Tag: supply-chain
-
Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet
Amazon linked four npm supply-chain attacks to North Korea’s Sapphire Sleet, exposing the security risks posed by compromised maintainer accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-amazon-npm-attacks-sapphire-sleet/
-
Künstliche Intelligenz ist fester Bestandteil moderner Cyberangriffe
Cyberangreifer operationalisieren künstliche Intelligenz nicht nur, um Schwachstellen innerhalb von Stunden auszunutzen, sondern auch, um KI, die in Unternehmen eingesetzt wird, anzugreifen. Zudem nutzen Angreifer sie auch, um Angriffe entlang der Software-Lieferkette zu skalieren. Dies verdeutlicht der aktuelle <> von Crowdstrike. So nutzten China-nahe Angreifer innerhalb von 24 Stunden nach der Veröffentlichung eines […] First seen…
-
Risiken der KI-Lieferkette
Die jüngste Offenlegung von kritischen Schwachstellen in großen KI-Repositorien wie Hugging Face verdeutlicht ein grundlegendes Problem. Ausgerechnet jene Plattformen, auf die Unternehmen bei der Entwicklung KI-gestützter Anwendungen setzen, entwickeln sich zunehmend zu einem Einfallstor für systemische Risiken. Mit dem Übergang zu agentenbasierten Systemen gewinnt dieses Problem an Dringlichkeit. Von Shadow-IT zu Shadow-AI Über Jahre […]…
-
Preventing dependency confusion in npm and PyPI pipelines
Dependency confusion is a supply chain issue that affects how package managers choose where to download a dependency from. If your build or developer tooling can see both a private package registry and a public registry, an attacker may try to publish a package with the same name as an internal one and rely on……
-
What the Minnesota Water Attacks Reveal About Securing Remote Access to Critical Infrastructure
Tags: access, ai, attack, authentication, cisa, control, corporate, credentials, cyberattack, data-breach, exploit, Hardware, identity, infrastructure, Internet, law, least-privilege, malware, mfa, monitoring, network, password, risk, router, supply-chain, technology, vpn, zero-day, zero-trustWhen headlines break about cyberattacks targeting critical infrastructure, the conversation often turns immediately to zero-day exploits, advanced malware, and other sophisticated techniques. The recent attacks on municipal water systems across at least seven US states, including more than 30 Minnesota water and wastewater utilities, illustrate why this assumption can be misleading. As a “recovering CISO” who…
-
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk.”These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the First seen…
-
XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs
XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize Telegram while operating almost entirely from memory with aggressive polymorphism and defense evasion. After several months of apparent inactivity, the actors behind the XCSSET malware resurfaced with version 40 (v40), a major re-architecture of the…
-
To Ban or Not Ban Chinese Open-Weight AI Models
Tags: ai, backdoor, china, control, cybersecurity, data, defense, finance, government, infrastructure, international, malicious, microsoft, military, network, nvidia, open-source, openai, regulation, risk, software, supply-chain, technology, usaShould the US ban American companies from using Chinese open-weight AI models? That is the ugly question. US officials have openly expressed concerns and a desire to implement regulations. The technology community has aggressively responded, with over 20 leading AI companies, including Microsoft, Nvidia, Meta, and Dell, urging legislators not to rush imposing restrictions on…
-
Online ad firm Adform’s script compromised to steal cryptocurrency
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors’ clipboards with ones controlled by an attacker. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/
-
Intel 471 Warns of Expanding Software Supply Chain Attacks
Intel 471 warns software supply chain attacks are increasingly targeting developer identities and CI/CD pipelines. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/intel-471-warns-of-expanding-software-supply-chain-attacks/
-
AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks
AWS has linked North Korea to the axios campaign to other attacks on npm libraries First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/aws-north-korea-axios-npm-supply/
-
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/
-
Trojaner ersetzt in einer JSON-Bibliothek die Konfiguration des Entwicklers zur Manipulation einer Wettplattform
Das JFrog Security Research Team hat ein per Typosquatting getarntes NuGet-Paket entdeckt und offengelegt, das einen ungewöhnlich präzisen Supply-Chain-Angriff darstellt. Statt als generischer Info-Stealer zu agieren, wurde ‘Newtonsoftt.Json.Net>> als gezieltes Betrugswerkzeug gegen ein einzelnes Unternehmen entwickelt, während es sich für alle anderen wie eine völlig normale Software-Bibliothek verhielt. Es gab sich als die weit verbreitete…
-
GitHub and PyPI implement new security measures against supply-chain attacks
First seen on scworld.com Jump to article: www.scworld.com/brief/github-and-pypi-implement-new-security-measures-against-supply-chain-attacks
-
Clop Tied to PTC Product Lifecycle Management Software Hits
Signs Point to Cl0p Extortion Group Again Stealing Data and Holding It to Ransom. Digital extortion group Clop, aka Cl0p, has been tied to a fresh spate of supply-chain attacks, this time targeting users of popular Windchill and FlexPLM product lifecycle management software from PTC. Victims appear to at least span the aerospace, automotive, manufacturing…
-
Ernst & Young data breach claimed by ShinyHunters extortion gang
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company’s systems via a supply-chain attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
-
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies as soon as they are released. This change comes in response to a rise in supply chain attacks where attackers publish trojanized package versions to public registries, relying on automated update…
-
Marathon Petroleum’s CISO on OT security automation, supply chain risk
In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/mary-rose-martinez-marathon-petroleum-ot-security-automation/
-
PyPI Blocks New File Uploads to Old Releases to Prevent Package Poisoning Attacks
PyPI has introduced a new supply-chain security control that prevents publishers from uploading additional files to package releases older than 14 days, reducing the risk of attackers poisoning previously trusted versions after compromising project credentials, automation workflows, or publishing tokens. The Python Package Index (PyPI) has begun rejecting new distribution files uploaded to releases that…
-
GitHub, PyPI add time-based defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/
-
GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/
-
Ransomware gangs go after EMEA healthcare’s supply chain
A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/emea-healthcare-ransomware-activity/
-
136 Malicious RubyGems Packages Deploy XMRig Miner and Spread via SSH
A large-scale supply chain attack has flooded RubyGems with 136 trojanized packages that deploy an XMRig Monero miner and self-propagate via SSH, underscoring systemic weaknesses in language ecosystems beyond npm and PyPI. On July 22, 2026, researchers Moe Ghasemisharif, Ruian Duan, Zhanhao Chen, and Daiping Liu documented a coordinated cryptojacking campaign abusing RubyGems as the…
-
Ransomware in 2026: More groups, more victims, no slowdown
Ransomware activity followed a recognizable pattern during the previous four years. Each year was defined by a dominant actor, its collapse, or a major supply chain incident. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/ransomware-attack-trends-2026-report/
-
JFrog analysiert gezielten Supply-Chain-Angriff über manipuliertes Newtonsoft.Json-Paket
JFrog entdeckt ein gefälschtes NuGet-Paket, das gezielt die Spielergebnisse einer Online-Wettplattform manipulierte und Daten unbemerkt exfiltrierte. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/jfrog-analysiert-gezielten-supply-chain-angriff-ueber-manipuliertes-newtonsoft-json-paket/a45858/
-
Third-Party SDKs Raise Privacy Questions for Apps Marketed to U.S. Military
Researchers found Chinese and Russian SDKs in Android apps marketed to U.S. military users, highlighting software supply chain and enterprise privacy risks. The post Third-Party SDKs Raise Privacy Questions for Apps Marketed to U.S. Military appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-android-sdk-supply-chain-privacy-military-apps/
-
Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Game Results
JFrog Security Research has disclosed a precision supply-chain attack in which a typosquatted NuGet package, Newtonsoftt.Json.Net, impersonated the ubiquitous Newtonsoft.Json library while secretly rigging game outcomes at online betting operator Digitain. Unlike typical info-stealers that harvest credentials indiscriminately, this trojan functions as a fully operational JSON library for every host except its single intended target.…
-
Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns
Global ransomware attacks climbed 3% in the second quarter of 2026, rising from 2,165 incidents in Q1 to 2,229, according to NCC Group’s latest Quarterly Cyber Threat Intelligence Report. While the increase in volume was modest, the security firm warned that supply chain attacks are growing rapidly in both scale and sophistication, and that the…
-
Wansview IoT Camera Flaw Exposes Supply Chain Security Risks
Researchers found decades-old software flaws in a Wansview IoT camera that expose software supply chain security risks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/wansview-iot-camera-flaw-exposes-supply-chain-security-risks/
-
1 in 4 businesses hit by cyber attacks through their supply chain in the last year
One in four UK businesses (26%) have suffered a cyber incident that originated in their supply chain over the last year, according to new research from business continuity and disaster recovery specialist Databarracks. The finding is particularly striking given that organisations are highly aware of the risk they face: nearly half (48%) admit they have…

