Tag: supply chain
871 articles

Netgear Sidesteps Router Ban with FCC Waiver
Netgear has scored a major win with the FCC granting it a temporary waiver, allowing the company to import consumer routers until 2027 despite a broader ban on foreign-made networking hardware. This move marks a significant exception to the rule, with Netgear becoming the first consumer brand to sidestep the import restriction.

WordPress Plugin Suite Compromised, Malware Deployed on Thousands of Sites
Thousands of websites have been unwittingly turned into malware gateways due to a massive compromise of over 30 WordPress plugins in the EssentialPlugin package, highlighting a disturbing vulnerability in the internet ecosystem. This security breach has left countless sites exposed, raising urgent questions about accountability and prevention.

n8n Workflow Automation Platform Exploited to Deliver Malware via Phishing Emails
Imagine a tool designed to streamline your work being turned against you - that's what happened when threat actors exploited the popular n8n workflow automation platform to deliver malware via phishing emails, starting as early as October 2025. This clever tactic uses trusted infrastructure to evade defenses, turning productivity tools into a conduit for harm.

Ransomware Disrupts Autovista's Automotive Data Services
A ransomware infection has crippled Autovista's automotive data services in Europe and Australia, forcing customers to choose between isolating the affected vendor or patiently waiting for a resolution. Autovista has called in outside experts to help contain and clean up the breach.

Industrial Automation Systems Face Rising Cyber Threats Globally
As cyber threats escalate globally, industrial automation systems are becoming a prime target, leaving factories and control rooms vulnerable to attack - but who's sounding the alarm and answering the call? A recent industry snapshot for Q4 2025 sheds light on the rising threat landscape, revealing key infection vectors, malware trends, and regional hotspots.

Transportation Sector Grapples with Rising Cyber Risks from Connected Vehicles
As modern trucks transform into data centers on wheels, loaded with sensors and connectivity, they also become vulnerable to cyber threats - turning transportation into a pressing cybersecurity issue. With their expanding attack surfaces, the transportation sector is racing against time to tackle the fast-evolving risks of connected vehicles.

GitHub AI Agents Exposed to Credential Theft via Prompt Injection
Security researchers have uncovered a shocking vulnerability in popular GitHub AI agents, demonstrating how a simple prompt injection technique can be exploited to steal sensitive credentials, leaving users alarmingly exposed. The findings highlight a disturbing lack of transparency from vendors, putting automation and service access at risk.

Domestic Production Bolsters Mobile Artillery Capabilities
In today's fast-paced battles, mobile artillery is crucial for success - but can it keep up unless we rebuild its industrial base right here at home? By manufacturing these powerful guns domestically, we can ensure their availability and stay ahead of the game.

Microsoft Rushes Fixes for 167 Vulnerabilities Amid Zero-Day Exploits
Microsoft just rolled out urgent Patch Tuesday fixes for a whopping 167 vulnerabilities in Windows and related software, including zero-day exploits in SharePoint Server and Windows Defender. But with threats evolving at breakneck speed, can patches keep up to protect our increasingly software-reliant lives?

Malicious Chrome Extensions Infiltrate Web Store, Compromise User Data
Malicious Chrome extensions, masquerading as harmless tools, have infiltrated the official Web Store, putting millions of users' data at risk by stealing sensitive tokens, planting backdoors, and running ad fraud. Over 100 of these rogue add-ons have been identified, highlighting a growing threat in a marketplace we thought was safe.

Microsoft Patch Tuesday Addresses 167 Vulnerabilities, Fixes 2 Zero-Day Flaws
Microsoft's April Patch Tuesday update is a doozy, tackling a whopping 167 vulnerabilities, including two zero-day flaws that demand immediate attention. The question is, can you afford to wait - or do you need to act fast to safeguard your organization?

Rheinmetall Forges Missile Alliance with Destinus to Bolster European Defence Industry
Rheinmetall and Destinus are joining forces to create a game-changing missile systems joint venture, set to supercharge Europe's defence industry with cutting-edge capabilities. This powerful alliance aims to strengthen the continent's industrial base, drive innovation, and safeguard strategic autonomy.
Open-Source Silicon Initiative Aims to Bolster Hardware Trust
Imagine having a tiny chip inside your device that you can trust completely - one that's transparent, secure, and designed to put your mind at ease. The Baochip-1x, a groundbreaking open-source silicon project by Andrew Bunnie Huang, aims to provide just that, giving developers an affordable and security-focused solution for building high-assurance embedded devices.

Mythos Exposes Software Backlog, Pressures Vendors on Patching
The Claude Mythos Preview has uncovered a harsh reality: artificial intelligence can spot long-known software defects faster than teams can fix them, revealing a massive backlog of vulnerabilities that could leave businesses exposed. This AI capability is sounding the alarm, forcing a critical rethink of how software vendors prioritize and deploy patches.

Pentagon Seeks Massive Munitions Boost Amid Industry Capacity Questions
The Pentagon is making a bold move, seeking a massive 188% boost in missile procurement, with a whopping $70.5 billion earmarked for munitions in its FY27 budget request. But can the industry keep pace, and how quickly can this ambitious plan translate into operational stockpiles?

Satellite Imagery Firm Curtails Mideast Coverage Amid Iran War
A commercial satellite-imagery firm, Planet, has started withholding images of the Middle East, including Iran and nearby conflict zones, for a 14-day delay - raising questions about who gets to know what, and when. This private policy change has significant public implications, especially amid rising tensions in the region.
OpenAI Rushes Updates for Mac Apps After Axios Hack Compromise
OpenAI recently issued urgent updates for its Mac apps after a developer tool inadvertently pulled in a malicious library, highlighting the risks of supply-chain vulnerabilities. Fortunately, the company assured that its systems and software integrity remained intact despite the incident.

France Accelerates Exodus from US Tech with Open-Source Push
France is taking a bold step towards digital independence, with a push to ditch American commercial software for open-source alternatives, and all government ministries are now racing against the clock to reduce their reliance on US tech by the fall. This move signals a growing unease among European governments about Silicon Valley's influence.

Impersonator Exploits Slack to Target Linux Developers
A clever impersonator tricked Linux developers on Slack by posing as a trusted official, leading them to click a link that seemed harmless but actually handed over their credentials and development environment. This sneaky attack used Google-hosted pages to disguise a bogus root certificate, catching developers off guard.

OpenAI Revokes macOS Certs Amid Supply Chain Breach Fallout
A recent supply chain breach has raised concerns about software trustworthiness, prompting OpenAI to revoke its macOS code-signing certificates after a malicious package was executed in its build pipeline. This swift action highlights the vulnerability of even the most secure systems to supply chain attacks.

FBI Disrupts W3LL Phishing Operation Linked to $20m in Fraud
The FBI has successfully dismantled a massive phishing operation built around the notorious W3LL phishing kit, which was linked to a staggering $20 million in fraud attempts. By taking down this operation, the bureau has disrupted a key tool used by cybercriminals to carry out their scams.

Rockstar Games Data Breached as ShinyHunters Exploits Third-Party Vulnerability
Rockstar Games has been hit by a data breach, with a notorious hacking group called ShinyHunters claiming it accessed sensitive information through a vulnerability in a third-party tool, rather than a complex hack. The group says it simply walked through an open door, exploiting access to Snowflake metrics to get to the data.

Lockheed Martin Expands Australian Missile Production
Lockheed Martin is taking a major step forward in Australian missile production, having successfully test-fired GMLRS rockets assembled in Australia - a milestone that marks a significant boost to the country's defense capabilities. But what does it really mean for a missile to be Australian-made when critical parts still come from overseas?

OpenAI Disrupts macOS App Signing Process After Supply Chain Breach
OpenAI recently took swift action to protect its users by revoking a macOS app certificate after discovering a malicious library had been downloaded through a GitHub Actions workflow used to sign its applications. This move highlights the vulnerability of even trusted software signing processes to supply chain breaches, and the importance of staying vigilant in macOS app security.