Tag: supply chain
870 articles

OpenAI Disrupted in TanStack npm Supply Chain Breach
Malicious packages have rocked the TanStack npm supply chain, with 84 tainted versions of 42 @tanstack/* packages published, drawing OpenAI into the crisis and prompting urgent action to secure its systems. The AI company has confirmed that attackers compromised two employee devices, stealing credentials and forcing a reset across multiple desktop products.

China-Linked Hackers Deploy TencShell Malware Against Global Manufacturer
In a clever move, China-linked hackers adapted existing malware tools to create TencShell, using it to launch a stealthy attack on a global manufacturer's Indian site. Fortunately, researchers at Cato Networks' Cyber Threats Research Lab were able to block the intrusion and uncover the sophisticated tactics used.

TeamPCP hackers target Mistral AI code repos for sale
Hackers from TeamPCP are demanding $25,000 for nearly 5 gigabytes of stolen Mistral AI code, threatening to leak it for free if they don't find a buyer within a week. The group claims to have snagged around 450 internal repositories, including sensitive source code used for training and model delivery.

Foxconn Disrupted by Nitrogen Ransomware Attack
Nitrogen ransomware attackers claim to have stolen a massive 8 terabytes of sensitive data, including confidential files from tech giants like Intel, Apple, and Google, potentially disrupting the entire consumer-tech supply chain. The breach could have far-reaching consequences for suppliers and customers worldwide.

Australia's Supply Chains Face Structural Resilience Test
Australia's supply chains, once optimized for efficiency, are now facing a harsh reality: a world where disruption is the new norm, and resilience is the ultimate test. The intricate link between fuel and fertiliser - a coupled system that drives farming productivity - is buckling under the pressure, threatening economic and social stability.

Cisco SD-WAN Flaw Exploited in Zero-Day Attacks
A critical vulnerability in Cisco's SD-WAN system is being actively exploited, allowing attackers to bypass authentication and gain unauthorized access. This high-risk flaw, tracked as CVE-2026-20182, affects both on-prem and cloud deployments of Cisco Catalyst SD-WAN products.

Malicious Node-IPC Versions Expose Developer Secrets to Stealer Backdoor
Three versions of the popular Node IPC package have been compromised with a stealthy backdoor that can steal sensitive developer secrets, sparking urgent concerns about supply-chain security. The malicious versions, published under a fake account, contain heavily obfuscated code that springs into action when the package is loaded at runtime.

Foxconn Cyberattack Exposes Supply Chain Risks
A massive cyberattack on Foxconn has exposed the dark underbelly of supply chain risks, with hackers claiming to have stolen a staggering 11 million files - including confidential data from tech giants like Intel, Apple, and Nvidia. This breach highlights the long-term architectural risks that ransomware attacks can pose to global supply chains.

West Pharmaceutical Ransomware Attack Exposes Supply Chain Vulnerabilities
In the wake of a ransomware attack, West Pharmaceutical Services swiftly sprang into action, disclosing the breach and launching a thorough investigation with law enforcement and cyber-forensic experts. But despite their rapid response, the company's data loss has left many questions unanswered – and a glaring spotlight on supply chain vulnerabilities.

Cybercrime Tactics Disrupt $725 Million in Cargo Heists
Cargo thieves are getting smarter, with cybercrime tactics fueling a staggering $725 million in heists across North America in 2025, and experts warn that the true cost may be even higher. This sophisticated game plan typically starts with online snooping, using publicly available info to plot the perfect crime.

Windows Zero-Days Expose BitLocker, CTFMON Vulnerabilities
A security researcher has uncovered a pair of alarming Windows zero-day vulnerabilities, including a BitLocker bypass and a privilege-escalation exploit that can be triggered with just a USB drive. Dubbed YellowKey, this exploit can even surface a shell on BitLocker-protected systems, giving attackers an easy way in.

UAE Deploys 'Cope Cages' to Shield Energy Sites from Iranian Drone Threats
The UAE is taking bold steps to safeguard its energy sites from Iranian drone threats, with recent images revealing the deployment of metal "cope cages" around oil tanks near Dubai International Airport. This innovative defense strategy is the UAE's latest move to bolster its air defenses, which have already intercepted over 2,000 UAVs fired by Iran.

Russia Targets Polish Water Utilities in Hybrid Warfare Campaign
Poland's Internal Security Agency has uncovered a concerning trend: five cyber intrusions into water utilities have been linked to a pro-Russian hybrid campaign, part of a broader Kremlin strategy to target NATO's eastern flank.

Claude Code Attack Persists Through Token Rotation Flaw
A surprising lack of resistance to a proof-of-concept attack has exposed a vulnerability in Claude Code, allowing a five-step attack chain that can turn routine token rotation into a continuous compromise. This exploit requires just one malicious npm package and the ability to run code on a developer's machine, making it a concerning threat.

Malware Worm Targets npm, PyPi in Mass Supply-Chain Attack
A self-spreading worm, dubbed Mini Shai-Hulud, has infected over 170 packages with nearly 180 million weekly downloads, posing a massive threat to the software supply chain. This highly contagious malware has been open-sourced, making it easier for others to exploit and escalate the attack.

China-linked hackers exploit Microsoft Exchange in Azerbaijani energy firm attacks.
A group of China-linked hackers, known as FamousSparrow, launched a sustained cyberattack on an Azerbaijani oil and gas company, exploiting Microsoft Exchange vulnerabilities in a multi-wave intrusion that spanned three months. The attackers used the ProxyNotShell exploit to gain and maintain access to the victim's environment.

Foxconn Hit by Nitrogen Ransomware Attack
Foxconn, the world's largest electronics manufacturer, confirmed that some of its North American factories were hit by a cyberattack, with the Nitrogen ransomware operation claiming to have stolen a large trove of sensitive data. The company swiftly activated its response mechanism to minimize disruption and ensure production continuity.

Navy Unveils 450-Hull Fleet Plan With 83 Unmanned Vessels
The Navy is set to revolutionize its fleet with a bold new plan, aiming to grow to 450 vessels by 2031, including 83 cutting-edge unmanned ships. This ambitious vision promises a more capable and powerful force, ready to defend and project strength on a global scale.

Southeast Asia Fractures Over Iranian Oil Deals
Singapore stands firm on its right to transit through international straits, a principle it sees as vital to its prosperity, and is now at odds with its Southeast Asian neighbors over Iranian oil deals. While Singapore advocates for unrestricted passage, others like Malaysia, Thailand, the Philippines, and Vietnam are pursuing bilateral arrangements, revealing a regional fracture.

GemStuffer Exploits RubyGems to Exfiltrate UK Council Data
Meet GemStuffer, a sneaky campaign that's hijacking the RubyGems registry to steal sensitive data, including information from a UK council, by hiding scraped content within seemingly harmless package files. Over 150 malicious gems have been used to store and exfiltrate this data, exposing it to anyone who knows where to look.

Malware Infects Hundreds of Open-Source Packages in Supply-Chain Attack
A massive supply-chain attack, dubbed "mini Shai-Hulud," has infected hundreds of open-source packages with credential-stealing malware, putting millions of developers and users at risk. The malicious code has been embedded in widely-used libraries and projects, including TanStack's React Router, which alone has over 12 million weekly downloads.

Foxconn Cyberattack Exposes Sensitive Data from Apple, Nvidia Projects
A massive cyberattack on Foxconn's North American factories has compromised sensitive data from major tech giants, including Apple and Nvidia, with hackers allegedly making off with a staggering 8 TB of data and over 11 million files. Foxconn has confirmed the breach, assuring that production is resuming after swiftly activating its cybersecurity response mechanism.

Linux Defenders Scramble to Outpace Exploit Cycle
Linux defenders are racing against the clock to outmaneuver exploiters, with one maintainer proposing a temporary "kill switch" to disable vulnerable kernel functions until a proper patch can be developed. This stopgap solution aims to buy crucial time between vulnerability discovery and patch release.

Microsoft Patch Tuesday Addresses 120 Vulnerabilities
Microsoft's May 2026 Patch Tuesday rollout is a doozy, tackling a whopping 120 vulnerabilities in one fell swoop - and thankfully, there are no zero-day threats to worry about this time around. This massive update means admins have their work cut out for them, but it's a big win for security.