Skip to main content

Tag: supply chain

870 articles

Workers in a brightly-lit shipbuilding facility with a large naval ship under construction.

US Navy Seeks Overseas Shipbuilding Amid Domestic Capacity Crunch

The US Navy is taking bold steps to reclaim its maritime dominance, with Acting Secretary Hung Cao calling for urgency and commitment to overcome America's shipbuilding capacity crunch. The Navy's Fiscal Year 2027 Shipbuilding Plan proposes a strategic solution: supplementing domestic yards with targeted overseas shipbuilding.

Analyst 207
Laptop workstation with blank screen, surrounded by papers and notes in a neutral-colored room.

TanStack npm packages compromised in cache-poisoning attack

Malicious attackers have launched a lightning-fast cache-poisoning attack on TanStack npm packages, flooding the supply chain with 84 tainted versions loaded with credential theft and disk-wiping code. This six-minute blitz highlights the vulnerability of software supply chains to swift and devastating strikes.

Analyst 207
Dimly lit development workspace with laptop and empty GitHub repositories or terminal windows.

Shai Hulud Campaign Targets Developers with Malicious npm Packages

Malicious actors have unleashed a barrage of 84 tainted versions of popular software packages, cleverly disguising them with legitimate credentials to deceive developers. The Shai Hulud campaign, linked to the TeamPCP threat group, has been wreaking havoc on the software supply chain since September.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center setting.

SAP Patches Critical Flaws in Commerce Cloud and S/4HANA

SAP has patched a critical vulnerability in its Commerce Cloud and S/4HANA systems, warning that hackers could exploit the flaw to upload malicious code and take control of the application. This security gap, caused by a misconfigured Spring Security setup, put sensitive data and system integrity at risk.

Analyst 207
Cluttered tech workspace with laptop and development tools on a desk.

Mini Shai-Hulud Worm Targets Multiple AI, Dev Packages

Meet the Mini Shai-Hulud worm, a sneaky new malware that's infiltrating AI and development packages through a clever supply-chain attack. This malicious code can steal sensitive data from cloud providers, cryptocurrency wallets, and even popular dev tools like GitHub Actions.

Analyst 207
Naval supply ship surrounded by autonomous vessels in open ocean under cloudy sky.

Navies Target Autonomous Logistics Shift

The traditional logistics problem of the "last mile" has morphed into a far larger threat, now spanning 1,700 km or more, as persistent surveillance and precision strike capabilities turn large supply ships into vulnerable targets. The era of concentrating ships in big logistics formations is rapidly becoming a relic of the past.

Analyst 207
Developer workstation with laptop, code editor, and cluttered desk in a bright office.

Malware Exploits Chromium Interface to Steal Dev Secrets

Malware is masquerading as a legitimate software installer, tricking developers into spilling their secrets by exploiting the Chromium interface. A simple search ad has become the conduit for this malicious campaign, leading unsuspecting devs down a path of deceit.

Analyst 207
Laptop screen displays Jenkins plugin interface with code environment, beside blurred smartphone and sticky notes.

TeamPCP Breaches Checkmarx Jenkins Plugin Again

If you're using the Checkmarx Jenkins AST plugin, make sure you're on a safe footing by using version 2.0.13-829.vc72453fa_1c16 or earlier, published on December 17, 2025, as newer versions may be vulnerable. Checkmarx has since released a patched version, 2.0.13-848.v76e89de8a_053, available on GitHub and the Jenkins Marketplace.

Analyst 207
Software development team works at a continuous-integration workstation with laptop and monitor displaying a plugin…

Checkmarx Plugin Sabotaged in Fresh TeamPCP Intrusion

Checkmarx issued a warning on May 9, 2026, that a tampered version of its Jenkins AST plugin had been released on the Jenkins Marketplace, posing a risk to continuous-integration pipelines. The company quickly responded by urging customers to update to a trusted version, 2.0.13-829.vc72453fa_1c16, to safeguard their systems.

Analyst 207
Developers' workstation with laptop, code editor, notes, and coffee cups in a bright office setting.

PowerShell Stealer Targets Devs via Fake Claude Code Pages

Developers beware: a sneaky PowerShell Stealer is targeting you through fake Claude Code pages, putting your organization's most sensitive assets at risk. Clicking on innocent-looking sponsored search results could be the first step in a devastating cyberattack.

Analyst 207
Router on a rack with cables connected, in a neutral-colored room with ordinary lighting.

FCC Extends Security Update Deadline for Banned Routers

The FCC is giving banned routers a lifeline with an extended security update deadline, ensuring they stay safe and functional with continued software and firmware updates. This move comes after the commission banned the import and sale of certain foreign-made routers in March 2026 due to national security concerns.

Analyst 207
Laptop, smartphone, and notebook arranged on a desk in a tidy workspace.

Malicious Repo Exploits OpenAI Model to Deliver Info Stealer

A malicious repository disguised as OpenAI's legitimate Privacy Filter model racked up 244,000 downloads and became the #1 trending project on Hugging Face, but actually hid a sneaky Rust-based information stealer targeting Windows machines. The fake repository, Open-OSS/privacy-filter, expertly impersonated OpenAI's release, even copying the official model card to gain users' trust.

Analyst 207
Worn rail track stretches into the distance across arid Australian landscape.

Australia's Infrastructure Failures Erode National Security

Australia's broken promises on infrastructure are compromising its national security, with crucial projects like the Inland Rail - a game-changing freight line from Melbourne to Brisbane - stalled due to flawed assumptions, politics, and the passage of time. This has left the nation's supply chain resilience, regional industry, and agricultural competitiveness hanging in the balance.

Analyst 207
Mac laptop on a desk with a Terminal window open, in a blurred office setting.

Hackers Exploit Google Ads, AI Chats to Spread Mac Malware

Malicious hackers are exploiting Google ads and AI chat platforms to trick Mac users into downloading malware, using a sneaky tactic that involves fake installation guides and Terminal commands. Clicking on what seems to be a legitimate ad can lead to a malware-ridden surprise, thanks to a vulnerability in Claude's shared-chat feature.

Analyst 207
Military drone on barren terrain with supplies, vehicles, and soldiers in background.

Drones Transform Battlefield Logistics Amid Resource Scarcity

In Ukraine, a staggering 50-80% of frontline resupply is now handled by drones, revolutionizing battlefield logistics and transforming the way troops receive vital supplies. This seismic shift is driven by the simple math of cost and risk: drones are cheaper and safer than traditional trucks and soldiers.

Analyst 207
Laptop screen displays compromised website in home office setting.

JDownloader Site Compromised to Spread Python RAT Malware

A Reddit user recently raised the alarm after Microsoft Defender flagged a JDownloader download on their new PC, uncovering a sinister plot to spread Python RAT malware through the popular download manager's compromised website. The JDownloader site was hacked between May 6-7, 2026, allowing attackers to swap legitimate downloads with malicious payloads.

Analyst 207
Naval shipyard scene with workers, equipment, and large vessel in background.

Rheinmetall Sees Sales Surge Amid Naval Expansion

Rheinmetall is riding a wave of success, with sales soaring to €1.9 billion in Q1 2026 - an impressive 8% jump from last year - as its naval expansion plans gain momentum. The company is optimistic about the future, predicting a significant growth spurt in Q2 fueled by large naval and automotive orders.

Analyst 207
Cluttered computer workstation in a small office with a blurred laptop screen.

NVIDIA Discloses GeForce NOW Breach Affecting Armenian Users

NVIDIA recently discovered a security breach affecting users of GeForce NOW in Armenia, which was caused by a compromised system operated by a third-party partner, not by NVIDIA's own network. The company is working closely with the partner to resolve the issue and notify affected users.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center.

Data Breaches Surge, Exposing Sensitive Info at AI Startups, Agencies

Data breaches are surging, with AI startups and agencies exposed, as seen in the alarming theft of 10 petabytes from a Chinese supercomputer and 4 terabytes from AI startup Mercor due to a supply-chain vulnerability. These incidents highlight the hidden risks of connecting data to AI models, creating sensitive blind spots that leave large data sets vulnerable to compromise.

Analyst 207
Cluttered developer workstation with laptop and devices, screens blank.

Linux RAT Quasar Exploits Developer Credentials for Supply Chain Compromise

Meet QLNX, a sneaky Linux malware that's targeting developers and DevOps teams to gain control of the software supply chain by stealing sensitive credentials. This stealthy threat operates from memory, masquerading as a harmless system process while secretly exfiltrating data and awaiting commands from its controllers.

Analyst 207
Server racks and cloud storage units in a data center with a hint of disruption.

PCPJack Disrupts TeamPCP's Cloud Footprint with Credential Theft

Meet PCPJack, a sneaky new credential theft framework that's wreaking havoc on TeamPCP's cloud operations by stealing sensitive credentials and clearing out the competition. This malicious tool is quietly moving through cloud environments, leaving a trail of compromised systems in its wake.

Analyst 207
Blurred laptop screen shows Canvas login page in bright college library setting.

ShinyHunters Breach Exposes 330 Colleges in Canvas Hack

The notorious ShinyHunters gang has breached Instructure's Canvas, exposing a staggering 330 colleges to a devastating hack, and issued a chilling ultimatum with a May 2026 deadline to negotiate. The attackers replaced login pages with an extortion message, demanding schools seek cyber advisory help and secretly reach out to settle.

Analyst 207
US Department of Defense facility interior with technology devices on a neutral surface.

Pentagon Moves to Diversify Frontier AI Suppliers Amid Anthropic Dispute

The Pentagon is shaking things up by diversifying its frontier AI suppliers, vowing to never again rely on just one vendor for advanced artificial intelligence systems. This move comes after a public pledge from Under Secretary of Defense Emil Michael to break free from a single-provider dependency.

Analyst 207
Cluttered developer workstation with laptop and monitor in shared office space.

Cline Kanban Flaw Exposes AI Coding Agents to Website Hijacking

A critical vulnerability in Cline Kanban's WebSocket endpoints lets hackers hijack websites visited by developers, silently interacting with local AI agents - and it's a flaw that requires zero phishing, malware, or social engineering. This severe flaw, scoring 9.7 on the CVSS scale, puts AI coding agents at risk of website hijacking.

Analyst 207