Tag: supply chain
853 articles

Miasma Malware Targets npm, GitHub in Expanded Supply Chain Attack
Over 550 GitHub repositories have been compromised in a massive supply-chain attack, with malware harvesting developer credentials and spreading across package registries and workflows. The attack has already infected numerous npm packages and one Go module, putting developer data at risk.

Pentagon Rallies New Defense Firms to Boost Munitions Production
The Pentagon has taken a proactive approach to ramping up munitions production by convening a closed-door meeting with emerging defense firms, including Anduril, Castelion, CoAspire, and Leidos, to discuss accelerating production in response to current global threats. Top defense officials, such as Defense Secretary Pete Hegseth, were in attendance to drive this crucial initiative forward.

Huntress Insider Leak Exposes Potential Security Breach
A shocking security breach at Huntress has come to light, with a former analyst claiming that a colleague may have compromised the company's integrity by passing sensitive law enforcement communications to a notorious cybercriminal. The explosive allegations have left many questions unanswered about the breach and its potential impact.

Army Expands Digital Marketplace for Global Materiel Buys
Imagine a digital storefront where soldiers, allies, and partners can easily find and acquire the best materiel, with reviews and ratings guiding their choices - that's the vision Army Secretary Dan Driscoll shared for a single, global digital marketplace. This platform would prioritize interoperability, harnessing the power of free market forces to drive innovation and excellence.

US Defense Base Exposes Strategic Vulnerability
With US President Donald Trump invoking the Defense Production Act, the Department of Defense can now collaborate with private providers to speed up supply chains and address critical bottlenecks. This move comes as global alliances shift, with North Korea's recent endorsement of China's "One China" principle raising questions about the region's future dynamics.

Google Warns of Cisco Vulnerability Exploited as Zero-Day Months Before Disclosure
Google sounded the alarm on a Cisco vulnerability that was exploited as a zero-day months before its disclosure, putting users of Cisco Catalyst SD-WAN products on high alert. This critical flaw, tracked as CVE-2026-20245, allows authenticated local attackers to wreak havoc due to insufficient validation of user input in the command-line interface.

Cisco SD-WAN Zero-Day Exploited for Root Access
A shocking new discovery reveals that a Cisco SD-WAN zero-day vulnerability, CVE-2026-20245, was exploited for root access at least two months before its public disclosure. This highly critical flaw, with a CVSS score of 7.8, allows attackers to execute arbitrary commands with elevated privileges.

Hackers Exploit Cisco Zero-Day for High-Level Access at Telecom Provider
In a chilling cyberattack, hackers exploited a previously unknown Cisco zero-day vulnerability to gain unrestricted access to a major telecom provider's system, creating a rogue admin account with full control. The breach, detected in March, was carried out in two waves, allowing the attackers to infiltrate the provider's SD-WAN Manager devices.

Mandiant Exposes Cisco SD-WAN Zero-Day Attacks' Root Access Methods
Cisco's SD-WAN system was exploited in active attacks using a high-severity flaw, allowing hackers to create a rogue root account and take full control of targeted devices. This vulnerability, tracked as CVE-2026-20245, was triggered through a simple tenant-upload feature in the command-line interface.

Threats Expose Gaps in US Air-and-Missile-Defense Industrial Base
The US air-and-missile-defense system is struggling to keep up with today's threats, revealing gaps in real time, because its industrial base was designed for a bygone era. It's clear that we need a new approach, with more innovators and fresh ways to design, build, and deploy critical technologies like munitions and hypersonics.

Governments Struggle to Secure Open-Source Software
The alarming reality is that years of underinvestment in open-source software security are catching up with us, with a new supply chain compromise emerging almost every week. A recent scan by Project Glasswing found over 6,000 high-risk vulnerabilities in popular open-source projects, but only a tiny fraction have been patched.

Air Force Weighs $1.5B Engine Deal with GE in T-7 'Horse Trade
The US Air Force is considering a game-changing $1.5 billion engine deal with GE Aerospace, a move that could significantly impact the T-7 Red Hawk program. This potential shift could add up to $1.5 billion in extra costs, but may also bring new efficiencies to the program.

Cordyceps Flaws Compromise 300+ GitHub Repositories
A newly discovered flaw, dubbed Cordyceps, has left over 300 GitHub repositories vulnerable to exploitation by unauthenticated users, allowing for code execution, credential theft, and supply-chain compromise. This critical weakness can be easily exploited, putting countless open-source projects at risk.

Social Engineering Attacks Target Service Desks
Service desks have become a prime target for cyber attackers, who often find it easier to manipulate staff into divulging sensitive information than to crack the technology itself. In a string of recent incidents, hackers have successfully impersonated employees to gain access to internal systems, as seen in the 2025 UK attacks on major retailers like Marks & Spencer, Co-op, and Harrods.

Mistic Backdoor Enables Long-Term Access in Ransomware Attacks
Cyber attackers have deployed a sneaky backdoor called Mistic, allowing them to maintain long-term access to infected systems during ransomware attacks, all while staying remarkably under the radar. This stealthy threat uses clever tactics like running payloads in memory and mimicking legitimate Microsoft security tools to evade detection.

Tata Electronics Hit by Cyberattack, Data Leaked
Tata Electronics recently fell victim to a cyberattack, but swift action was taken to contain the breach and minimize disruption, with the company confirming that its operations remained uninterrupted. The incident affected parts of its IT infrastructure, but established response protocols were activated to mitigate the impact.

FortiBleed Exposes 110 Million Credentials in Global Firewall Hack
A recent global firewall hack, dubbed FortiBleed, has exposed a staggering 110 million credentials, putting countless individuals and organizations at risk. This massive breach was made possible by a sophisticated five-stage pipeline that allowed hackers to capture sensitive information, including cleartext and hashed credentials, from compromised devices.

Air Force Grapples with Boeing Over T-7 Data Rights
The Air Force is facing a major headache in maintaining its new T-7 Red Hawk aircraft, with a high risk of sustainment issues due to a lack of technical data and parts shortages. This looming challenge threatens to severely hinder the aircraft's upkeep, a source close to the program warns.

Malicious npm Package Exploits Supply Chain with Multi-Stage Windows RAT
Beware of sneaky impostors in your build dependencies - a recent discovery by JFrog revealed a malicious npm package masquerading as a popular JavaScript tool, hiding a multi-stage Windows remote access trojan. Treat similar-sounding package names with caution, as they could be potential delivery mechanisms for threats.

LastPass Breach Exposes Customer Data in Supply Chain Hack
LastPass recently discovered a security incident at Klue, a third-party platform they use, which led to an unauthorized actor accessing some customer data through its Salesforce environment. Fortunately, customer vaults and core products remain secure, and swift action has been taken to mitigate the breach.

Malicious npm Packages Deliver Windows RAT via PostCSS Tooling
Beware of malicious npm packages masquerading as popular tools like PostCSS - researchers have uncovered three fake packages that have racked up over 1,000 downloads and deliver a sneaky Windows remote access trojan. These lookalike packages, published just over a month ago, have been cleverly designed to fly under the radar.

US Issues Orders to Advance Quantum Computing and Counter Its Risks
The US is taking a bold step forward in quantum computing, with two new executive orders aimed at harnessing its potential while mitigating risks, and National Cyber Director Sean Cairncross emphasizing the need to balance innovation and security. The orders will drive a national effort to accelerate quantum innovation, foster partnerships, and develop a skilled workforce.

France, Germany Finalize KNDS Shareholding Pact Ahead of Potential IPO
France and Germany have taken a giant leap in their defense collaboration, finalizing a pact that paves the way for equal shareholding in European defense giant KNDS, cementing their sovereignty in land defence. This strategic move marks a significant milestone in their joint effort to strengthen defense ties and cooperation.

Cloud Providers' Global Namespace Flaw Enables Bucket Hijacking
A newly discovered flaw in cloud providers' global namespace has been exploited in a simple yet powerful bucket hijacking technique, allowing attackers to redirect sensitive data streams into their own accounts. This alarming vulnerability affects multiple services across major cloud providers.