Tag: supply-chain
-
Trojaner ersetzt in einer JSON-Bibliothek die Konfiguration des Entwicklers zur Manipulation einer Wettplattform
Das JFrog Security Research Team hat ein per Typosquatting getarntes NuGet-Paket entdeckt und offengelegt, das einen ungewöhnlich präzisen Supply-Chain-Angriff darstellt. Statt als generischer Info-Stealer zu agieren, wurde ‘Newtonsoftt.Json.Net>> als gezieltes Betrugswerkzeug gegen ein einzelnes Unternehmen entwickelt, während es sich für alle anderen wie eine völlig normale Software-Bibliothek verhielt. Es gab sich als die weit verbreitete…
-
GitHub and PyPI implement new security measures against supply-chain attacks
First seen on scworld.com Jump to article: www.scworld.com/brief/github-and-pypi-implement-new-security-measures-against-supply-chain-attacks
-
Clop Tied to PTC Product Lifecycle Management Software Hits
Signs Point to Cl0p Extortion Group Again Stealing Data and Holding It to Ransom. Digital extortion group Clop, aka Cl0p, has been tied to a fresh spate of supply-chain attacks, this time targeting users of popular Windchill and FlexPLM product lifecycle management software from PTC. Victims appear to at least span the aerospace, automotive, manufacturing…
-
Ernst & Young data breach claimed by ShinyHunters extortion gang
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company’s systems via a supply-chain attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
-
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies as soon as they are released. This change comes in response to a rise in supply chain attacks where attackers publish trojanized package versions to public registries, relying on automated update…
-
Marathon Petroleum’s CISO on OT security automation, supply chain risk
In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/mary-rose-martinez-marathon-petroleum-ot-security-automation/
-
PyPI Blocks New File Uploads to Old Releases to Prevent Package Poisoning Attacks
PyPI has introduced a new supply-chain security control that prevents publishers from uploading additional files to package releases older than 14 days, reducing the risk of attackers poisoning previously trusted versions after compromising project credentials, automation workflows, or publishing tokens. The Python Package Index (PyPI) has begun rejecting new distribution files uploaded to releases that…
-
GitHub, PyPI add time-based defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/
-
GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/
-
Ransomware gangs go after EMEA healthcare’s supply chain
A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/emea-healthcare-ransomware-activity/
-
136 Malicious RubyGems Packages Deploy XMRig Miner and Spread via SSH
A large-scale supply chain attack has flooded RubyGems with 136 trojanized packages that deploy an XMRig Monero miner and self-propagate via SSH, underscoring systemic weaknesses in language ecosystems beyond npm and PyPI. On July 22, 2026, researchers Moe Ghasemisharif, Ruian Duan, Zhanhao Chen, and Daiping Liu documented a coordinated cryptojacking campaign abusing RubyGems as the…
-
Ransomware in 2026: More groups, more victims, no slowdown
Ransomware activity followed a recognizable pattern during the previous four years. Each year was defined by a dominant actor, its collapse, or a major supply chain incident. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/ransomware-attack-trends-2026-report/
-
JFrog analysiert gezielten Supply-Chain-Angriff über manipuliertes Newtonsoft.Json-Paket
JFrog entdeckt ein gefälschtes NuGet-Paket, das gezielt die Spielergebnisse einer Online-Wettplattform manipulierte und Daten unbemerkt exfiltrierte. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/jfrog-analysiert-gezielten-supply-chain-angriff-ueber-manipuliertes-newtonsoft-json-paket/a45858/
-
Third-Party SDKs Raise Privacy Questions for Apps Marketed to U.S. Military
Researchers found Chinese and Russian SDKs in Android apps marketed to U.S. military users, highlighting software supply chain and enterprise privacy risks. The post Third-Party SDKs Raise Privacy Questions for Apps Marketed to U.S. Military appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-android-sdk-supply-chain-privacy-military-apps/
-
Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Game Results
JFrog Security Research has disclosed a precision supply-chain attack in which a typosquatted NuGet package, Newtonsoftt.Json.Net, impersonated the ubiquitous Newtonsoft.Json library while secretly rigging game outcomes at online betting operator Digitain. Unlike typical info-stealers that harvest credentials indiscriminately, this trojan functions as a fully operational JSON library for every host except its single intended target.…
-
Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns
Global ransomware attacks climbed 3% in the second quarter of 2026, rising from 2,165 incidents in Q1 to 2,229, according to NCC Group’s latest Quarterly Cyber Threat Intelligence Report. While the increase in volume was modest, the security firm warned that supply chain attacks are growing rapidly in both scale and sophistication, and that the…
-
Wansview IoT Camera Flaw Exposes Supply Chain Security Risks
Researchers found decades-old software flaws in a Wansview IoT camera that expose software supply chain security risks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/wansview-iot-camera-flaw-exposes-supply-chain-security-risks/
-
1 in 4 businesses hit by cyber attacks through their supply chain in the last year
One in four UK businesses (26%) have suffered a cyber incident that originated in their supply chain over the last year, according to new research from business continuity and disaster recovery specialist Databarracks. The finding is particularly striking given that organisations are highly aware of the risk they face: nearly half (48%) admit they have…
-
(g+) Miasma-Lieferkette: Warum gültige Signaturen plötzlich nicht mehr reichen
Tags: supply-chainEin selbst verbreitender Wurm kapert npm-Pakete mit gültigen Signaturen. Worauf Dev-Teams jetzt achten sollten. First seen on golem.de Jump to article: www.golem.de/news/miasma-lieferkette-warum-gueltige-signaturen-ploetzlich-nicht-mehr-reichen-2607-210992.html
-
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma”‘associated Node.js backdoor through trusted GitHub Actionsdriven release workflows and exposing high”‘value developer and CI/CD environments to remote access, credential theft, and further lateral movement. Malicious versions were shipped for @asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, and @asyncapi/specs@6.11.2 and 6.11.2-alpha.1, together accounting for…
-
Cybersicherheit in der Lieferkette als Wettbewerbsvorteil für Unternehmen
Unternehmen versuchen auf viele Weisen, ihr Kerngeschäft vor Cyberattacken zu schützen. Doch längst sind ihre Lieferketten zum bevorzugten Angriffsziel geworden. Die Gefahr droht nicht mehr nur in der Firmenzentrale, sondern an der Peripherie durch sogenannte Supply-Chain-Attacken. Das Berliner Sicherheitsunternehmen Maconia sieht eine verantwortlich und schnell handelnde Unternehmensführung als wichtigsten Faktor für die Sicherheit im gesamten……
-
AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware
AgentBaiting is the clearest sign yet that AI agents and their capability ecosystems have become a first”‘class malware delivery surface, with FakeGit’s 7,600″‘repo operation pushing SmartLoader and StealC directly into AI Skills and MCP workflows. By turning agent”‘readable READMEs, public AI registries, and GitHub trust signals into a weaponized “AI capability supply chain,” attackers now…
-
Hackers steal customer data from major hospital software vendor
The breach is another reminder of how vulnerable the healthcare industry is to supply-chain attacks. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/craneware-health-care-data-breach/825643/
-
How agentic endpoint security shuts down IDE-based supply chain attacks
Attention shifts from EDR to Agentic Endpoint Security to close visibility gaps that AI can exploit. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/how-agentic-endpoint-security-shuts-down-ide-based-supply-chain-attacks/825550/
-
North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images
A sophisticated North Korean threat campaign dubbed “Contagious Interview” has resurfaced with new delivery techniques, leveraging weaponized SVG image files to deploy the OTTERCOOKIE malware while coinciding with a separate supply chain intrusion targeting the Ruby ecosystem. Security researchers tracking DPRK-linked activity note that the campaign continues to impersonate recruiters and job interview workflows, luring…
-
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.The rogue gems are listed below – git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) – Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) –…
-
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an “unprecedented” four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron, First seen on thehackernews.com Jump…
-
The Cyber Express Weekly Roundup: TikTok Age Verification Probe, Healthcare Data Breach, Qantas Ruling, and Major Cyberattacks
Tags: breach, cyber, cyberattack, cybersecurity, data, data-breach, healthcare, risk, supply-chain, threat, vulnerabilityThis week’s cybersecurity roundup highlights growing concerns around online child safety, healthcare data protection, supply chain risks, and cyber threats affecting organizations worldwide. From regulatory scrutiny of digital platforms to large-scale vulnerabilities and operational disruptions, recent incidents show how cyber risks continue expanding across industries. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cybersecurity-weekly-roundup-tce/
-
Upwind Finds Coordinated Supply Chain Campaign Compromising Multiple AsyncAPI npm Packages
Upwind links compromised AsyncAPI npm packages to a coordinated supply chain attack spanning repositories, publishing pipelines, and developer systems at risk. First seen on hackread.com Jump to article: hackread.com/upwind-supply-chain-compromise-asyncapi-npm-packages/
-
Healthcare sector faces persistent supply-chain security, identity management challenges
A new report says doctors and nurses should train for cyberattacks the way firefighters train for major blazes — even if they expect them to be rare. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/healthcare-cybersecurity-risk-management-identity-fortified/825175/

