Skip to main content
← All Articles

Category

Supply Chain

232 articles

Advertisement

Novo Nordisk Breach: Securing Secrets in GitHub Development Pipelines
MEDIUM
Supply Chain

Novo Nordisk Breach: Securing Secrets in GitHub Development Pipelines

Analysis of the Novo Nordisk GitHub token leak and why secrets management must transition from static tools to identity-based security frameworks.

Runtime Rebel Intel
4 min read · Jun 19, 2026
SU
HIGH
Supply Chain

Klue Supply Chain Attack Hits Salesforce Instances of Security Firms

Attackers breached competitive intelligence platform Klue, exfiltrating data from Salesforce instances of customers including Huntress and Recorded Future.

Runtime Rebel Intel
4 min read · Jun 19, 2026
Salesforce Disables Klue App Integration Following OAuth Token Abuse
HIGH
Supply Chain

Salesforce Disables Klue App Integration Following OAuth Token Abuse

Salesforce suspends Klue Battlecards integration after OAuth token abuse exposed customer data, highlighting significant SaaS supply chain security risks.

Runtime Rebel Intel
4 min read · Jun 19, 2026
SU
MEDIUM
Supply Chain

Nintendo Confirms Third-Party TinyPulse Data Breach — Supply Chain Risks

Nintendo confirms employee survey data was stolen via a breach at TinyPulse, a third-party vendor owned by WebMD subsidiary Internet Brands.

Runtime Rebel Intel
4 min read · Jun 19, 2026
SU
HIGH
Supply Chain

Malicious JetBrains Plugins Steal AI API Keys: Supply Chain Risks

Researchers discovered 15 malicious plugins on the JetBrains Marketplace designed to exfiltrate sensitive AI API keys from developers' IDE environments.

Runtime Rebel Intel
3 min read · Jun 17, 2026
SU
HIGH
Supply Chain

OptinMonster 2.6.5 Update: Managing CDN Supply Chain Attack Risks

Learn how the OptinMonster CDN supply chain attack compromised over 1 million WordPress sites and how to mitigate the risk of malicious script injection.

Runtime Rebel Intel
4 min read · Jun 15, 2026
SU
INFO
Supply Chain

npm 12 Security: Default Script Execution Changes to Mitigate Supply Chain Attacks

npm 12 introduces a critical change: 'npm install' will no longer run dependency scripts by default, significantly reducing software supply chain risks.

Runtime Rebel Intel
4 min read · Jun 13, 2026
400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer
HIGH
Supply Chain

400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer

Attackers compromised over 400 Arch User Repository (AUR) packages to deploy Rust-based infostealers and eBPF rootkits, targeting developer credentials.

Runtime Rebel Intel
4 min read · Jun 12, 2026
SU
MEDIUM
Supply Chain

AUR Compromise: 400+ Packages Distributing Rootkits and Infostealers

Over 400 Arch User Repository (AUR) packages compromised to deploy Linux rootkits and harvest credentials, tokens, and sensitive developer data.

Runtime Rebel Intel
4 min read · Jun 12, 2026
GitHub to Disable npm Install Scripts by Default in Version 12
MEDIUM
Supply Chain

GitHub to Disable npm Install Scripts by Default in Version 12

GitHub announces breaking changes for npm v12, disabling install scripts by default to prevent malicious code execution and enhance supply chain security.

Runtime Rebel Intel
4 min read · Jun 11, 2026
SU
HIGH
Supply Chain

GitHub Supply Chain Disruption: Microsoft Repos Abused to Host Malware

GitHub recently disabled 73 official Microsoft repositories after they were targeted in a massive campaign pushing password-stealing malware to developers.

Runtime Rebel Intel
4 min read · Jun 9, 2026
Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis
HIGH
Supply Chain

Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis

Microsoft restores some GitHub repositories after 73 projects were hit by Miasma's supply chain attack to inject information stealers. Learn detection steps.

Runtime Rebel Intel
4 min read · Jun 9, 2026
SU
HIGH
Supply Chain

Shai-Hulud Attack: Trojanized PyPI Packages Steal Developer Secrets

New Shai-Hulud supply chain attack compromises 19 science-focused PyPI packages, distributing malware to steal developer credentials and secrets.

Runtime Rebel Intel
4 min read · Jun 8, 2026
SU
MEDIUM
Supply Chain

AI Code Generation Security Risks: Managing Vibe Coding Governance

Learn how to manage AI code generation security risks and implement governance for vibe coding practices in the software development lifecycle.

Runtime Rebel Intel
4 min read · Jun 8, 2026
VS Code Extension Auto-Update Delay: Mitigating Supply Chain Attacks
MEDIUM
Supply Chain

VS Code Extension Auto-Update Delay: Mitigating Supply Chain Attacks

Microsoft introduces a two-hour delay for VS Code extension auto-updates to prevent rapid compromise during software supply chain attacks.

Runtime Rebel Intel
4 min read · Jun 8, 2026
SU
MEDIUM
Supply Chain

Toshiba and Muji Impacted by Polyfill Supply Chain Attack

Toshiba and Muji have warned of malicious login prompts appearing on their sites. This follows the takeover of the Polyfill.io domain used for script injection.

Runtime Rebel Intel
4 min read · Jun 6, 2026
npm Supply Chain Attack: IronWorm and Miasma Malware Analysis
HIGH
Supply Chain

npm Supply Chain Attack: IronWorm and Miasma Malware Analysis

Threat actors target npm developers with the IronWorm info stealer and Miasma worm, utilizing eBPF rootkits to exfiltrate secrets and ensure persistence.

Runtime Rebel Intel
3 min read · Jun 5, 2026
SU
INFO
Supply Chain

OWASP CVE Lite CLI: Strengthening Supply Chain Security for Developers

OWASP's CVE Lite CLI provides a fast, local method for developers to identify vulnerable dependencies and mitigate supply chain risks early in development.

Runtime Rebel Intel
4 min read · Jun 5, 2026
IronWorm: Rust-Written Malware Hits npm Supply Chain Developers
HIGH
Supply Chain

IronWorm: Rust-Written Malware Hits npm Supply Chain Developers

Analysis of the Rust-written IronWorm malware targeting npm supply chain developers. Learn how it steals credentials and propagates, and discover essential mitigation…

Runtime Rebel Intel
5 min read · Jun 5, 2026
SU
HIGH
Supply Chain

Hola Browser for Windows Compromised: Cryptominer Delivery via Supply Chain

Critical alert: Hola Browser for Windows compromised in a supply chain attack, delivering an undeclared cryptominer. Learn to detect and mitigate the threat.

Runtime Rebel Intel
4 min read · Jun 5, 2026
SU
MEDIUM
Supply Chain

Optimizing TPRM: Closing the Vendor Risk Performance Gap

Analyze the disconnect between third-party risk management perceptions and reality. Learn strategies to optimize TPRM performance and mitigate supply chain threats.

Runtime Rebel Intel
3 min read · Jun 4, 2026
SU
HIGH
Supply Chain

IronWorm Malware: 36 npm Packages Identified in Supply Chain Attack

Security researchers discover a campaign delivering IronWorm infostealer malware via 36 malicious npm packages using preinstall script execution hooks.

Runtime Rebel Intel
3 min read · Jun 4, 2026
Anthropic Claude Code GitHub Action Flaw Enables Repo Hijacking
HIGH
Supply Chain

Anthropic Claude Code GitHub Action Flaw Enables Repo Hijacking

A critical flaw in Anthropic's Claude Code GitHub Action allowed attackers to hijack public repositories using malicious issues, posing supply chain risks.

Runtime Rebel Intel
4 min read · Jun 4, 2026
SU
HIGH
Supply Chain

Red Hat npm Supply Chain Compromise: Miasma Steals Dev Credentials

Over 30 Red Hat npm packages under @redhat-cloud-services were compromised in a supply chain attack distributing Miasma malware to steal developer credentials.

Runtime Rebel Intel
5 min read · Jun 2, 2026