Advertisement
Novo Nordisk Breach: Securing Secrets in GitHub Development Pipelines
Analysis of the Novo Nordisk GitHub token leak and why secrets management must transition from static tools to identity-based security frameworks.
Klue Supply Chain Attack Hits Salesforce Instances of Security Firms
Attackers breached competitive intelligence platform Klue, exfiltrating data from Salesforce instances of customers including Huntress and Recorded Future.
Salesforce Disables Klue App Integration Following OAuth Token Abuse
Salesforce suspends Klue Battlecards integration after OAuth token abuse exposed customer data, highlighting significant SaaS supply chain security risks.
Nintendo Confirms Third-Party TinyPulse Data Breach — Supply Chain Risks
Nintendo confirms employee survey data was stolen via a breach at TinyPulse, a third-party vendor owned by WebMD subsidiary Internet Brands.
Malicious JetBrains Plugins Steal AI API Keys: Supply Chain Risks
Researchers discovered 15 malicious plugins on the JetBrains Marketplace designed to exfiltrate sensitive AI API keys from developers' IDE environments.
OptinMonster 2.6.5 Update: Managing CDN Supply Chain Attack Risks
Learn how the OptinMonster CDN supply chain attack compromised over 1 million WordPress sites and how to mitigate the risk of malicious script injection.
npm 12 Security: Default Script Execution Changes to Mitigate Supply Chain Attacks
npm 12 introduces a critical change: 'npm install' will no longer run dependency scripts by default, significantly reducing software supply chain risks.
400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer
Attackers compromised over 400 Arch User Repository (AUR) packages to deploy Rust-based infostealers and eBPF rootkits, targeting developer credentials.
AUR Compromise: 400+ Packages Distributing Rootkits and Infostealers
Over 400 Arch User Repository (AUR) packages compromised to deploy Linux rootkits and harvest credentials, tokens, and sensitive developer data.
GitHub to Disable npm Install Scripts by Default in Version 12
GitHub announces breaking changes for npm v12, disabling install scripts by default to prevent malicious code execution and enhance supply chain security.
GitHub Supply Chain Disruption: Microsoft Repos Abused to Host Malware
GitHub recently disabled 73 official Microsoft repositories after they were targeted in a massive campaign pushing password-stealing malware to developers.
Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis
Microsoft restores some GitHub repositories after 73 projects were hit by Miasma's supply chain attack to inject information stealers. Learn detection steps.
Shai-Hulud Attack: Trojanized PyPI Packages Steal Developer Secrets
New Shai-Hulud supply chain attack compromises 19 science-focused PyPI packages, distributing malware to steal developer credentials and secrets.
AI Code Generation Security Risks: Managing Vibe Coding Governance
Learn how to manage AI code generation security risks and implement governance for vibe coding practices in the software development lifecycle.
VS Code Extension Auto-Update Delay: Mitigating Supply Chain Attacks
Microsoft introduces a two-hour delay for VS Code extension auto-updates to prevent rapid compromise during software supply chain attacks.
Toshiba and Muji Impacted by Polyfill Supply Chain Attack
Toshiba and Muji have warned of malicious login prompts appearing on their sites. This follows the takeover of the Polyfill.io domain used for script injection.
npm Supply Chain Attack: IronWorm and Miasma Malware Analysis
Threat actors target npm developers with the IronWorm info stealer and Miasma worm, utilizing eBPF rootkits to exfiltrate secrets and ensure persistence.
OWASP CVE Lite CLI: Strengthening Supply Chain Security for Developers
OWASP's CVE Lite CLI provides a fast, local method for developers to identify vulnerable dependencies and mitigate supply chain risks early in development.
IronWorm: Rust-Written Malware Hits npm Supply Chain Developers
Analysis of the Rust-written IronWorm malware targeting npm supply chain developers. Learn how it steals credentials and propagates, and discover essential mitigation…
Hola Browser for Windows Compromised: Cryptominer Delivery via Supply Chain
Critical alert: Hola Browser for Windows compromised in a supply chain attack, delivering an undeclared cryptominer. Learn to detect and mitigate the threat.
Optimizing TPRM: Closing the Vendor Risk Performance Gap
Analyze the disconnect between third-party risk management perceptions and reality. Learn strategies to optimize TPRM performance and mitigate supply chain threats.
IronWorm Malware: 36 npm Packages Identified in Supply Chain Attack
Security researchers discover a campaign delivering IronWorm infostealer malware via 36 malicious npm packages using preinstall script execution hooks.
Anthropic Claude Code GitHub Action Flaw Enables Repo Hijacking
A critical flaw in Anthropic's Claude Code GitHub Action allowed attackers to hijack public repositories using malicious issues, posing supply chain risks.
Red Hat npm Supply Chain Compromise: Miasma Steals Dev Credentials
Over 30 Red Hat npm packages under @redhat-cloud-services were compromised in a supply chain attack distributing Miasma malware to steal developer credentials.