Tag: supply chain
871 articles

CPUID Compromised, Trojanized Software Deploys STX RAT
For one day in April, unsuspecting users who visited CPUID.com, a trusted site for hardware-monitoring tools, unknowingly downloaded trojanized software that deployed a malicious remote access trojan called STX RAT. The compromised software, including CPU-Z and HWMonitor, turned a trusted resource into a malware delivery vehicle.

Compromised Plugin Update Injects Backdoor into WordPress Sites
A widely used WordPress plugin, Smart Slider 3 Pro, was compromised when hackers hijacked its update system to push a poisoned version containing a backdoor, putting over 800,000 active installations at risk. This alarming breach raises critical questions about trust and security in the mechanisms we rely on to protect our online presence.

Leidos, Defense Unicorns to Validate Navy Ship Software Prototypes
The Navy has taken a crucial step in bringing innovative shipboard software to life by partnering with Leidos and Defense Unicorns to test and validate cutting-edge prototypes in a controlled lab environment. This strategic move aims to mitigate risks and ensure seamless integration of new systems at sea.

Australia's AFV Maintenance Plan Sparks Logistical Concerns
Sending armoured fighting vehicles to a distant repair hub raises eyebrows - it's like shipping Ukraine's tanks to Paris for a tune-up, an arrangement that's both illogical and unacceptable. Australia's plan to sustain its AFVs far from their base in Townsville is being called into question.

Quantum Computing Advances Accelerate Push to Secure Data
The timeline for securing our digital world is rapidly shrinking, driven by a triple threat of lightning-fast advances in quantum computing hardware, groundbreaking mathematical discoveries, and growing concerns about China's scientific progress. This perfect storm is pushing tech giants to urgently migrate to quantum-proof systems.

Court Upholds Pentagon Ban on Anthropic AI Models
In a significant ruling, a federal appeals court has sided with the Pentagon, allowing it to ban Anthropic's advanced AI models, including Claude, from defense contracts due to supply-chain risk concerns. This decision deals a blow to Anthropic's ambitions in the national defense space, at least for now.

AI Tools Accelerate Healthcare Cyber Threats, Experts Warn
As AI tools become more advanced, experts warn that they can also supercharge healthcare cyber threats, autonomously identifying and exploiting software flaws at unprecedented speeds. This could lead to a dramatic surge in attacks on hospitals, clinics, and patients, making the threat landscape more treacherous than ever.

Chinese Supercomputer Breach Exposes Massive 10-Petabyte Data Heist
A massive 10-petabyte data heist has been reported from a state-run Chinese supercomputer, raising urgent questions about the breach and its potential consequences. The staggering scale of the alleged theft has sparked widespread concern, but details about the incident remain scarce.

Hackers Exploit Smart Slider Plugin to Deploy Malicious Code
Hackers have hijacked the update system for the popular Smart Slider 3 Pro plugin, deploying a malicious release that lets them take control of affected websites. This alarming breach highlights the vulnerability of even trusted software update channels to exploitation.

Microsoft Abruptly Bans Top Open-Source Developers
Imagine being a leading open-source developer, only to be suddenly and silently locked out of your Microsoft developer account, with no warning, no emails, and no human contact - just automated blocks and a lengthy appeal wait. This is what recently happened to the creators of VeraCrypt and WireGuard, leaving their critical projects in limbo.

Zephyr Energy Hit by $900K Cyber Heist via Contractor Payment Redirect
Zephyr Energy plc lost a staggering £700,000 in a shocking cyber heist, where attackers cleverly redirected a single payment meant for a contractor into their own account. This brazen attack serves as a stark reminder of the devastating consequences of cyber risk.

Google Exposes New Extortion Group Targeting BPOs and Helpdesks
A new extortion group, uncovered by Google's threat intelligence team, is setting its sights on Business Process Outsourcing (BPO) companies and helpdesks, posing a significant threat to the service layers that many businesses rely on. This emerging threat, possibly linked to the notorious "Raccoon" persona, has the potential to create widespread pressure points across multiple organizations.

Malicious Code Infiltrates Python Package Index
A recent supply-chain attack on a popular Python package has raised a critical question: how much trust do you really have in the software that quietly powers your work? A malicious .pth file hidden in the litellm package version 1.82.8 can automatically execute malicious code on every Python startup.

OT Cybersecurity Sector Fears AI Exclusion
As artificial intelligence revolutionizes software security, the operational technology cybersecurity sector is sounding the alarm: will experts who safeguard factories, grids, and industrial sites be left behind? Pure-play OT security firms are pushing for a seat at the table, fearing they may be sidelined by the latest AI-driven initiatives.

Hackers Conceal Credit Card Stealer in Tiny SVG Images
One tiny pixel can cause massive damage: hackers have successfully hidden credit card-stealing code inside a nearly invisible, one-pixel Scalable Vector Graphics (SVG) image, putting almost 100 Magento-based online stores at risk. This sneaky tactic allowed the malicious code to blend in with normal site assets, evading detection.

France Fortifies Solar Sector with Curbs on Chinese Components
France is taking a bold step towards a cleaner future by launching a new wave of government-backed solar energy projects, while also setting strict rules to exclude Chinese-made photovoltaic components and ensure top-notch cybersecurity. By combining protectionist measures with tough tech requirements, Paris is pushing the boundaries of how nations can promote renewable energy while safeguarding their interests.

Apache ActiveMQ Flaw Exposes Systems to Remote Code Execution
A critical security flaw in Apache ActiveMQ Classic, hidden for over 13 years, allows remote code execution, putting vulnerable systems at risk of arbitrary command execution. This long-undetected vulnerability highlights the importance of staying vigilant and proactive in identifying and addressing potential security threats.

CISA Warns of Iranian Cyber Actors Targeting US Infrastructure
The Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm: Iranian-linked cyber actors are targeting US critical infrastructure, posing a threat to public safety, services, and commerce. American organizations must take immediate action to assess their risk and bolster defenses.

Ransomware Attack Cripples Dutch Healthcare Software Vendor ChipSoft
A ransomware attack has taken down ChipSoft, a Dutch healthcare software vendor, leaving many questions unanswered - but one thing is certain, the company's website is currently offline and its email system is still functioning. The extent of the damage and the identity of the perpetrators remain unclear.

Anthropic's AI Model Exposes Thousands of Zero-Day Flaws in Major Systems
Anthropic's cutting-edge AI model, Claude Mythos, has made a groundbreaking discovery - uncovering thousands of zero-day flaws in major systems, giving us a glimpse into the hidden vulnerabilities of our digital world. This breakthrough is the result of Anthropic's innovative Project Glasswing initiative, which aims to revolutionize cybersecurity.

Myanmar Junta Exploits Shadow Networks for Jet Fuel Lifeline
In a desperate bid to maintain its grip on power, Myanmar's junta relies on a clandestine network to keep its aircraft fueled and flying, delivering devastating air strikes on its own people. A recent investigation, From Tehran to Naypyidaw, exposes the shadowy supply chains that provide the regime's strategic lifeline: imported jet fuel.

Askul ransomware attack: Stunning, Risky supply-chain hit
When Muji paused online orders after logistics partner Askul was hit by ransomware, it exposed a stark truth: a single third-party breach can freeze entire retail operations. This outage is a wake-up call for brands to map dependencies, tighten vendor security, and treat supply-chain risk as an ongoing priority.

Linux rootkits: Stunning, Dangerous Threats
From F5 supply-chain compromises to stealthy Linux kernel rootkits and pixnapping of media, attackers are increasingly able to live unseen inside systems for months. Now more than ever, teams should treat vendor appliances as high-risk, elevate kernel-level detection, and assume breach to stop quiet, long-lived exfiltration.

firewall vulnerabilities: Exclusive Risky Flaws Exposed
Senator Cassidy has blasted Cisco with a pointed letter after critical firewall flaws were reportedly used to breach at least one federal agency, asking whether the vendor delayed disclosure or patches while networks stayed exposed. His probe spotlights urgent questions about vendor transparency, coordinated disclosure, and who’s accountable when core defenses fail.