Tag: supply chain
826 articles

Chinese Spies Exploit Roundcube Flaw to Breach University Servers
A recent series of university server breaches, attributed to a group called UNK_MassTraction, has exposed vulnerabilities in North American higher-education institutions, with potentially dozens more affected. The breach, linked to a flaw in Roundcube, is believed to be an ongoing campaign.

Paris Peace Forum Launches Global Hub to Track AI Cyber Threats
The Paris Peace Forum is tackling the growing threat of AI-driven cyber attacks by launching INTAiC, a groundbreaking global hub that unites experts from two previously separate spheres: network defense and AI security. By bridging this gap, INTAiC aims to provide a unified front against the evolving risks to global internet infrastructure.

Hackers Exploit Roundcube Flaw to Target Academic Researchers
A new wave of cyber attacks linked to China is targeting academic researchers in the US and Canada, specifically those in physics, engineering, and national security-related fields, by exploiting a vulnerability in Roundcube webmail servers. The campaign, tracked as 'UNK_MassTraction', has been ongoing since May and has already hit several universities.

Phishing Campaign Targets Microsoft 365 Users with Voice-Based Entra Passkey Scam
Beware of scammers impersonating Microsoft 365, tricking users into enrolling a fake Entra passkey by mimicking the real enrollment portal and leveraging voice calls to urge action. This sneaky phishing campaign has been targeting multiple sectors since April, putting unsuspecting users at risk.

Anthropic's Claude Code Exposes Security Risk, China Alleges
A Chinese cybersecurity group has raised a red flag about a potential backdoor security risk in Anthropic's Claude Code, warning that certain versions can secretly send sensitive user data to remote servers without consent. This alarming claim puts users' identity and location information at risk.

Accenture Breach Exposes Source Code, Heightens Supply Chain Risk
Accenture's recent data breach, where 35GB of sensitive data including source code was stolen, shines a spotlight on the hidden risks of working with major consulting and services firms. As a trusted partner to businesses and governments worldwide, Accenture's breach heightens concerns about supply chain vulnerabilities.

AI Coding Agents Expose Unix-Era Security Flaw
A clever trick that exploits a long-standing Unix security flaw, dubbed GhostApproval, can bypass human approvals in AI coding assistants, rendering consent meaningless. By manipulating a harmless-looking project file, attackers can secretly alter sensitive system settings.

Turkish Defence Firms Penetrate NATO Markets Amid European Rearmament Push
Turkish defence firms are making a major breakthrough into NATO markets, with record exports of over $10 billion in 2025, and sales to Europe and the US nearly quadrupling to $5.6 billion. Turkish companies are now supplying top NATO nations like Poland, Spain, Portugal, and Romania with cutting-edge military hardware.

China Warns of Claude Code Backdoor Risks, Urges Developers to Uninstall
China's National Vulnerability Database has issued a high-priority alert, warning developers to immediately uninstall certain versions of Claude Code due to a potential backdoor risk that could compromise sensitive data. Upgrade to the latest secure version to safeguard your information.

Australia Exposed to Uyghur Forced Labour Imports
Australia's imports from China have raised red flags, with a staggering $6.95 billion worth of goods from high-risk sectors linked to Uyghur forced labour flooding the market in 2024. This exposes the country to a redirected risk of inadvertently supporting human rights abuses through its supply chains.

GitHub Verified Commits Can Be Rewritten Without Breaking Signatures
A recent study revealed a surprising vulnerability in GitHub's verified commits, showing that signed commits can be rewritten without breaking their digital signatures. This means that tampered code can still be labeled as Verified, posing a significant risk to code security.

Ubiquiti Discloses Max-Severity UniFi OS Vulnerability
Ubiquiti has urgently patched a critical vulnerability in its UniFi OS, warning customers of a maximum-severity flaw that could allow malicious actors to inject commands on host devices - and it's crucial to upgrade to version 3.4.20 or later to stay safe.

Pacific Seabed Becomes Contested Zone in Regional Power Struggle
The Pacific seabed, once a vast and empty space, has become a hotly contested zone as a growing number of nations and interests converge on its valuable resources, transforming the way power and risk are distributed in the region. This emerging crowded landscape is sparking new tensions, as mining, military operations, and other activities increasingly overlap and collide.

Malicious Activity on Industrial Systems Declines to 3-Year Low
Malicious activity on industrial systems has hit a 3-year low, with only 19.6% of ICS computers encountering malicious objects in Q1 2026 - a significant drop of 1.4 times from Q2 2023. However, beneath the calm surface, localized spikes of threats persist, warranting close attention.

Microsoft Telemetry Fingers Scattered Spider Suspect in US Crackdown
Microsoft's sharp-eyed telemetry has helped track down a suspect linked to the notorious Scattered Spider group, a prolific gang that allegedly raked in over $100 million in ransom payments by infiltrating more than 100 US company networks.

GitHub AI Agent Exposes Private Repos to Malicious Prompts
A shocking vulnerability in GitHub's AI-powered Agentic Workflows has been discovered, allowing attackers to expose private repositories with just a cleverly crafted issue and some plain English instructions - no coding skills or credentials required. This flaw lets hackers fetch and publicly share sensitive files, putting organizations at risk.

Google Dialogflow Flaw Lets Rogue Agents Hijack Chatbots
A security flaw in Google Dialogflow, dubbed "Rogue Agent," allowed hackers to hijack chatbots, but thankfully, a fix was rolled out after Varonis reported the issue through Google's Vulnerability Reward Program. The flaw was cleverly exploited through custom Code Blocks in Dialogflow CX, highlighting the importance of robust security measures in chatbot development.

GitHub Agentic Workflows Exposed to Data Leak Threat via Public Issues
GitHub's Agentic Workflows are vulnerable to a data leak threat, as researchers have demonstrated a clever technique called GitLost that tricks AI agents into spilling private content from secure repositories into public comments. All it takes is a simple public issue to launch the attack, with no stolen credentials or special access required.

China-Aligned Hackers Exploit Roundcube Servers at US, Canada Universities
China-aligned hackers are targeting universities in the US and Canada, exploiting vulnerable Roundcube webmail servers to gain access to sensitive physics and engineering departments with potential national security links. This latest campaign highlights the ongoing threat of email-based attacks and the need for robust server security.

China-Aligned Hackers Exploit Roundcube Flaws to Infiltrate Universities
China-aligned hackers have launched a sneaky attack on universities, exploiting two flaws in the popular Roundcube webmail client to steal credentials and gain persistent access. At least a few dozen universities are believed to be affected, with Proofpoint researchers confirming fewer than 10 intrusions so far.

GitHub Actions Expose Vulnerability in CI/CD Pipelines
A single misstep in a GitHub Actions workflow can become a four-step chain to permanent credential exposure, putting your entire CI/CD pipeline at risk. Researchers have uncovered a class of vulnerabilities, dubbed Cordyceps, that can be exploited in a surprisingly simple way.

UK Government's Cyber Resilience Pledge Gains 60 Signatories
The UK government's Cyber Resilience Pledge has gained momentum with 60 signatories, demonstrating a united front against cyber threats. By signing the pledge, businesses acknowledge that cyber resilience is a top priority, not just an IT issue, but a business imperative.

UK Government Unveils Cyber Resilience Pledge with Over 60 Signatories
Joining forces to combat cyber threats, the UK government has launched a groundbreaking Cyber Resilience Pledge, signed by over 60 organisations, to strengthen board-level accountability and supply chain security. By making three key commitments, signatories can bolster their defences and stay ahead of emerging threats.

Adobe ColdFusion Flaw Exploited in Targeted Attacks
With 775 exposed ColdFusion instances online, a newly patched flaw is being exploited by attackers, putting countless systems at risk. Adobe has urgently warned customers to apply updates immediately to protect against this and 10 other critical vulnerabilities.