Tag: supply-chain
-
Russian Hackers Use AI Slopsquatting to Publish 700+ Malicious npm Packages
A large-scale supply chain attack has hit the npm registry, with a suspected Russian threat actor publishing more than 700 malicious packages in just 48 hours. Researcher Paul McCarty documented the campaign, tracked as WEL1DROPPER, and the package count has since grown past 1,000. WEL1DROPPER marks an evolution in AI slopsquatting, where attackers register randomly…
-
Island’s Michael Leland on the hidden risks of the AI supply chain
First seen on scworld.com Jump to article: www.scworld.com/resource/islands-michael-leland-on-the-hidden-risks-of-the-ai-supply-chain
-
Why ‘America First’ in AI Shouldn’t Mean ‘America Only’
Former US Cyber Director on Cooperation, AI Supply Chains and National Security. U.S. leadership in AI requires more than protecting domestic technology. Former U.S. National Cyber Director Chris Inglis says national security will depend on outperforming competitors, strengthening global supply chains and working with allies against shared AI risks. First seen on govinfosecurity.com Jump to…
-
AI Agents, Supply Chain Attacks, and Critical Flaws Define the Week in August 2026
Weekly summary of Cybersecurity Insider newsletters for August 2026, including Def Con and Black Hat conference coverage First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/ai-agents-supply-chain-attacks-and-critical-flaws-define-the-week-in-august-2026/
-
Top 10 Breaches of the Week
Security Boulevard’s weekly after-action roundup looks at the breaches and security incidents that mattered most over the past two weeks. This edition spans large healthcare exposures, attacks on government and financial infrastructure, a fast-moving software supply-chain compromise, and incidents where the final scope is still being established. #1: Unlimited Technology Systems: 3.8 million healthcare records..…
-
The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks
This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure. First seen on thecyberexpress.com Jump…
-
15 AI Security Lessons From Black Hat and Ai4 2026
Black Hat and Ai4 2026 highlighted gaps in AI agent security, identity controls, software supply chains, monitoring, and incident response. The post 15 AI Security Lessons From Black Hat and Ai4 2026 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-black-hat-ai4-2026-ai-security-takeaways/
-
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Tags: attack, cybercrime, group, infrastructure, Internet, malware, software, supply-chain, threat, trainingA new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain.”The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend…
-
Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attacks
Tags: ai, attack, automation, breach, cyber, flaw, google, openai, rce, remote-code-execution, supply-chain, theft, tool, vulnerabilitySecurity researchers have disclosed a vulnerability affecting AI coding-agent workflows from Anthropic, Google, and OpenAI. Their research highlights how an attacker-controlled issue or zero-privilege input can breach trust boundaries in an agent “harness”, which includes the permissions, tools, sandbox, filesystem, and automation surrounding the model, and result in code execution, secret theft, or workflow compromise.…
-
AI Accelerates Financial Services Fraud
Coinbase’s Lunglhofer on Deepfakes, Supply-Chain Risk and Human Expertise. AI is helping criminals clone voices, exploit software flaws and guide fraud schemes in real time. Coinbase Chief Security Officer Jeff Lunglhofer explains why faster attacks demand AI-enabled defense backed by cybersecurity experts. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-accelerates-financial-services-fraud-a-32450
-
Hackers Stalked Me by Hijacking a Smartwatch for Kids
Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets. First seen on wired.com Jump to article: www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/
-
Black Hat 2026: Critical Flaws Found in Anthropic, Google, and OpenAI Coding Agents
Researchers disclosed critical flaws in AI coding agents from Anthropic, Google, and OpenAI that could enable credential theft, RCE, and supply chain attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/black-hat-2026-critical-flaws-found-in-anthropic-google-and-openai-coding-agents/
-
Alarm sounded around supply chain risks
With AI agents demonstrating their ability to bypass security, the need to protect against attacks originating from third-party suppliers has increased First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366648132/Alarm-sounded-around-supply-chain-risks
-
Suppliers, logins, and AI tools are all becoming attack paths
Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/crowdstrike-cyber-threat-trends-report/
-
QuickFox VPN targeted in long-standing supply chain attack delivering FDMTP backdoor
First seen on scworld.com Jump to article: www.scworld.com/brief/quickfox-vpn-targeted-in-long-standing-supply-chain-attack-delivering-fdmtp-backdoor
-
Why Healthcare AI Use Demands Transparency to Manage Risks
Anne Snowdon of SCAN Health on AI Governance, Supply Chains. Healthcare organizations adopting AI must prioritize transparency, measurable outcomes and vendor accountability. Anne Snowdon of SCAN Health explains why AI governance, supply-chain visibility, cyber preparedness and patient trust determines whether emerging tech deliver value or create new risks. First seen on govinfosecurity.com Jump to article:…
-
Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
A long”‘running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems, exposing a major blind spot in defenders’ visibility where command”‘and”‘control (C2) traffic never touches traditional DNS. The attackers added just two lines of JavaScript to an internal Electron renderer HTML file, causing the app…
-
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users.According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to…
-
Massive supply-chain attack compromises 440 packages under four hours
Researchers from multiple security firms observed a variant of Mini Shai-Hulud, self-replicating malware linked to TeamPCP, in all the affected packages. First seen on cyberscoop.com Jump to article: cyberscoop.com/supply-chain-attack-malware-mini-shai-hulud-teampcp/
-
Black Hat 2026: CrowdStrike Threat Hunting Report Findings
CrowdStrike’s 2026 Threat Hunting Report highlights how AI, identity attacks, and software supply chain threats are reshaping cyber risk. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/black-hat-2026-crowdstrike-threat-hunting-report-findings/
-
AI widely used to exploit critical flaws, disrupt supply chains
A report confirms the growing use of AI across a broad spectrum of threat groups. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-exploit-critical-flaws-disrupt-supply-chains/826915/
-
GitHub Account Breach Fuels Shai-Hulud npm Supply Chain Attack
A compromised GitHub account fueled a supply chain attack, spreading credential-stealing malware across hundreds of packages. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/github-account-breach-fuels-shai-hulud-npm-supply-chain-attack/
-
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named ‘ChainDrop’ has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/
-
Shai-Hulud Supply Chain Attack Compromises Keyv and Hundreds of npm Packages
Attackers have compromised the GitHub account of a Keyv maintainer, a widely used JavaScript key-value storage library, to distribute credential-stealing malware via npm packages. This ongoing supply chain attack, known as the Shai-Hulud campaign, has affected Keyv and several related caching libraries, with a combined monthly installation reach in the billions. Aikido Security reported that…
-
18 Malicious npm Packages Deploy Cross-Platform RAT Against Alibaba Developers
18 malicious npm packages have been used in a tightly coordinated software supply chain attack to deliver a cross”‘platform RAT that specifically targets developers working with Alibaba’s internal Aone tooling and @ali-scoped packages. The operation came to light after researchers analyzed a seemingly simple malicious npm package, lib-mtop, which acted as a downloader and exposed…
-
Microsoft shortens NuGet API key lifetime to improve supply chain security
Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its package repository for … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/microsoft-reducing-nuget-api-keys-lifetime/
-
CrowdStrike 2026 Threat Hunting Report: KI ist heute fester Bestandteil moderner Cyberangriffe
Cyberangreifer operationalisieren künstliche Intelligenz nicht nur, um Schwachstellen innerhalb von Stunden auszunutzen, sondern auch, um KI, die in Unternehmen eingesetzt wird, anzugreifen. Zudem nutzen Angreifer sie auch, um Angriffe entlang der Software-Lieferkette zu skalieren. CrowdStrike hat am 3. August den 2026 Threat Hunting Report veröffentlicht, der verdeutlicht, wie sehr künstliche Intelligenz mittlerweile Bestandteil von… First…
-
Google Warns Open-Source Attacks Will Reach New Heights
Google Says Open-Source Compromises Are Easier to Scale and Replicate. Compromising the open-source supply chain is easy to do and spreads more quickly than traditional supply-chain attacks, making it a lucrative tactic that will continue to expand, warned Google. One of the largest open-source supply-chain attacks involved a North Korean threat actor. First seen on…
-
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private…

