Skip to main content

Tag: supply chain

871 articles

BAE Systems shipyard at Barrow, England, with industrial equipment and cranes.

UK lawmakers warn AUKUS submarine program faces delays over investment shortcomings

UK lawmakers are sounding the alarm that the AUKUS submarine program is at risk of delays due to insufficient investment in upgrading the BAE Systems shipyard in Barrow, England, where the submarines will be built. If upgrades continue to slip, it could have serious consequences for UK national security and damage credibility with AUKUS partners.

Analyst 207
Computer workstation with blank screen in a government or research facility setting.

US Urged to Block AI Chip Exports to China Amid Distillation Threats

To stay ahead of adversaries, the US must restrict their access to advanced AI chips - a crucial step in preventing them from replicating the capabilities of American AI models. Blocking exports of these chips to China is a vital move, experts warn.

Analyst 207
Large, empty development environment with rows of code on sleek computer screens against a neutral background.

Checkmarx GitHub Data Leaked by LAPSUS$ Hackers

Checkmarx confirmed that hackers from the LAPSUS$ group breached its GitHub repository on March 23, 2026, and published stolen data on April 22, after a series of supply-chain and credential-theft events. The attackers used the access to publish malicious code to certain artifacts, compromising the integrity of Checkmarx's software development process.

Analyst 207
Formal courthouse scene with stern atmosphere, blurred figures in background.

China's Silk Typhoon Hacker Extradited to US Over COVID Cyberattacks

A Chinese hacker, Xu Zewei, has been extradited to the US from Italy for masterminding a series of devastating cyberattacks on US universities, immunologists, and virologists working on COVID-19 vaccines, treatments, and testing between 2020 and 2021. He faces charges of wire fraud and conspiracy for his role in the attacks.

Analyst 207
Formal government setting with podium and judicial backdrop, lit by daylight and abstract shapes.

US Charges Chinese National in Silk Typhoon Cyber Attacks

A Chinese national, Xu Zewei, has been extradited to the US from Italy to face charges for his alleged role in the notorious HAFNIUM cyber attacks, a vast intrusion campaign that compromised over 12,700 US organizations. Xu's arrival in US court marks a significant step in holding him accountable for his actions.

Analyst 207
Cluttered developer workstation with laptop, monitors, and notes in a bright office setting.

Supply-Chain Attack Targets Security, Dev Tools with Credential Theft

Malicious hackers are exploiting the very tools developers rely on, including security scanners and password managers, to steal sensitive credentials and gain unauthorized access. This latest supply-chain attack has already hit major players like Checkmarx, compromising their GitHub repository and potentially putting customer data at risk.

Analyst 207
Formal government building entrance with steps and abstract seal-like patterns.

Ex-DOD Leaders Challenge Pentagon's Anthropic Designation as Illegal

Former national security officials are challenging the Pentagon's designation of Anthropic as a supply-chain risk, calling it a politically motivated move that's legally flawed and actually undermines national security. They argue that the designation was a misuse of authorities meant to address genuine threats, rather than a legitimate national security concern.

Analyst 207
Laptop screen displays code editor surrounded by papers and notes on a simple desk.

GlassWorm Malware Resurfaces Through 73 OpenVSX Extensions

Researchers at Socket have uncovered a sneaky new wave of GlassWorm malware, this time hiding in 73 OpenVSX extensions that behave like sleepers - seemingly harmless at first, but turning malicious after a stealthy update. Six of these extensions have already been activated, unleashing malware on unsuspecting developers.

Analyst 207
Crypto executive looks concerned at laptop with subtle scheduling software on screen.

North Korean Hackers Exploit Fake Zoom Meetings to Target Crypto Executives

North Korean hackers are using a sneaky tactic to target crypto executives: they pose as legitimate meeting attendees, harvesting video and audio to make future scams more convincing. They start by sending Calendly invites for fake catch-up meetings, then swap the link with a fake Zoom or Teams URL to gain their victim's trust.

Analyst 207
Smart meter on a utility pole with blurred details set against a calm daytime city backdrop.

Medtronic, Itron Disclose Breaches by Digital Intruders

Itron sprang into action after detecting an unauthorized break-in on April 13, swiftly notifying law enforcement, and working with cybersecurity experts to investigate and remediate the breach. The company has since confirmed that it has prevented any further unauthorized activity within its corporate systems.

Analyst 207
Developer workstation with code on screen in a clean, minimalist environment.

Checkmarx Breach Exposes GitHub Repository Data on Dark Web

Checkmarx revealed that a security breach, linked to a March 23 supply chain attack, exposed sensitive GitHub repository data, which has now surfaced on the dark web. The incident has been contained, with no customer data compromised, as the affected repository was separate from Checkmarx's customer production environment.

Analyst 207
Cluttered developer workstation with laptop and monitor in a home office setting.

PyPI Package elementary-data Compromised to Steal Developer Data

A malicious release of the popular elementary-data package on PyPI, which has over 1.1 million monthly downloads, allowed an attacker to steal developer data through a sneaky backdoor. This widely-used open-source tool for data observability in dbt pipelines became a prime target for the secrets-stealing campaign.

Analyst 207
Residential building with open door and scattered personal items, hinting at vulnerability.

ADT Breach Exposes 5.5 Million in ShinyHunters Hack

A massive data breach at ADT has put 5.5 million people's personal info at risk, including names, phone numbers, addresses, and sensitive details like dates of birth and Social Security numbers. The breach, linked to the ShinyHunters extortion group, has left millions vulnerable to potential identity theft and scams.

Analyst 207
Cluttered developer workstation with laptop, notes, and coffee cups, blurred cityscape in background.

npm Ecosystem Faces Rising Threat from Sophisticated Malware Campaigns

The npm ecosystem's security has reached a critical turning point, with sophisticated malware campaigns on the rise and a new baseline of threats emerging since September 2025. Malicious actors are now exploiting developer trust, transforming nuisance attacks into high-consequence supply-chain threats.

Analyst 207
A postcard on a wooden table with a small Bluetooth device beside it.

Mail Exploited to Track Dutch Naval Ship with Hidden Bluetooth Device

A clever journalist working for Omroep Gelderland successfully tracked a Dutch naval ship for nearly a day using a sneaky hidden Bluetooth tracker sent via postcard - all thanks to publicly available instructions on how to pull off the trick. This eye-opening experiment reveals just how easy it can be to compromise security with a little creativity and some off-the-shelf tech.

Analyst 207
Blurred customer information sheet on a cluttered office desk with scattered papers and a pen.

ADT Confirms Data Breach After ShinyHunters Extortion Threat

ADT confirmed a data breach after a threat from hackers known as ShinyHunters, who demanded an extortion payment. The breach exposed sensitive customer info, including names, phone numbers, addresses, and in some cases, dates of birth and Social Security numbers.

Analyst 207
Laptop screen displays lines of code on a modern office desk with blurred equipment in the background.

Supply-Chain Attacks Target Software Libraries

Supply-chain attacks are now using automation tools to spread malware at alarming speed, with recent incidents showing malicious code can go live in mere hours and be merged into projects in just minutes. This sinister trend highlights the dark side of modern software development's emphasis on speed and automation.

Analyst 207
Network equipment and security appliances in a brightly lit industrial control room.

CISA Exposes Persistent FIRESTARTER Backdoor in Cisco Devices

CISA and NCSC have uncovered a sneaky FIRESTARTER backdoor lurking in Cisco devices, allowing hackers to regain control even after patches are applied. This persistent threat can leave devices vulnerable to re-entry, putting your entire network at risk.

Analyst 207
NASA employees work at desks with laptops and computers in a well-lit office setting.

NASA Targeted in Chinese Phishing Scheme for U.S. Defense Software

For years, unsuspecting NASA employees and collaborators were duped into sharing sensitive US defense software with a Chinese national masquerading as a colleague, in a brazen phishing scheme that went undetected for years. The scam funneled top-secret aerospace and defense tech to the imposter, violating US export control laws in the process.

Analyst 207
American and Indonesian officials shake hands in a formal conference room.

US-Indonesia Ties Pivot to High-Stakes Partnership

The US-Indonesia partnership has leveled up, shifting from a focus on shared values to a high-stakes game of mutual benefit, where critical minerals, supply chains, and defense capabilities are on the table. The question is, can this new transactional relationship deliver the real results both countries are counting on?

Analyst 207
Person working remotely on laptop with security warning on screen.

Microsoft Update Disrupts Remote Desktop Security Warnings

Microsoft's latest update aimed at boosting Remote Desktop security may have an unintended consequence: a display-scaling bug that makes crucial security warnings hard to read or even unreadable. This glitch comes at a critical time, as the update was designed to protect against phishing attacks that exploit .rdp files.

Analyst 207
Developer workstation with laptop and terminal, surrounded by notes and coffee cups, with a blurred cityscape in the…

Malware Targets Developers with Worm-Like Npm Supply Chain Attack

Malware is targeting developers through a sneaky npm supply chain attack, executing malicious code the moment a package is installed, and harvesting sensitive data to spread across ecosystems. Over 6,700 weekly downloads of one affected package show just how widespread the threat could be.

Analyst 207
Cluttered server room with stacked routers, cables, and wires in dim light.

China Builds Covert Hacker Networks with Compromised Routers

China-nexus cyber actors have dramatically changed their game, ditching solo operations for massive networks of hacked devices - and it's a threat you need to know about. A joint advisory from top cyber agencies worldwide warns of this new tactic, urging vigilance in the face of large-scale cyber attacks.

Analyst 207
Defense facility workstations and equipment with computer screens in the foreground.

Pentagon Pushes Modular Defense Acquisition With Multi-Sourcing, MOSA

The Department of Defense is shaking up its acquisition strategy with a bold move towards modular defense, embracing multi-sourcing and MOSA to boost resilience and reduce costs. By enforcing a "two-for-production" standard, it's aiming to revive second sourcing for critical content and break the habit of single-source suppliers.

Analyst 207