Tag: supply-chain
-
Healthcare sector faces persistent supply-chain security, identity management challenges
A new report says doctors and nurses should train for cyberattacks the way firefighters train for major blazes — even if they expect them to be rare. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/healthcare-cybersecurity-risk-management-identity-fortified/825175/
-
The AI Supply Chain Is Your Latest Unguarded Attack Surface
When You Consume AI, You Inherit Every Upstream Risk You Can’t See Most enterprises don’t build AI, they consume it through APIs, open-source models and orchestration frameworks. Each layer inherits upstream risk with little visibility. This piece maps the four-layer AI supply chain and the existing security disciplines that bring it under control. First seen…
-
MSPs ideally placed to improve supply chain resilience
Research from Proxima indicates more CEOs are worried about their ability to defend from attacks originating outside the organisation First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366645762/MSPs-ideally-placed-to-improve-supply-chain-resilience
-
Why SBOMs, signing, and provenance still don’t tell you if software is safe
We have made real progress in software supply chain security, improving visibility into software components, authenticity and build integrity. Much of this progress traces … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/sbom-zero-trust-for-code/
-
Jscrambler npm Supply Chain Attack Steals Cloud Credentials and Crypto Wallet Secrets
A malicious actor compromised the Jscrambler npm package and published several trojanized versions that included a hidden, cross-platform credential-stealing payload. The attack targeted developers, build pipelines, and CI/CD systems, where npm installations could access source code, cloud credentials, deployment tokens, and sensitive environment variables. Jscrambler npm Supply Chain Attack Socket’s Research Team detected the initial…
-
npm and PyPI Malware Campaign Exfiltrates CI/CD Secrets Through Fake Payment SDKs
A coordinated supply-chain campaign that pushed 17 malicious packages across npm and PyPI, masquerading as SDKs for well-known payment services including PaySafe, Skrill and Neteller. The campaign’s packages 17 npm modules published with four rapid versions each and four PyPI packages access with single malicious releases presented as convenient payment SDK facades but contained logic…
-
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
Software supply chain security was hard enough. Then AI joined the build pipeline.For five years, “software supply chain security” meant one question: what’s in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? SolarWinds, Log4Shell, and XZ Utils all taught the same lesson: the risk lives…
-
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
Software supply chain security was hard enough. Then AI joined the build pipeline.For five years, “software supply chain security” meant one question: what’s in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? SolarWinds, Log4Shell, and XZ Utils all taught the same lesson: the risk lives…
-
TeamPCP Supply Chain Attacks Feed VECT Ransomware With Stolen CI/CD Credentials
TeamPCP’s wide-scale supply-chain compromises have materially fueled VECT ransomware operations by supplying a vast archive of stolen CI/CD credentials, reshaping how organizations should measure ransomware exposure. Rather than choosing victims in advance, TeamPCP contaminated widely used components Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK access so that any organization that installed those packages…
-
Berechtigungen in der Lieferkette werden zum kritischen Einfallstor
Regulierung schützt nicht vor Angriffen mit kompromittierten Identitäten und Zugangsdaten Identitäts-Sicherheit hingegen schon. Exemplarische Vorfälle im Juni, wie bei der V-Bank, bei dem Hacker über einen IT-Dienstleister Zugriff auf Systeme erlangten und einen Datenabfluss verursachten, oder das Datenleck bei Lastpass, das durch eine Schwachstelle bei einem Drittanbieter ausgenutzt wurde, zeigen exemplarisch eine bittere Wahrheit: […]…
-
Thousands of MCP Servers Found Vulnerable to File Access and Injection Attacks
Thousands of Model Context Protocol (MCP) servers, widely used to connect large language models (LLMs) to external systems, have been found vulnerable to critical security flaws, including arbitrary file access, command injection, server-side request forgery (SSRF), and SQL injection, raising significant concerns about AI supply chain security. A large-scale analysis of 9,695 MCP servers across…
-
North Korean PolinRider supply chain attack targets 108 unique repos
First seen on scworld.com Jump to article: www.scworld.com/news/north-korean-polinrider-supply-chain-attack-targets-108-unique-repos
-
Alibaba Bans Claude Code Over Spy-Like Tracking Code
Supply-Chain Risks Cited After Hidden Code Checked for China-Related Indicators. The latest twist in the U.S.-China AI race sees Alibaba ban Anthropic’s Claude Code after hidden tracking code sparked backlash, adding another layer to an increasingly bitter battle over AI leadership. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/alibaba-bans-claude-code-over-spy-like-tracking-code-a-32162
-
Vect and TeamPCP Cybercrime Groups Link for Ransomware Hits
Supply-Chain Victims Also at Risk From Poorly Coded, Data-Shredding Crypto-Locker. Recently announced tie-ups between ransomware group Vect, supply-chain attack specialists TeamPCP and data-leak stalwart Lapsus$ show cybercriminals continuing their quest to monetize their attacks and develop new profit streams. But not all has been smooth sailing. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/vect-teampcp-cybercrime-groups-link-for-ransomware-hits-a-32159
-
The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident
Vercel breach happened after an employee used an unvetted AI tool. Attackers exploited it as a trusted link to access systems, steal data, and extort $2M. The Vercel breach of April 2026 did not begin with a classic zero-day exploit, a misconfigured cloud bucket, or a sophisticated nation-state infrastructure implant. Instead, it unfolded when an…
-
FBI Says TeamPCP Uses Trojanized Updates to Steal Cloud Tokens, SSH Keys, and Kubernetes Secrets
Tags: access, advisory, attack, cloud, cyber, cybercrime, exploit, group, kubernetes, software, supply-chain, updateThe Federal Bureau of Investigation (FBI) has issued an urgent FLASH advisory warning that the cybercriminal group TeamPCP is weaponizing trojanized software updates to harvest cloud access tokens, SSH keys, and Kubernetes secrets at scale. This campaign represents one of the most sophisticated software supply chain attacks observed in 2026, exploiting trust in widely deployed…
-
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Tags: access, citrix, credentials, exploit, group, monitoring, ransomware, supply-chain, tactics, threat, vulnerabilityThreat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.”Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral First seen on thehackernews.com Jump to…
-
ChocoPoC Campaign Abuses GitHub PoC Repositories to Steal Browser Credentials
A coordinated supply-chain campaign has been weaponizing GitHub proof-of-concept (PoC) repositories to compromise vulnerability researchers and penetration testers, delivering a stealthy Python Remote Access Trojan (RAT) dubbed “ChocoPoC.” The lure is simple and effective: newly disclosed high-severity CVEs create urgency for fast PoC and scanner module development. Adversaries create seemingly legitimate PoC repositories that include…
-
‘Phantom Squatting’: An Emerging AI-Driven Supply Chain Threat
LLMs consistently hallucinate Web domains for legitimate brands that attackers can register for malicious activity in a difficult-to-detect attack vector. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/phantom-squatting-ai-driven-supply-chain-threat
-
Attackers Register AI-Hallucinated Domains to Deliver Phishing Kits and Malware
An emergent supply-chain attack vector they term >>phantom squatting,<< in which large language models (LLMs) routinely hallucinate plausible but nonexistent domains for legitimate brands and adversaries then preemptively register those domains to host phishing kits, malware, and other malicious infrastructure. By systematically probing two distinct LLM families across temperature settings, Unit 42 generated a 2.1…
-
XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t
Police arrested the alleged admin of XSS.is, a major cybercrime forum whose trusted escrow service helped power the underground economy. On 22 July 2025, French and Ukrainian police arrested a 38-year-old man in Kyiv and shut down XSS.is, the most influential Russian-language cybercrime forum of the past decade. Europol, which coordinated the operation under the…
-
Aikido Buys Root for $70M to Automate Open-Source Patching
Deal Adds Hardened Packages, Automated CVE Fixes to Application Security Platform. Belgian software vendor Aikido Security acquired Boston-based Root for $70 million to embed automated vulnerability remediation into its application security platform, enabling enterprises to deploy hardened open-source packages and container images while reducing software supply-chain risk. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/aikido-buys-root-for-70m-to-automate-open-source-patching-a-32118
-
29th June Threat Intelligence Report
Polymarket, a large cryptocurrency-based prediction market, has confirmed a supply chain attack after a third-party frontend vendor breach led to malicious JavaScript being injected into its website. Attackers tricked users into approving fraudulent […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/29th-june-threat-intelligence-report-2/
-
ClawHavoc Attack Hits ClawHub With 1,184 Malicious Skills and 247,000 Installations
The AI-agent ecosystem experienced its largest supply-chain compromise to date when ClawHavoc detonated across ClawHub, the official skill marketplace for OpenClaw. Our full AIG-powered scan of nearly 50,000 ClawHub Skills found 1,184 clearly malicious packages tied to 12 compromised publisher accounts and confirmed 247,693 installations. The campaign combined typosquatting, ranking manipulation, and multi-stage payload delivery…
-
Post-Quantum Security Spurs National Sovereignty Thinking
AI Export Controls Expose Hidden Risks to Post-Quantum Cryptography Migrations. Security leaders warn that post-quantum cryptography migration is creating new dependencies on foreign vendors, hyperscalers and supply chains, raising questions about resilience, crypto-agility and national control over critical security infrastructure. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/post-quantum-security-spurs-national-sovereignty-thinking-a-32095
-
Post-Quantum Security Spurs National Sovereignty Thinking
AI Export Controls Expose Hidden Risks to Post-Quantum Cryptography Migrations. Security leaders warn that post-quantum cryptography migration is creating new dependencies on foreign vendors, hyperscalers and supply chains, raising questions about resilience, crypto-agility and national control over critical security infrastructure. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/post-quantum-security-spurs-national-sovereignty-thinking-a-32095
-
Post-Quantum Security Spurs National Sovereignty Thinking
AI Export Controls Expose Hidden Risks to Post-Quantum Cryptography Migrations. Security leaders warn that post-quantum cryptography migration is creating new dependencies on foreign vendors, hyperscalers and supply chains, raising questions about resilience, crypto-agility and national control over critical security infrastructure. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/post-quantum-security-spurs-national-sovereignty-thinking-a-32095
-
Polymarket customers lose $3 million in supply-chain attack
Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform’s frontend following a breach at a third-party vendor. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/polymarket-customers-lose-3-million-in-supply-chain-attack/
-
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propagated to the Go ecosystem.”The latest activity includes malicious npm releases affecting LeoPlatform and RStreams packages, GitHub Actions workflow abuse,…
-
Mini Shai-Hulud Worm Poisons LeoPlatform npm Packages to Steal Developer and CI/CD Secrets
A fresh supply-chain wave tied to the Mini Shai-Hulud, Miasma, and Hades malware families is actively poisoning npm packages in the LeoPlatform and RStreams ecosystems and expanding into source-repository compromises. The intrusion blends registry poisoning, install-time execution via binding.gyp, Bun-staged JavaScript loaders, GitHub Actions abuse, and persistence hooks for IDEs and AI coding assistants an…

