Skip to main content

Tag: supply chain

870 articles

Developer workstation with npm package management software on laptop screen, surrounded by clutter, with cityscape visible…

OpenAI Disrupted in TanStack npm Supply Chain Breach

Malicious packages have rocked the TanStack npm supply chain, with 84 tainted versions of 42 @tanstack/* packages published, drawing OpenAI into the crisis and prompting urgent action to secure its systems. The AI company has confirmed that attackers compromised two employee devices, stealing credentials and forcing a reset across multiple desktop products.

Analyst 207
Interior of a manufacturing facility with industrial equipment, a slightly ajar server room door, and scattered network…

China-Linked Hackers Deploy TencShell Malware Against Global Manufacturer

In a clever move, China-linked hackers adapted existing malware tools to create TencShell, using it to launch a stealthy attack on a global manufacturer's Indian site. Fortunately, researchers at Cato Networks' Cyber Threats Research Lab were able to block the intrusion and uncover the sophisticated tactics used.

Analyst 207
Person working on laptop surrounded by notes in neutral room.

TeamPCP hackers target Mistral AI code repos for sale

Hackers from TeamPCP are demanding $25,000 for nearly 5 gigabytes of stolen Mistral AI code, threatening to leak it for free if they don't find a buyer within a week. The group claims to have snagged around 450 internal repositories, including sensitive source code used for training and model delivery.

Analyst 207
Brightly-lit industrial setting with computer screens and machinery in disarray.

Foxconn Disrupted by Nitrogen Ransomware Attack

Nitrogen ransomware attackers claim to have stolen a massive 8 terabytes of sensitive data, including confidential files from tech giants like Intel, Apple, and Google, potentially disrupting the entire consumer-tech supply chain. The breach could have far-reaching consequences for suppliers and customers worldwide.

Analyst 207
Rural Australian landscape with combine harvester, vast fields, and distant shipping containers.

Australia's Supply Chains Face Structural Resilience Test

Australia's supply chains, once optimized for efficiency, are now facing a harsh reality: a world where disruption is the new norm, and resilience is the ultimate test. The intricate link between fuel and fertiliser - a coupled system that drives farming productivity - is buckling under the pressure, threatening economic and social stability.

Analyst 207
Network device on a rack in a data center with a neutral background.

Cisco SD-WAN Flaw Exploited in Zero-Day Attacks

A critical vulnerability in Cisco's SD-WAN system is being actively exploited, allowing attackers to bypass authentication and gain unauthorized access. This high-risk flaw, tracked as CVE-2026-20182, affects both on-prem and cloud deployments of Cisco Catalyst SD-WAN products.

Analyst 207
Dimly lit software development workspace with cluttered desk and turned-off laptop and monitor.

Malicious Node-IPC Versions Expose Developer Secrets to Stealer Backdoor

Three versions of the popular Node IPC package have been compromised with a stealthy backdoor that can steal sensitive developer secrets, sparking urgent concerns about supply-chain security. The malicious versions, published under a fake account, contain heavily obfuscated code that springs into action when the package is loaded at runtime.

Analyst 207
Electronics manufacturing facility with rows of workstations and equipment.

Foxconn Cyberattack Exposes Supply Chain Risks

A massive cyberattack on Foxconn has exposed the dark underbelly of supply chain risks, with hackers claiming to have stolen a staggering 11 million files - including confidential data from tech giants like Intel, Apple, and Nvidia. This breach highlights the long-term architectural risks that ransomware attacks can pose to global supply chains.

Analyst 207
Pharmaceutical facility personnel converse, looking concerned, near locked cabinet.

West Pharmaceutical Ransomware Attack Exposes Supply Chain Vulnerabilities

In the wake of a ransomware attack, West Pharmaceutical Services swiftly sprang into action, disclosing the breach and launching a thorough investigation with law enforcement and cyber-forensic experts. But despite their rapid response, the company's data loss has left many questions unanswered – and a glaring spotlight on supply chain vulnerabilities.

Analyst 207
Dimly lit shipping yard at dusk with rows of containers and a single, rusty, partially open cargo container.

Cybercrime Tactics Disrupt $725 Million in Cargo Heists

Cargo thieves are getting smarter, with cybercrime tactics fueling a staggering $725 million in heists across North America in 2025, and experts warn that the true cost may be even higher. This sophisticated game plan typically starts with online snooping, using publicly available info to plot the perfect crime.

Analyst 207
Windows computer on a clean surface with a USB drive inserted, in a brightly-lit secure setting.

Windows Zero-Days Expose BitLocker, CTFMON Vulnerabilities

A security researcher has uncovered a pair of alarming Windows zero-day vulnerabilities, including a BitLocker bypass and a privilege-escalation exploit that can be triggered with just a USB drive. Dubbed YellowKey, this exploit can even surface a shell on BitLocker-protected systems, giving attackers an easy way in.

Analyst 207
Construction workers build metal cages around oil tanks near an airport, with large enclosures shielding fuel tanks in the…

UAE Deploys 'Cope Cages' to Shield Energy Sites from Iranian Drone Threats

The UAE is taking bold steps to safeguard its energy sites from Iranian drone threats, with recent images revealing the deployment of metal "cope cages" around oil tanks near Dubai International Airport. This innovative defense strategy is the UAE's latest move to bolster its air defenses, which have already intercepted over 2,000 UAVs fired by Iran.

Analyst 207
Control room with exposed management panels and industrial equipment on a neutral-colored wall.

Russia Targets Polish Water Utilities in Hybrid Warfare Campaign

Poland's Internal Security Agency has uncovered a concerning trend: five cyber intrusions into water utilities have been linked to a pro-Russian hybrid campaign, part of a broader Kremlin strategy to target NATO's eastern flank.

Analyst 207
Developer workstation with laptop and office supplies in a bright, minimalist room.

Claude Code Attack Persists Through Token Rotation Flaw

A surprising lack of resistance to a proof-of-concept attack has exposed a vulnerability in Claude Code, allowing a five-step attack chain that can turn routine token rotation into a continuous compromise. This exploit requires just one malicious npm package and the ability to run code on a developer's machine, making it a concerning threat.

Analyst 207
A cluttered tech workspace with a laptop and coding materials in a neutral-colored room.

Malware Worm Targets npm, PyPi in Mass Supply-Chain Attack

A self-spreading worm, dubbed Mini Shai-Hulud, has infected over 170 packages with nearly 180 million weekly downloads, posing a massive threat to the software supply chain. This highly contagious malware has been open-sourced, making it easier for others to exploit and escalate the attack.

Analyst 207
Server room with computer equipment and servers under ordinary indoor lighting.

China-linked hackers exploit Microsoft Exchange in Azerbaijani energy firm attacks.

A group of China-linked hackers, known as FamousSparrow, launched a sustained cyberattack on an Azerbaijani oil and gas company, exploiting Microsoft Exchange vulnerabilities in a multi-wave intrusion that spanned three months. The attackers used the ProxyNotShell exploit to gain and maintain access to the victim's environment.

Analyst 207
Factory floor with machinery and a laptop or control panel in the foreground.

Foxconn Hit by Nitrogen Ransomware Attack

Foxconn, the world's largest electronics manufacturer, confirmed that some of its North American factories were hit by a cyberattack, with the Nitrogen ransomware operation claiming to have stolen a large trove of sensitive data. The company swiftly activated its response mechanism to minimize disruption and ensure production continuity.

Analyst 207
Naval official stands beside large vessel model at shipyard with manned and unmanned ships in background.

Navy Unveils 450-Hull Fleet Plan With 83 Unmanned Vessels

The Navy is set to revolutionize its fleet with a bold new plan, aiming to grow to 450 vessels by 2031, including 83 cutting-edge unmanned ships. This ambitious vision promises a more capable and powerful force, ready to defend and project strength on a global scale.

Analyst 207
Large vessel navigates through busy international strait with cityscape backdrop.

Southeast Asia Fractures Over Iranian Oil Deals

Singapore stands firm on its right to transit through international straits, a principle it sees as vital to its prosperity, and is now at odds with its Southeast Asian neighbors over Iranian oil deals. While Singapore advocates for unrestricted passage, others like Malaysia, Thailand, the Philippines, and Vietnam are pursuing bilateral arrangements, revealing a regional fracture.

Analyst 207
Developer workspace with open laptop and blurred screen, surrounded by tech equipment.

GemStuffer Exploits RubyGems to Exfiltrate UK Council Data

Meet GemStuffer, a sneaky campaign that's hijacking the RubyGems registry to steal sensitive data, including information from a UK council, by hiding scraped content within seemingly harmless package files. Over 150 malicious gems have been used to store and exfiltrate this data, exposing it to anyone who knows where to look.

Analyst 207
Software development workspace with laptop, tools, and notes, set against a blurred cityscape with natural light.

Malware Infects Hundreds of Open-Source Packages in Supply-Chain Attack

A massive supply-chain attack, dubbed "mini Shai-Hulud," has infected hundreds of open-source packages with credential-stealing malware, putting millions of developers and users at risk. The malicious code has been embedded in widely-used libraries and projects, including TanStack's React Router, which alone has over 12 million weekly downloads.

Analyst 207
Factory floor with industrial equipment, computer terminals, and a hint of a network room in the background.

Foxconn Cyberattack Exposes Sensitive Data from Apple, Nvidia Projects

A massive cyberattack on Foxconn's North American factories has compromised sensitive data from major tech giants, including Apple and Nvidia, with hackers allegedly making off with a staggering 8 TB of data and over 11 million files. Foxconn has confirmed the breach, assuring that production is resuming after swiftly activating its cybersecurity response mechanism.

Analyst 207
Linux developer in dimly lit workspace looks concerned amidst computer screens and notes.

Linux Defenders Scramble to Outpace Exploit Cycle

Linux defenders are racing against the clock to outmaneuver exploiters, with one maintainer proposing a temporary "kill switch" to disable vulnerable kernel functions until a proper patch can be developed. This stopgap solution aims to buy crucial time between vulnerability discovery and patch release.

Analyst 207
Rows of computer workstations and a large screen in a brightly-lit tech facility.

Microsoft Patch Tuesday Addresses 120 Vulnerabilities

Microsoft's May 2026 Patch Tuesday rollout is a doozy, tackling a whopping 120 vulnerabilities in one fell swoop - and thankfully, there are no zero-day threats to worry about this time around. This massive update means admins have their work cut out for them, but it's a big win for security.

Analyst 207