Tag: supply chain
830 articles

GitHub Actions Expose Vulnerability in CI/CD Pipelines
A single misstep in a GitHub Actions workflow can become a four-step chain to permanent credential exposure, putting your entire CI/CD pipeline at risk. Researchers have uncovered a class of vulnerabilities, dubbed Cordyceps, that can be exploited in a surprisingly simple way.

UK Government's Cyber Resilience Pledge Gains 60 Signatories
The UK government's Cyber Resilience Pledge has gained momentum with 60 signatories, demonstrating a united front against cyber threats. By signing the pledge, businesses acknowledge that cyber resilience is a top priority, not just an IT issue, but a business imperative.

UK Government Unveils Cyber Resilience Pledge with Over 60 Signatories
Joining forces to combat cyber threats, the UK government has launched a groundbreaking Cyber Resilience Pledge, signed by over 60 organisations, to strengthen board-level accountability and supply chain security. By making three key commitments, signatories can bolster their defences and stay ahead of emerging threats.

Adobe ColdFusion Flaw Exploited in Targeted Attacks
With 775 exposed ColdFusion instances online, a newly patched flaw is being exploited by attackers, putting countless systems at risk. Adobe has urgently warned customers to apply updates immediately to protect against this and 10 other critical vulnerabilities.

Democracies Need Critical-Minerals Stockpile Alignment
Democratic governments are taking a proactive approach to securing their critical mineral supplies, with Australia's recent announcement of a Critical Minerals Strategic Reserve being the latest example. This move is part of a growing trend to build resilience and reduce reliance on vulnerable supply chains dominated by a single country.

Microsoft Teams Abused to Deploy EtherRAT Malware via Fake IT Support Calls
Beware of fake IT support calls on Microsoft Teams - hackers are using convincing tactics, including a phishing email with a malicious PDF, to trick victims into downloading the potent EtherRAT malware. They impersonate system administrators to gain your trust, making it crucial to stay vigilant.

Phishing Campaign Targets Google Accounts with Fake Job Interviews
Beware of fake job interviews that could be phishing scams! A clever new campaign is targeting marketing pros with emails that appear to be from recruiters, aiming to trick them into handing over their Google account credentials.

Threat Actors Probe Gitea Docker Flaw Just 13 Days After Patch
Security researchers have spotted threat actors probing a critical Gitea Docker flaw just 13 days after it was patched, highlighting the urgent need for users to update their systems. This highly vulnerable flaw, scoring 9.8, allows attackers to exploit a default setting that trusts user headers from any source IP address.

Adobe ColdFusion Flaw Exploited in Ongoing Attacks
A critical Adobe ColdFusion vulnerability, CVE-2026-48282, is under attack - and it's crucial to patch now to prevent remote code execution on your system. This maximum-severity flaw affects ColdFusion releases 2025.9, 2023.20, and earlier, and can be exploited without privileges.

China-nexus Hackers Deploy DcRAT via Fake Indian Tax Utility
Cyber attackers with ties to China are pulling out all the stops to scam Indian taxpayers, using a sophisticated fake tax utility to deploy malware and pilfer sensitive info. Their precision-crafted phishing campaign, dubbed Operation DragonReturn, sends convincing emails and PDFs that even cite real laws to trick victims.

TrojPix Exploits Video Cables to Leak Air-Gapped Data
Meet TrojPix, a sneaky technique that can stealthily siphon air-gapped data at lightning-fast speeds of up to 1 megabyte per second - fast enough to exfiltrate a 100MB file in under two minutes while the monitor appears dark and inactive.

Opera GX Flaw Enables Silent Mod Installs to Steal User Data
Researchers have discovered a security flaw in Opera GX that allows for silent mod installs, potentially putting user data at risk, and surprisingly, this vulnerability can be exploited with just a single page visit. This alarming issue enables malicious mods to be installed without user consent, highlighting a concerning gap in the browser's security.

Ransomware Operation Exploits AI to Automate Cyberattack
Meet JadePuffer, a notorious ransomware operation that's taking cyberattacks to the next level with the power of AI, automating attacks with ease. In a shocking example, JadePuffer used a large language model agent to encrypt a staggering 1,342 Nacos service configuration items.

North Korean Hackers Publish 108 Malicious Packages in PolinRider Campaign
North Korean hackers have unleashed a massive wave of malware, publishing 108 malicious packages and web browser extensions across popular platforms like npm, Packagist, Go, and Google Chrome as part of their sneaky PolinRider campaign. This ongoing operation has already produced 162 malicious release artifacts and compromised thousands of systems worldwide.

North Korea-Linked npm Packages Target Developers with Stealthy Data Theft
Malicious npm packages, linked to North Korean threat actors, are impersonating popular tools to trick developers into handing over sensitive data. These sneaky packages masquerade as legitimate polyfill tools, making them hard to spot during a quick review.

AdaptHealth Breach Exposes Patient Data via Social Engineering Tactics
AdaptHealth recently fell victim to a data breach, where hackers used clever social engineering tactics to trick a third-party contractor into giving them access to sensitive patient information stored in the company's cloud environment. This alarming breach put a large volume of patient data at risk, prompting AdaptHealth to disclose the incident to the Securities and Exchange Commission.

Ransomware Gang Exploits Supply Chain Attacks in New Partnership
Ransomware gangs are now operating like businesses, forming partnerships to supercharge their attacks - and a new alliance between Vect and TeamPCP is a prime example, combining massive credential theft with devastating ransomware-as-a-service operations. This unprecedented pairing puts organizations directly in the crosshairs.

Pentagon Struggles to Meet Weapons Delivery Timelines, GAO Warns
The Pentagon is facing a major challenge in delivering new military capabilities on time, with a staggering 12-year average delay in bringing vital projects to fruition, according to a damning new report from the Government Accountability Office. This alarming trend reveals a worrying pattern of slow progress and broken promises of rapid fielding.

Ransomware Groups Exploit Citrix Bleed 2 in Supply Chain Attacks
Ransomware groups are exploiting the Citrix Bleed 2 vulnerability to launch devastating supply chain attacks, using legitimate remote access tools to spread their reach. This critical flaw has already been linked to multiple ransomware families, including Anubis, which has claimed 91 victims so far.

FortiBleed exposes link between ransomware gangs
A major breakthrough in the fight against ransomware has been uncovered, revealing a direct link between ransomware gangs and the recent FortiBleed attack. Researchers have found a single operator working with multiple ransomware groups, using infrastructure tied to FortiBleed.

FortiBleed Exposes Link to Ransomware Ops
A shocking new report reveals that the notorious FortiBleed vulnerability has a direct link to ransomware operations, with a key player found negotiating with both groups. This alarming connection has led to at least 12 ransomware deployments and hundreds of encrypted endpoints.

ChocoPoC Malware Targets Vulnerability Researchers via Fake PoC Repos
Beware of fake proof-of-concept repositories on GitHub - a new malware called ChocoPoC is hiding in plain sight, stealing data from vulnerability researchers through a cleverly designed trap. This sneaky malware uses a dependency chain to infect systems, masquerading as a harmless Python proof-of-concept exploit.

Physical Security Lapses Grant Hackers Network Admin Access
Meet Kristopher Johnson and Michael, two expert red teamers who walked into a company's office through an unlocked maintenance door, posing as new IT employees, and gained access to the building by simply offering to help shovel ice. Their easy entry exposed a shocking truth: physical security lapses can give hackers an open invitation to wreak havoc on your network.

China's Military Bets Big on AI for Logistics Overhaul
China is revolutionizing its military logistics with a bold bet on artificial intelligence, aiming to transform the way it supplies and supports large-scale operations. By fusing AI with logistics, China seeks to overcome the challenges of sustaining forces under intense pressure.