Tag: supply-chain
-
Asruex Trojan Found Embedded in GEEKOM Mini PC Realtek Ethernet Driver
GEEKOM has confirmed that a malware-flagged Realtek LAN driver package was previously accessible through an outdated support page for its mini PCs, raising fresh supply-chain security concerns around vendor-hosted driver downloads. The company said the affected file was confined to a legacy resource, not its current support portal or factory-installed Windows images. The incident came…
-
Tricentis macht KI-Sicherheit zur Chefsache: Erika Dean übernimmt CISO-Posten
Tricentis ernennt Erika Dean zur CISO. Sie verantwortet Cybersecurity, Produktsicherheit, Software Supply Chain und Governance rund um Agentic AI. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/tricentis-macht-ki-sicherheit-zur-chefsache-erika-dean-uebernimmt-ciso-posten/a46196/
-
US FCC Weighs Chinese Transceiver Supply-Chain Crackdown
Draft Covered List Expansion Would Reach Components Inside AI Data Center Switches. The U.S. FCC reportedly may restrict imports of new-model optical transceivers made in China, a move that would reach AI data center interconnects for the first time and leaves open how regulators would define origin, what counts as a new model and whether…
-
LiteLLM Supply-Chain Attack Technology, Banking and Healthcare the Most Affected
Tags: attack, backdoor, banking, credentials, cybersecurity, data-breach, finance, healthcare, supply-chain, technologyThe SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code repository compromise. According to cybersecurity experts, LiteLLM / TeamPCP Supply-Chain Attack will have long-lasting consequences. By compromising a…
-
Major genetic-testing firm says hack compromised sensitive patient data
The June breach, which also exposed employees’ information, underscored the supply-chain risks facing the healthcare sector. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/baylor-genetics-cyberattack-compromise-patient-data-genetic-testing/828019/
-
LiteLLM Supply-Chain Attack Exposed Credentials Across 2,500 Organizations
Malicious LiteLLM releases may have exposed credentials from more than 2,500 organizations and hundreds of thousands of CI/CD pipelines. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity-threats/news-litellm-supply-chain-attack-credential-theft/
-
Wesco confirms security incident after ExfilSquad claims data theft
Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/
-
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target
Tags: ai, attack, breach, cloud, credentials, cyber, infrastructure, malicious, pypi, software, supply-chain, theftThe March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can turn AI infrastructure into a high-value conduit for credential theft, cloud intrusion, and downstream software supply chain abuse. The packages were available for roughly 40 minutes before quarantine, but their brief…
-
Logistics Giant Ceva Suffers Data Breach Impacting European Clients
Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/logistics-ceva-data-breach/
-
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform’s plugins team to temporarily disable their downloads.”Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository,” Wordfence researcher Paolo Tresso said. First seen on thehackernews.com Jump to…
-
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators’ browsers to create rogue admin accounts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/
-
âš¡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed…
-
77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data
Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk. The post 77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-open-vsx-extension-risk/
-
GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems
GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This rollout is supported by a new GitHub Advisory Database importer for OpenSSF’s malicious-packages repository, which enhances supply chain detection across these eight ecosystems. GitHub Expands…
-
Chainloop: Open-source evidence store and policy engine for the software supply chain
Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/chainloop-open-source-supply-chain-security/
-
UK manufacturers face rising hacking risk as survey shows 30% were hit last year
Big companies describe being under constant threat but only half have a plan in place to respond to an attackNearly a third of British manufacturers have been hit by a cyber-attack on them or a company in their supply chain, according to a survey that highlighted the growing hacking risk to companies.The findings come almost…
-
Russian Hackers Use AI Slopsquatting to Publish 700+ Malicious npm Packages
A large-scale supply chain attack has hit the npm registry, with a suspected Russian threat actor publishing more than 700 malicious packages in just 48 hours. Researcher Paul McCarty documented the campaign, tracked as WEL1DROPPER, and the package count has since grown past 1,000. WEL1DROPPER marks an evolution in AI slopsquatting, where attackers register randomly…
-
Island’s Michael Leland on the hidden risks of the AI supply chain
First seen on scworld.com Jump to article: www.scworld.com/resource/islands-michael-leland-on-the-hidden-risks-of-the-ai-supply-chain
-
Why ‘America First’ in AI Shouldn’t Mean ‘America Only’
Former US Cyber Director on Cooperation, AI Supply Chains and National Security. U.S. leadership in AI requires more than protecting domestic technology. Former U.S. National Cyber Director Chris Inglis says national security will depend on outperforming competitors, strengthening global supply chains and working with allies against shared AI risks. First seen on govinfosecurity.com Jump to…
-
AI Agents, Supply Chain Attacks, and Critical Flaws Define the Week in August 2026
Weekly summary of Cybersecurity Insider newsletters for August 2026, including Def Con and Black Hat conference coverage First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/ai-agents-supply-chain-attacks-and-critical-flaws-define-the-week-in-august-2026/
-
Top 10 Breaches of the Week
Security Boulevard’s weekly after-action roundup looks at the breaches and security incidents that mattered most over the past two weeks. This edition spans large healthcare exposures, attacks on government and financial infrastructure, a fast-moving software supply-chain compromise, and incidents where the final scope is still being established. #1: Unlimited Technology Systems: 3.8 million healthcare records..…
-
The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks
This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure. First seen on thecyberexpress.com Jump…
-
15 AI Security Lessons From Black Hat and Ai4 2026
Black Hat and Ai4 2026 highlighted gaps in AI agent security, identity controls, software supply chains, monitoring, and incident response. The post 15 AI Security Lessons From Black Hat and Ai4 2026 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-black-hat-ai4-2026-ai-security-takeaways/
-
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Tags: attack, cybercrime, group, infrastructure, Internet, malware, software, supply-chain, threat, trainingA new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain.”The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend…
-
Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attacks
Tags: ai, attack, automation, breach, cyber, flaw, google, openai, rce, remote-code-execution, supply-chain, theft, tool, vulnerabilitySecurity researchers have disclosed a vulnerability affecting AI coding-agent workflows from Anthropic, Google, and OpenAI. Their research highlights how an attacker-controlled issue or zero-privilege input can breach trust boundaries in an agent “harness”, which includes the permissions, tools, sandbox, filesystem, and automation surrounding the model, and result in code execution, secret theft, or workflow compromise.…
-
AI Accelerates Financial Services Fraud
Coinbase’s Lunglhofer on Deepfakes, Supply-Chain Risk and Human Expertise. AI is helping criminals clone voices, exploit software flaws and guide fraud schemes in real time. Coinbase Chief Security Officer Jeff Lunglhofer explains why faster attacks demand AI-enabled defense backed by cybersecurity experts. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-accelerates-financial-services-fraud-a-32450
-
Hackers Stalked Me by Hijacking a Smartwatch for Kids
Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets. First seen on wired.com Jump to article: www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/
-
Black Hat 2026: Critical Flaws Found in Anthropic, Google, and OpenAI Coding Agents
Researchers disclosed critical flaws in AI coding agents from Anthropic, Google, and OpenAI that could enable credential theft, RCE, and supply chain attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/black-hat-2026-critical-flaws-found-in-anthropic-google-and-openai-coding-agents/

