Tag: supply-chain
-
(g+) Miasma-Lieferkette: Warum gültige Signaturen plötzlich nicht mehr reichen
Tags: supply-chainEin selbst verbreitender Wurm kapert npm-Pakete mit gültigen Signaturen. Worauf Dev-Teams jetzt achten sollten. First seen on golem.de Jump to article: www.golem.de/news/miasma-lieferkette-warum-gueltige-signaturen-ploetzlich-nicht-mehr-reichen-2607-210992.html
-
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma”‘associated Node.js backdoor through trusted GitHub Actionsdriven release workflows and exposing high”‘value developer and CI/CD environments to remote access, credential theft, and further lateral movement. Malicious versions were shipped for @asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, and @asyncapi/specs@6.11.2 and 6.11.2-alpha.1, together accounting for…
-
Cybersicherheit in der Lieferkette als Wettbewerbsvorteil für Unternehmen
Unternehmen versuchen auf viele Weisen, ihr Kerngeschäft vor Cyberattacken zu schützen. Doch längst sind ihre Lieferketten zum bevorzugten Angriffsziel geworden. Die Gefahr droht nicht mehr nur in der Firmenzentrale, sondern an der Peripherie durch sogenannte Supply-Chain-Attacken. Das Berliner Sicherheitsunternehmen Maconia sieht eine verantwortlich und schnell handelnde Unternehmensführung als wichtigsten Faktor für die Sicherheit im gesamten……
-
AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware
AgentBaiting is the clearest sign yet that AI agents and their capability ecosystems have become a first”‘class malware delivery surface, with FakeGit’s 7,600″‘repo operation pushing SmartLoader and StealC directly into AI Skills and MCP workflows. By turning agent”‘readable READMEs, public AI registries, and GitHub trust signals into a weaponized “AI capability supply chain,” attackers now…
-
Hackers steal customer data from major hospital software vendor
The breach is another reminder of how vulnerable the healthcare industry is to supply-chain attacks. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/craneware-health-care-data-breach/825643/
-
How agentic endpoint security shuts down IDE-based supply chain attacks
Attention shifts from EDR to Agentic Endpoint Security to close visibility gaps that AI can exploit. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/how-agentic-endpoint-security-shuts-down-ide-based-supply-chain-attacks/825550/
-
North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images
A sophisticated North Korean threat campaign dubbed “Contagious Interview” has resurfaced with new delivery techniques, leveraging weaponized SVG image files to deploy the OTTERCOOKIE malware while coinciding with a separate supply chain intrusion targeting the Ruby ecosystem. Security researchers tracking DPRK-linked activity note that the campaign continues to impersonate recruiters and job interview workflows, luring…
-
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.The rogue gems are listed below – git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) – Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) –…
-
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an “unprecedented” four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron, First seen on thehackernews.com Jump…
-
The Cyber Express Weekly Roundup: TikTok Age Verification Probe, Healthcare Data Breach, Qantas Ruling, and Major Cyberattacks
Tags: breach, cyber, cyberattack, cybersecurity, data, data-breach, healthcare, risk, supply-chain, threat, vulnerabilityThis week’s cybersecurity roundup highlights growing concerns around online child safety, healthcare data protection, supply chain risks, and cyber threats affecting organizations worldwide. From regulatory scrutiny of digital platforms to large-scale vulnerabilities and operational disruptions, recent incidents show how cyber risks continue expanding across industries. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cybersecurity-weekly-roundup-tce/
-
Upwind Finds Coordinated Supply Chain Campaign Compromising Multiple AsyncAPI npm Packages
Upwind links compromised AsyncAPI npm packages to a coordinated supply chain attack spanning repositories, publishing pipelines, and developer systems at risk. First seen on hackread.com Jump to article: hackread.com/upwind-supply-chain-compromise-asyncapi-npm-packages/
-
Healthcare sector faces persistent supply-chain security, identity management challenges
A new report says doctors and nurses should train for cyberattacks the way firefighters train for major blazes — even if they expect them to be rare. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/healthcare-cybersecurity-risk-management-identity-fortified/825175/
-
Healthcare sector faces persistent supply-chain security, identity management challenges
A new report says doctors and nurses should train for cyberattacks the way firefighters train for major blazes — even if they expect them to be rare. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/healthcare-cybersecurity-risk-management-identity-fortified/825175/
-
The AI Supply Chain Is Your Latest Unguarded Attack Surface
When You Consume AI, You Inherit Every Upstream Risk You Can’t See Most enterprises don’t build AI, they consume it through APIs, open-source models and orchestration frameworks. Each layer inherits upstream risk with little visibility. This piece maps the four-layer AI supply chain and the existing security disciplines that bring it under control. First seen…
-
MSPs ideally placed to improve supply chain resilience
Research from Proxima indicates more CEOs are worried about their ability to defend from attacks originating outside the organisation First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366645762/MSPs-ideally-placed-to-improve-supply-chain-resilience
-
Why SBOMs, signing, and provenance still don’t tell you if software is safe
We have made real progress in software supply chain security, improving visibility into software components, authenticity and build integrity. Much of this progress traces … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/sbom-zero-trust-for-code/
-
Jscrambler npm Supply Chain Attack Steals Cloud Credentials and Crypto Wallet Secrets
A malicious actor compromised the Jscrambler npm package and published several trojanized versions that included a hidden, cross-platform credential-stealing payload. The attack targeted developers, build pipelines, and CI/CD systems, where npm installations could access source code, cloud credentials, deployment tokens, and sensitive environment variables. Jscrambler npm Supply Chain Attack Socket’s Research Team detected the initial…
-
npm and PyPI Malware Campaign Exfiltrates CI/CD Secrets Through Fake Payment SDKs
A coordinated supply-chain campaign that pushed 17 malicious packages across npm and PyPI, masquerading as SDKs for well-known payment services including PaySafe, Skrill and Neteller. The campaign’s packages 17 npm modules published with four rapid versions each and four PyPI packages access with single malicious releases presented as convenient payment SDK facades but contained logic…
-
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
Software supply chain security was hard enough. Then AI joined the build pipeline.For five years, “software supply chain security” meant one question: what’s in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? SolarWinds, Log4Shell, and XZ Utils all taught the same lesson: the risk lives…
-
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
Software supply chain security was hard enough. Then AI joined the build pipeline.For five years, “software supply chain security” meant one question: what’s in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? SolarWinds, Log4Shell, and XZ Utils all taught the same lesson: the risk lives…
-
TeamPCP Supply Chain Attacks Feed VECT Ransomware With Stolen CI/CD Credentials
TeamPCP’s wide-scale supply-chain compromises have materially fueled VECT ransomware operations by supplying a vast archive of stolen CI/CD credentials, reshaping how organizations should measure ransomware exposure. Rather than choosing victims in advance, TeamPCP contaminated widely used components Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK access so that any organization that installed those packages…
-
Berechtigungen in der Lieferkette werden zum kritischen Einfallstor
Regulierung schützt nicht vor Angriffen mit kompromittierten Identitäten und Zugangsdaten Identitäts-Sicherheit hingegen schon. Exemplarische Vorfälle im Juni, wie bei der V-Bank, bei dem Hacker über einen IT-Dienstleister Zugriff auf Systeme erlangten und einen Datenabfluss verursachten, oder das Datenleck bei Lastpass, das durch eine Schwachstelle bei einem Drittanbieter ausgenutzt wurde, zeigen exemplarisch eine bittere Wahrheit: […]…
-
Thousands of MCP Servers Found Vulnerable to File Access and Injection Attacks
Thousands of Model Context Protocol (MCP) servers, widely used to connect large language models (LLMs) to external systems, have been found vulnerable to critical security flaws, including arbitrary file access, command injection, server-side request forgery (SSRF), and SQL injection, raising significant concerns about AI supply chain security. A large-scale analysis of 9,695 MCP servers across…
-
North Korean PolinRider supply chain attack targets 108 unique repos
First seen on scworld.com Jump to article: www.scworld.com/news/north-korean-polinrider-supply-chain-attack-targets-108-unique-repos
-
Alibaba Bans Claude Code Over Spy-Like Tracking Code
Supply-Chain Risks Cited After Hidden Code Checked for China-Related Indicators. The latest twist in the U.S.-China AI race sees Alibaba ban Anthropic’s Claude Code after hidden tracking code sparked backlash, adding another layer to an increasingly bitter battle over AI leadership. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/alibaba-bans-claude-code-over-spy-like-tracking-code-a-32162
-
Vect and TeamPCP Cybercrime Groups Link for Ransomware Hits
Supply-Chain Victims Also at Risk From Poorly Coded, Data-Shredding Crypto-Locker. Recently announced tie-ups between ransomware group Vect, supply-chain attack specialists TeamPCP and data-leak stalwart Lapsus$ show cybercriminals continuing their quest to monetize their attacks and develop new profit streams. But not all has been smooth sailing. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/vect-teampcp-cybercrime-groups-link-for-ransomware-hits-a-32159
-
The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident
Vercel breach happened after an employee used an unvetted AI tool. Attackers exploited it as a trusted link to access systems, steal data, and extort $2M. The Vercel breach of April 2026 did not begin with a classic zero-day exploit, a misconfigured cloud bucket, or a sophisticated nation-state infrastructure implant. Instead, it unfolded when an…
-
FBI Says TeamPCP Uses Trojanized Updates to Steal Cloud Tokens, SSH Keys, and Kubernetes Secrets
Tags: access, advisory, attack, cloud, cyber, cybercrime, exploit, group, kubernetes, software, supply-chain, updateThe Federal Bureau of Investigation (FBI) has issued an urgent FLASH advisory warning that the cybercriminal group TeamPCP is weaponizing trojanized software updates to harvest cloud access tokens, SSH keys, and Kubernetes secrets at scale. This campaign represents one of the most sophisticated software supply chain attacks observed in 2026, exploiting trust in widely deployed…
-
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Tags: access, citrix, credentials, exploit, group, monitoring, ransomware, supply-chain, tactics, threat, vulnerabilityThreat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.”Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral First seen on thehackernews.com Jump to…
-
ChocoPoC Campaign Abuses GitHub PoC Repositories to Steal Browser Credentials
A coordinated supply-chain campaign has been weaponizing GitHub proof-of-concept (PoC) repositories to compromise vulnerability researchers and penetration testers, delivering a stealthy Python Remote Access Trojan (RAT) dubbed “ChocoPoC.” The lure is simple and effective: newly disclosed high-severity CVEs create urgency for fast PoC and scanner module development. Adversaries create seemingly legitimate PoC repositories that include…

