Airports Group swiftly sprang into action after a hack, reassuring customers that they've taken robust measures to safeguard their info and reaching out to those affected, including those with upcoming bookings, to offer extra support. Meanwhile, hackers FulcrumSec claimed responsibility, boasting of swiping 86 GB of sensitive data.

Analyst 207
Laptop on a table displays a blurred Chrome Web Store page surrounded by out-of-focus software boxes.

Malicious Chrome Extensions Expose Crypto, Browser Data Theft

Malicious Chrome extensions have been caught stealing cryptocurrency and browser data, with a recent investigation uncovering a sophisticated malware campaign that may have been active since early 2024. The attack used 16 distinct modules to deliver a modular malware framework to unsuspecting Chrome and Edge users.

Analyst 207
Person sits at desk with laptop displaying blurred CAPTCHA prompt on screen.

Microsoft Warns of TerminalFix Backdoor Deploying via Fake Cloudflare CAPTCHAs

Beware of fake Cloudflare CAPTCHAs that can lead to a sneaky backdoor invasion, giving attackers direct access to your organization's internal network. A new variant of malware, called TerminalFix, tricks victims into executing a malicious PowerShell command, allowing hackers to gain control.

Analyst 207
Military logistics hub with shipping containers and equipment, laptop on workstation in foreground.

Marines Test AI-Powered Logistics Engine in Pacific Theater

The Marines are revolutionizing their logistics game with an AI-powered engine, recently tested in the Pacific Theater, which can analyze over 16 million parts and 4 million vendors to streamline sustainment planning. This cutting-edge tech, developed by defense company Tagup, is already being used by select Marine units to optimize logistics and drive efficiency.

Analyst 207