Topic · 39 stories
Supply chain attacks: compromised software, news
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Timeline
- Google analyst spent months inside TeamPCP supply-chain gang Security
- Malicious npm package hides loader in runtime code Security
- Compromised Packagist themes serve iOS exploit chain Security
- EndlessDoors backdoor found in Zbtlink router firmware gives Chinese server root control Security
- Shai-Hulud npm worm returns with identical payload, bypassing new scanning Security
- North Korea Trojanized HAProxy in South Korea, Turning SSL Termination Into Wiretap Security
- Poisoned Scanner Compromise Hits 2,500 Companies via AI Supply-Chain Package Security
- Hackers Abuse npm Mirrors to Host Phishing Pages on Legitimate Domains Security
- UK Proposes New Powers to Ban Essential Services from Buying Risky Tech Vendors Security
- Supply-Chain Attack Infects Android Car Head Units With Proxy Botnet Malware Security
Show older (29 stories)
- Kimi Desktop Updater Installs Unverified Code from Mutable CDN Security
- Extension Resurrection: Shadow dependencies in IDE packs open supply-chain attack vector Security
- LiteLLM supply chain attack compromises thousands of enterprises, 153GB of secrets leaked Security
- Hidden Backdoor in Zbtlink Routers Opens Root Access on 100,000 Devices Security
- npm Attack Uses Provenance Attestations as Camouflage in 400+ Package Supply Chain Breach Security
- Head Mare Breaches TrueConf Servers to Trojanize Client Installers with Backdoors Security
- ENDLESSDOORS backdoor found in Chinese routers sold under multiple brand names Security
- Persistent ‘EndlessDoors’ Backdoor Found in Over 20 Zbtlink Router Models Security
- ChainDrop worm compromises 1,300+ npm packages Security
- Arch Linux freezes AUR adoption as Tor-backed Rust infostealer hits third wave Security
- Amazon links NPM supply chain attacks to North Korean hacker group Security
- Amazon Attributes Debug, Chalk, and Axios npm Attacks to North Korean Hackers Security
- New ‘hallusquatting’ attack exploits AI coding assistants to install malware AI
- FakeGit Campaign Uses 7,600 GitHub Repos to Distribute Malware Security
- Cisco Sounds Alarm Over New Russian Malware Campaign Hitting Firms in US and Europe Security
- Slopsquatting Exploits LLM Hallucinations for Software Supply Chain Attacks AI
- HalluSquatting Exploits AI Hallucinations to Build Agentic Botnets Security
- Operation Muck and Load Uses 200 GitHub Repositories to Deliver Malware Security
- Two-Click RCE in Meccha Chameleon Exploits Steam Workshop Security
- North Korean npm Packages Impersonate Rollup Polyfill Tools Security
- AI Coding Agents Bypass Package Verification, Fueling Supply Chain Attacks AI
- Polymarket Loses $3.1M to Frontend Hack Amid CFTC Investigation Security
- 15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers Security
- LastPass Breached via Klue Supply-Chain Attack: Customer Data Stolen, Vaults Intact Privacy
- LastPass Breached via Klue Supply-Chain Attack Security
- Cordyceps: Malicious Pull Requests Compromise Developer Workflows Security
- Steam’s Wallpaper Engine Workshop Hijacked with Malicious Wallpapers Security
- Attackers Hijacked Over 1,500 Arch Linux Packages in Supply Chain Attack Security
- Microsoft GitHub Repositories Compromised with Credential-Stealing Malware Security