Tag: supply chain
871 articles

Weaver E-cology Flaw Exploited Through Debug API Endpoint
A critical bug in Weaver E-cology, known as CVE-2026-22679, is being actively exploited - allowing hackers to take full control of your system with a CVSS score of 9.8. This severe vulnerability lets attackers execute commands without needing login credentials, putting your entire system at risk.

Australia's Northern Economies Require Security-Focused Boost
With a severe shortage of workers in the Northern Territory, where only 7% of employers feel adequately staffed, the region is crying out for a security-focused boost to attract and retain the 14,000 extra workers it desperately needs over the next five years. Labour shortages are already crippling key industries like mining, construction, and hospitality, with flow-on effects that threaten the region's economic growth.

Nation-State Hackers Target Small Defense Firms' Network Gaps
Small defense firms are leaving themselves exposed to nation-state hackers, who exploited over 14 zero-day vulnerabilities in edge devices like routers and firewalls in 2025 to gain a foothold in the US defense industrial base. These stealthy cyber espionage groups are investing heavily in reconnaissance and pre-positioning operations to infiltrate and linger in their targets' networks.

Hackers Exploit Weaver E-cology Bug in Targeted Attacks
Hackers are taking advantage of a critical bug in Weaver E-cology, using an exposed debug API endpoint to execute system commands on vulnerable servers without needing login credentials. This security flaw, tracked as CVE-2026-22679, affects Weaver E-cology 10.0 builds prior to March 12.

New York Fines Delta Dental $2.25M for MOVEit Hack Violations
Delta Dental of New York has been fined $2.25 million by the New York Department of Financial Services for its handling of a massive data breach involving hackers stealing around 60,000 files from its MOVEit servers in 2023. The hefty penalty highlights the importance of robust cybersecurity measures to protect sensitive information.

Ransomware Breach Exposes Sensitive Data at Sandhills Medical Foundation
Sandhills Medical Foundation suffered a devastating ransomware attack on May 8, 2025, putting sensitive data at risk. It took nearly 11 months for affected individuals to be notified in April 2026, sparking an investigation into the breach.

EU Curbs Chinese Solar Inverter Funding Over Cybersecurity Fears
The European Commission has pulled the plug on EU funding for solar projects using Chinese-made inverters, citing serious cybersecurity threats that could lead to countrywide blackouts and unauthorized access to sensitive operational data. This move comes after risk assessments confirmed the potential for manipulation of electricity production and disruption of generation.

Malicious PyTorch Lightning Package Exploits Supply Chain to Steal Credentials
A malicious version of the popular PyTorch Lightning package, downloaded over 11 million times, was found to contain a stealthy backdoor that steals credentials by silently executing a heavily obfuscated JavaScript payload. The compromised package, version 2.6.3, triggers the malicious routine automatically when imported, putting users at risk.

AI-BOMs Tackle Shadow AI Risks in Enterprise Supply Chains
Imagine biting into a cake without knowing the recipe, ingredients, or who's behind the baking - it's a risk you wouldn't take, right? Similarly, without AI-BOMs, enterprises are left in the dark about the AI components powering their supply chains, leaving them vulnerable to shadow AI risks.

Progress Warns of MOVEit Automation Authentication Bypass Flaw
Progress Software has patched a critical authentication-bypass flaw in its MOVEit Automation product, and is strongly urging users to upgrade to the latest version to avoid low-complexity attacks by remote threat actors. Upgrading to version 2025.1.5, 2025.0.9, or 2024.1.8 and above will fix the vulnerability.

Silver Fox Targets India, Russia with ABCDoor Malware via Tax Phishing
Meet Silver Fox, a China-based cybercrime group that's using tax phishing scams to deliver a sneaky new malware called ABCDoor, targeting India and Russia with cleverly crafted emails that masquerade as official tax notices. The group's tactics involve PDFs with links to infected archives, tricking victims into downloading the malware.

Microsoft Updates Disrupt Third-Party Backup Apps on Windows
Microsoft's latest Windows security update has caused disruptions to third-party backup apps, adding a vulnerable kernel driver to its blocklist to protect users from potential exploits. This change aims to prevent attackers from escalating privileges or executing arbitrary code, but has unfortunately caused failures in some backup products.

Iran's Shahed Drone Imposes Cost-Exchange Crisis on US Air Defences
Iran's massive production of Shahed drones, potentially reaching 400-500 units monthly, has transformed these once-nuisance weapons into a game-changing force that could redefine the US-Iran conflict. With Iranian and Russian facilities churning out over 200 units per month, the US air defenses now face a daunting cost-exchange crisis.

Grain Markets Expose National Security Fault Lines
Discover how global conflicts, from World War I to today, have exposed the shocking vulnerabilities of grain markets and national security, revealing the high stakes of protecting our food supply. Maritime chokepoints like the Dardanelles and Strait of Hormuz have repeatedly put grain supplies at risk, highlighting the urgent need for secure agricultural supply chains.

US Weapons Deliveries to Nordic Allies Hit by Middle East War
US weapons deliveries to Norway and other Nordic allies are facing potential delays due to the ongoing conflict in the Middle East, with Washington notifying Oslo of possible hold-ups. The delays, however, have not been officially confirmed, with US authorities stressing that no decision has been made yet.

CISA's Zero Trust Guidance Falls Short on Cost, Implementation Details
While CISA's new zero trust guidance for operational technology is a step in the right direction, it leaves critical questions unanswered - namely, who foots the bill and how do organizations actually implement it? The guidance gets high marks for technical thinking, but falls short on practical details like funding, timelines, and automation.

Malicious Ruby Gems, Go Modules Exploit CI Pipelines for Credential Theft
Malicious actors are targeting developers and CI pipelines with fake Ruby Gems and Go Modules, masquerading as familiar libraries to steal credentials. The campaign, linked to the GitHub account BufferZoneCorp, poses a significant threat to software supply chains.

Home Office Bolsters Passport Contract to £576M Amid Rising Demand
The Home Office has supercharged its passport production contract, boosting its value to £576 million as demand for passports continues to soar. This 12-year deal, worth £48 million annually, is a significant increase from the original £360 million estimate.

FCC Fortifies Telecom Rules to Combat Robocalling and Cyber Threats
The FCC is cracking down on telecom companies that aren't doing enough to stop robocalling and cyber threats, with Chair Brendan Carr slamming those who do the bare minimum to verify callers as complicit in illegal schemes. New rules aim to tighten verification and supply-chain security to protect US phone networks.

China Accelerates Indo-Pacific Push, Tests Regional Cohesion
As China's influence grows in the Indo-Pacific, regional states face a daunting dilemma: balancing economic opportunities with sovereignty and security concerns, making it increasingly likely they'll hedge their bets rather than fully commit to either side. This strategic tightrope walk will be especially challenging for Pacific island countries under strain from China's more aggressive pursuit of port access and maritime influence.

Malware Worms Into SAP, Intercom and Lightning Developer Tools
Malicious actors struck SAP's JavaScript and cloud application development ecosystem on April 29, releasing poisoned versions of four widely-used npm packages that receive a staggering 572,000 weekly downloads. The compromised packages, which included mbt, @cap-js/db-service, @cap-js/postgres, and @cap-js/sqlite, were published in a brief window of just two hours.

Socket Expands Supply-Chain Visibility with Secure Annex Acquisition
Socket is supercharging its supply-chain visibility with the acquisition of Secure Annex, a cutting-edge extension security startup, to give developers unprecedented control across the entire software development life cycle. This strategic move combines Socket's expertise in application dependencies with Secure Annex's innovative approach to browser and IDE extensions.

Brazilian DDoS Firm Exposes Own Security Breach
A Brazilian firm's bold admission about notifying major internet providers of massive DDoS attacks against small ISPs took an unexpected turn when evidence revealed a shocking security breach of its own. The company's CEO, Erick Nascimento, revealed that an intrusion in January 2026 compromised key servers and his personal security codes.

Satellite Firm Apex Unveils Software 'Secret Sauce' for Mass Production
Meet Octopus, Apex's game-changing software suite that powers the entire company, from forecasting and inventory to factory operations and even satellite tracking. This AI-driven secret sauce has transformed a small satellite bus into a thriving production line, and Apex CEO Ian Cinnamon credits it as their key differentiator.