Tag: supply chain
853 articles

Oracle E-Business Suite Flaw CVE-2026-46817 Sees Active Exploitation
A critical flaw in Oracle Payments, known as CVE-2026-46817, is being actively exploited by hackers, allowing them to easily take control of vulnerable Oracle E-Business Suite instances. This easily exploitable vulnerability has a near-perfect CVSS score of 9.8, making it a high-risk threat to organizations using Oracle Payments.

Nissan Breach Exposes Employee Data After Oracle PeopleSoft Exploit
Nissan confirmed a data breach exposing employee information after a cyberattack exploited a critical vulnerability in Oracle PeopleSoft, part of a larger campaign that may have compromised hundreds of companies. The breach was tied to a specific threat actor targeting Nissan's personnel records.

ShinyHunters Breach Exposes NAIC's Public Data
The National Association of Insurance Commissioners (NAIC) revealed that a breach exposed its public data after an unauthorized third party exploited a PeopleSoft vulnerability, identified as CVE-2026-35273, tied to the notorious ShinyHunters extortion group. This security issue allowed attackers to gain access to a portion of NAIC's IT systems, compromising sensitive information.

US Engine Deal Propels India's Fighter Jet Ambitions
India's quest for self-reliant fighter modernization has hit a major roadblock: the elusive jet engine, and now a deal with US manufacturer General Electric for 15 F414 engines to power its Advanced Medium Combat Aircraft prototypes has seen costs triple. This development cements America's grip on India's indigenous fighter ecosystem for decades to come.

Russia Arms Commercial Tanker with Heavy Machine Guns
Meet the Marshal Vasilevskiy, a 945-foot LNG tanker that's moonlighting as a heavily armed behemoth, sporting sandbagged machine-gun positions on its deck. This unusual floating fortress is Russia's only floating storage and regasification vessel, supplying the exclave of Kaliningrad with a secure gas supply.

Human Error Exposes Security Breaches Despite AI Advances
Despite advancements in AI, human error continues to expose security breaches, as seen in a recent Salesforce supply-chain compromise where a legacy credential was exploited. A company called Klue, which integrates with Salesforce, was compromised when attackers used OAuth tokens to access customer data.

Hackers Exploit Oracle E-Business Flaw in Targeted Attacks
Hackers are actively exploiting a critical Oracle E-Business flaw, CVE-2026-46817, with a near-perfect CVSS score of 9.8, in targeted attacks, allowing for unauthenticated HTTP takeover. This alarming vulnerability has no known previous exploitation and no public proof-of-concept code exists, making it a high-risk threat.

Credentials Face Quantum Threat Decades Ahead
The NSA has set a critical deadline: by January 1, 2027, new national security systems must support quantum-resistant algorithms to stay ahead of emerging threats. With deadlines stretching into the 2030s, organizations must plan now to protect their systems from the looming quantum threat.

Nissan Discloses Oracle PeopleSoft Breach Exposing Payroll Records
Nissan has alerted the California Attorney General to a potential data breach, revealing that a cyber attack on Oracle PeopleSoft systems may have exposed sensitive payroll records of hundreds of companies, including Nissan, from May 27 to June 9. The automaker believes it was specifically targeted in the attack, which may have compromised a range of personnel data.

Russia Targets Jaguar Land Rover in Economically Destructive Cyber-Attack
Russian hackers allegedly launched a devastating cyber-attack on Jaguar Land Rover, causing a staggering £1.9bn hit to the British economy. This brazen breach is just the latest example of nation states using underhanded tactics to wreak havoc on a global scale.

Malware Exploits VS Code Tasks in Hijacked Packages
Researchers have uncovered a sneaky malware attack that hides in Visual Studio Code tasks, masquerading as a harmless "eslint-check" task that springs into action the moment you open a compromised package directory in VS Code. The malware cleverly disguises its executable payload as a font file, allowing it to slip past defenses undetected.

Russia Targets Messaging Credentials with Fake Support Texts
Beware of fake support texts that could compromise your personal data and sensitive information! A joint investigation by the Security Service of Ukraine and the FBI uncovered a systematic campaign to steal messaging platform credentials from government officials, military personnel, and activists worldwide.

China Dominates Argentina's Squid Fleet
Imagine a foreign power controlling nearly two-thirds of a nation's prized fishing fleet - in this case, Chinese companies hold the reins over Argentina's lucrative squid industry. This unprecedented level of ownership sparks questions about the impact on local communities, regulatory oversight, and the future of Argentina's seafood supply chain.

GitHub Repos Used to Deploy Malware via AI Coding Tools
Imagine a GitHub repository that looks perfectly safe, yet can secretly deploy malware on a developer's device - all without triggering any red flags. Researchers have demonstrated just how easily this can happen, using an AI coding agent to run a malicious payload hidden in a seemingly clean project.

AI Exposes Thousands of Open-Source Vulnerabilities
This summer is shaping up to be a wild ride, with thousands of open-source vulnerabilities exposed and a new coalition, Athena, stepping in to save the day with AI-powered solutions. Led by Chainguard, Athena brings together over two dozen major companies to tackle the problem head-on.

Massive Passport Leak Exposes Sensitive Traveler Data
A staggering leak of almost a million passport records from around the world has put sensitive traveler data at risk. The breach, linked to a low-security ID verification system for cannabis dispensaries, exposed passports as a vulnerable weak point in authentication processes.

Threat Actors Exploit OpenAI Invitations to Target Cybersecurity Firms
Threat actors are cleverly exploiting OpenAI invitations to scam cybersecurity firms, creating fake tenants that mimic legitimate companies and sending convincing emails that pass authentication checks. These targeted phishing attacks allow scammers to spread malicious content through a trusted channel.

India Accelerates Drone Production Amid Regional Security Push
India is taking a cue from Ukraine's playbook, aiming to turbocharge its drone production to marry mass manufacturing with real-time battlefield feedback, and transform its national industrial policy. By leveraging policy tools like import curbs, the Production Linked Incentive scheme, and the Drone Shakti Mission, New Delhi is aggressively pushing to become a major drone producer.

AM General Counters JLTV Funding Threat with Transition Woes
AM General is pushing back on lawmakers' plans to cut funding for the Joint Light Tactical Vehicle (JLTV) program, citing the complexities of transitioning major defense production from one manufacturer to another. The company attributes delivery delays to a tough handoff, inheriting an uncertain technical baseline and navigating supplier transition issues.

Texas Hunting License Data Breach Exposes Millions
A recent data breach at the Texas Parks and Wildlife Department may have exposed over three million hunting and fishing license customers, putting sensitive information like driver's license numbers and passport data at risk of being used for account takeover, synthetic identity fraud, and targeted phishing. This breach is just the beginning, as stolen data can be used for a range of malicious activities.

Amazon AI Coding Tool Exposes Cloud Credentials to Malicious Git Repos
A security vulnerability in Amazon's AI coding assistant, tracked as CVE-2026-12957, allowed malicious Git repositories to access sensitive cloud credentials, raising concerns about informed consent and user security. The flaw enabled automatic execution of commands with no user prompt required.

Amazon Q Developer Flaw Lets Malicious Repos Run Code via MCP Configs
A high-severity flaw in Amazon Q Developer, tracked as CVE-2026-12957, allowed malicious repositories to run commands and steal cloud credentials simply by being opened in an IDE. This vulnerability put developers at risk of having their sensitive AWS keys, cloud CLI tokens, and API secrets compromised.

CISA Flags Exploited PTC Windchill Flaw Amid Web Shell Attacks
PTC has confirmed that attackers are exploiting a high-severity flaw, CVE-2026-12569, in its Windchill software to drop malicious web shells on vulnerable systems, allowing them to execute arbitrary code remotely. The company has reported heightened threat activity, urging users to take immediate action to protect themselves.

Miasma Malware Poisons Over 20 npm Packages
In a lightning-fast attack, hackers poisoned over 20 npm packages with Miasma malware, completing the coordinated operation in under three seconds. The attackers compromised an npm maintainer account to publish tainted updates to popular packages.