Advertisement
ModHeader Extension Pulled Over Dormant Browsing Data Collector
ModHeader, a popular browser extension with 1.6M installs on Chrome and Edge, was pulled by Google and Microsoft after a dormant browsing history collector was found.
Lidl Data Breach: Service Provider Hack Exposes Customer Info
Lidl notifies customers in Germany, Belgium, and Netherlands after a third-party service provider breach exposed personal data and order histories.
jscrambler 8.14.0 Compromised: Rust Infostealer Supply Chain Attack
The jscrambler 8.14.0 npm release was compromised with a malicious preinstall hook dropping a cross-platform Rust infostealer. Mitigate the threat now.
Injective Labs npm Package Compromise Steals Crypto Keys
Critical supply chain attack compromises Injective Labs SDK on GitHub, distributing malicious npm package `@injectivelabs/sdk-ts@1.20.21` to steal crypto wallet keys.
Injective SDK npm Compromise: Crypto Wallet Stealer Detected
A malicious version of the Injective SDK (injective-js) on npm was published via a GitHub compromise, deploying a crypto wallet stealer. Developers are at risk.
OpenMandriva Insider Sabotage: Risks of Contributor Access Misuse
OpenMandriva Linux reports an attempted internal sabotage by a disgruntled contributor, highlighting critical risks of insider threats in open-source projects.
Advertisement
npm 12 Enhances Supply Chain Security by Disabling Install Scripts
npm version 12 introduces critical security defaults, disabling install scripts and deprecating GATs, significantly mitigating JavaScript supply chain risks.
Fake Paysafe/Skrill SDKs on npm & PyPI Steal Credentials
Malicious packages impersonating Paysafe and Skrill SDKs on npm and PyPI platforms are stealing credentials from developers and users. Threat intelligence analysis.
GitHub Actions Attack Patterns Evade CI Security Scanners
Learn how sophisticated GitHub Actions attack patterns bypass traditional CI security scanners, exposing CI/CD pipelines to supply chain risks.
PolinRider: North Korean Hackers Push 108 Malicious Packages
Analysis of the PolinRider campaign where North Korean actors published 108 malicious packages and extensions across npm, Go, and Chrome ecosystems.
N. Korea-Linked npm Packages Mimic Rollup Polyfills for Data Theft
North Korea-linked actors use malicious npm packages ('rollup-packages-polyfill-core', 'rollup-runtime-polyfill-core') to steal developer secrets, mimicking Rollup…
Auditing AI-Driven Software Development: Security Governance Strategies
Learn how to audit AI-generated code and govern AI tool usage to mitigate security risks in modern software development lifecycles.
Windows 11 Emoji Panel GIF Fix Highlights Supply Chain Dependency
Microsoft resolves Windows 11 Emoji Panel GIF functionality after provider shutdown, underscoring third-party service dependencies in OS features.
Education Sector Third-Party Risk: Protecting Student Data
The education sector confronts growing third-party breach threats, endangering student data.
Linux Foundation's Project Akrites: Bolstering Open Source Security
Project Akrites aims to streamline vulnerability management across open source projects, enhancing reporting, patching, and disclosure processes for critical software.
Cordyceps CI/CD Flaws: Supply Chain Attacks on GitHub Repositories
Novee Security uncovered Cordyceps, a critical CI/CD workflow flaw exposing over 300 GitHub repositories to supply chain compromise, affecting major organizations.
Cordyceps: Defending Against Malicious Pull Requests in CI/CD
The Cordyceps campaign highlights critical CI/CD vulnerabilities in GitHub Actions, targeting high-profile projects like Apache Doris and Cloudflare Workers SDK.
OAuth Token Theft: How Icarus Targets Salesforce via Klue Breach
Attackers known as Icarus are exploiting compromised OAuth tokens from Klue to exfiltrate sensitive Salesforce data. Learn how to mitigate supply chain risks.
Malicious npm Packages Impersonate PostCSS to Deliver Windows RAT
Security researchers uncover malicious npm packages such as postcss-minify-selector-parser delivering Windows RATs via supply chain attacks. Audit your builds.
ShapedPlugin Supply Chain Attack: WordPress Pro Plugins Backdoored
Attackers compromised ShapedPlugin's distribution pipeline to inject backdoors into Pro WordPress plugins. Learn how to detect and remediate this supply chain threat.
North Korean Sapphire Sleet Compromises 140+ Mastra AI npm Packages
Microsoft attributes the Mastra AI supply chain attack to Sapphire Sleet (BlueNoroff), involving 140+ malicious npm packages targeting AI developers.
Klue Security Incident: Mitigating Third-Party Risk in Intelligence
Analyze the impact of the Klue security incident on Recorded Future. Learn how to secure SaaS integrations and improve third-party vendor risk management.
Novo Nordisk Breach: Securing Secrets in GitHub Development Pipelines
Analysis of the Novo Nordisk GitHub token leak and why secrets management must transition from static tools to identity-based security frameworks.
Klue Supply Chain Attack Hits Salesforce Instances of Security Firms
Attackers breached competitive intelligence platform Klue, exfiltrating data from Salesforce instances of customers including Huntress and Recorded Future.