Tag: supply-chain
-
Alarm sounded around supply chain risks
With AI agents demonstrating their ability to bypass security, the need to protect against attacks originating from third-party suppliers has increased First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366648132/Alarm-sounded-around-supply-chain-risks
-
Suppliers, logins, and AI tools are all becoming attack paths
Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/crowdstrike-cyber-threat-trends-report/
-
QuickFox VPN targeted in long-standing supply chain attack delivering FDMTP backdoor
First seen on scworld.com Jump to article: www.scworld.com/brief/quickfox-vpn-targeted-in-long-standing-supply-chain-attack-delivering-fdmtp-backdoor
-
Why Healthcare AI Use Demands Transparency to Manage Risks
Anne Snowdon of SCAN Health on AI Governance, Supply Chains. Healthcare organizations adopting AI must prioritize transparency, measurable outcomes and vendor accountability. Anne Snowdon of SCAN Health explains why AI governance, supply-chain visibility, cyber preparedness and patient trust determines whether emerging tech deliver value or create new risks. First seen on govinfosecurity.com Jump to article:…
-
Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
A long”‘running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems, exposing a major blind spot in defenders’ visibility where command”‘and”‘control (C2) traffic never touches traditional DNS. The attackers added just two lines of JavaScript to an internal Electron renderer HTML file, causing the app…
-
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users.According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to…
-
Massive supply-chain attack compromises 440 packages under four hours
Researchers from multiple security firms observed a variant of Mini Shai-Hulud, self-replicating malware linked to TeamPCP, in all the affected packages. First seen on cyberscoop.com Jump to article: cyberscoop.com/supply-chain-attack-malware-mini-shai-hulud-teampcp/
-
Black Hat 2026: CrowdStrike Threat Hunting Report Findings
CrowdStrike’s 2026 Threat Hunting Report highlights how AI, identity attacks, and software supply chain threats are reshaping cyber risk. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/black-hat-2026-crowdstrike-threat-hunting-report-findings/
-
AI widely used to exploit critical flaws, disrupt supply chains
A report confirms the growing use of AI across a broad spectrum of threat groups. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-exploit-critical-flaws-disrupt-supply-chains/826915/
-
GitHub Account Breach Fuels Shai-Hulud npm Supply Chain Attack
A compromised GitHub account fueled a supply chain attack, spreading credential-stealing malware across hundreds of packages. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/github-account-breach-fuels-shai-hulud-npm-supply-chain-attack/
-
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named ‘ChainDrop’ has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/
-
Shai-Hulud Supply Chain Attack Compromises Keyv and Hundreds of npm Packages
Attackers have compromised the GitHub account of a Keyv maintainer, a widely used JavaScript key-value storage library, to distribute credential-stealing malware via npm packages. This ongoing supply chain attack, known as the Shai-Hulud campaign, has affected Keyv and several related caching libraries, with a combined monthly installation reach in the billions. Aikido Security reported that…
-
18 Malicious npm Packages Deploy Cross-Platform RAT Against Alibaba Developers
18 malicious npm packages have been used in a tightly coordinated software supply chain attack to deliver a cross”‘platform RAT that specifically targets developers working with Alibaba’s internal Aone tooling and @ali-scoped packages. The operation came to light after researchers analyzed a seemingly simple malicious npm package, lib-mtop, which acted as a downloader and exposed…
-
Microsoft shortens NuGet API key lifetime to improve supply chain security
Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its package repository for … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/microsoft-reducing-nuget-api-keys-lifetime/
-
CrowdStrike 2026 Threat Hunting Report: KI ist heute fester Bestandteil moderner Cyberangriffe
Cyberangreifer operationalisieren künstliche Intelligenz nicht nur, um Schwachstellen innerhalb von Stunden auszunutzen, sondern auch, um KI, die in Unternehmen eingesetzt wird, anzugreifen. Zudem nutzen Angreifer sie auch, um Angriffe entlang der Software-Lieferkette zu skalieren. CrowdStrike hat am 3. August den 2026 Threat Hunting Report veröffentlicht, der verdeutlicht, wie sehr künstliche Intelligenz mittlerweile Bestandteil von… First…
-
Google Warns Open-Source Attacks Will Reach New Heights
Google Says Open-Source Compromises Are Easier to Scale and Replicate. Compromising the open-source supply chain is easy to do and spreads more quickly than traditional supply-chain attacks, making it a lucrative tactic that will continue to expand, warned Google. One of the largest open-source supply-chain attacks involved a North Korean threat actor. First seen on…
-
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private…
-
Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet
Amazon linked four npm supply-chain attacks to North Korea’s Sapphire Sleet, exposing the security risks posed by compromised maintainer accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-amazon-npm-attacks-sapphire-sleet/
-
Risiken der KI-Lieferkette
Die jüngste Offenlegung von kritischen Schwachstellen in großen KI-Repositorien wie Hugging Face verdeutlicht ein grundlegendes Problem. Ausgerechnet jene Plattformen, auf die Unternehmen bei der Entwicklung KI-gestützter Anwendungen setzen, entwickeln sich zunehmend zu einem Einfallstor für systemische Risiken. Mit dem Übergang zu agentenbasierten Systemen gewinnt dieses Problem an Dringlichkeit. Von Shadow-IT zu Shadow-AI Über Jahre […]…
-
Künstliche Intelligenz ist fester Bestandteil moderner Cyberangriffe
Cyberangreifer operationalisieren künstliche Intelligenz nicht nur, um Schwachstellen innerhalb von Stunden auszunutzen, sondern auch, um KI, die in Unternehmen eingesetzt wird, anzugreifen. Zudem nutzen Angreifer sie auch, um Angriffe entlang der Software-Lieferkette zu skalieren. Dies verdeutlicht der aktuelle <> von Crowdstrike. So nutzten China-nahe Angreifer innerhalb von 24 Stunden nach der Veröffentlichung eines […] First seen…
-
Preventing dependency confusion in npm and PyPI pipelines
Dependency confusion is a supply chain issue that affects how package managers choose where to download a dependency from. If your build or developer tooling can see both a private package registry and a public registry, an attacker may try to publish a package with the same name as an internal one and rely on……
-
What the Minnesota Water Attacks Reveal About Securing Remote Access to Critical Infrastructure
Tags: access, ai, attack, authentication, cisa, control, corporate, credentials, cyberattack, data-breach, exploit, Hardware, identity, infrastructure, Internet, law, least-privilege, malware, mfa, monitoring, network, password, risk, router, supply-chain, technology, vpn, zero-day, zero-trustWhen headlines break about cyberattacks targeting critical infrastructure, the conversation often turns immediately to zero-day exploits, advanced malware, and other sophisticated techniques. The recent attacks on municipal water systems across at least seven US states, including more than 30 Minnesota water and wastewater utilities, illustrate why this assumption can be misleading. As a “recovering CISO” who…
-
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk.”These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the First seen…
-
XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs
XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize Telegram while operating almost entirely from memory with aggressive polymorphism and defense evasion. After several months of apparent inactivity, the actors behind the XCSSET malware resurfaced with version 40 (v40), a major re-architecture of the…
-
To Ban or Not Ban Chinese Open-Weight AI Models
Tags: ai, backdoor, china, control, cybersecurity, data, defense, finance, government, infrastructure, international, malicious, microsoft, military, network, nvidia, open-source, openai, regulation, risk, software, supply-chain, technology, usaShould the US ban American companies from using Chinese open-weight AI models? That is the ugly question. US officials have openly expressed concerns and a desire to implement regulations. The technology community has aggressively responded, with over 20 leading AI companies, including Microsoft, Nvidia, Meta, and Dell, urging legislators not to rush imposing restrictions on…
-
Online ad firm Adform’s script compromised to steal cryptocurrency
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors’ clipboards with ones controlled by an attacker. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/
-
Intel 471 Warns of Expanding Software Supply Chain Attacks
Intel 471 warns software supply chain attacks are increasingly targeting developer identities and CI/CD pipelines. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/intel-471-warns-of-expanding-software-supply-chain-attacks/
-
AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks
AWS has linked North Korea to the axios campaign to other attacks on npm libraries First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/aws-north-korea-axios-npm-supply/
-
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/

