Advertisement
Miasma Supply Chain Attack: Defending Red Hat npm Environments
Analysis of the Miasma supply chain attack targeting Red Hat npm packages with credential-stealing worms. Technical details and mitigation guide for SOC teams.
Malicious npm Package Targets Claude AI User Data — Technical Analysis
Researchers discover mouse5212-super-formatter, a malicious npm package designed to exfiltrate sensitive files from Claude AI user directories.
RevEng.AI Secures $15M for AI-Powered Software Binary Analysis
RevEng.AI raises $15 million to scale BinNet, a proprietary AI model designed to automate binary analysis and detect hidden backdoors in software assets.
GlassWorm Malware Takedown: Disruption of Developer Supply Chain C2
CrowdStrike, Google, and Shadowserver disrupt the GlassWorm malware C2 infrastructure, halting a persistent developer-focused supply chain attack campaign.
Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain
Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.
Megalodon Malware: GitHub Repo Compromise & Secret Theft
Analysis of the Megalodon malware campaign, which compromised over 5,500 GitHub repositories in six hours to steal developer credentials and sensitive secrets. Learn how…
TeamPCP Supply Chain Attack Targets Microsoft SDKs and GitHub
TeamPCP expands its supply chain campaign to trojanize official Microsoft Python SDKs and infiltrate GitHub, requiring immediate dependency audits.
Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories
Attackers used automated commits to inject malicious GitHub Actions workflows into 5,500+ repositories, targeting CI/CD secrets and sensitive tokens.
TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks
The TrapDoor campaign targets npm, PyPI, and Crates.io with over 384 malicious versions designed to exfiltrate developer credentials and sensitive data.
Laravel Lang Hijack: Supply Chain Attack via Malicious GitHub Tags
Analysis of the Laravel Lang supply chain attack involving malicious GitHub tags v13.8.1 and v13.8.2 used to steal environmental secrets and credentials.
Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware
Security researchers identified a supply chain attack on Packagist involving eight infected packages that deploy Linux malware via GitHub Releases URLs.
npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks
GitHub introduces staged publishing for npm, requiring manual 2FA approval for package releases to mitigate malicious automated updates and account takeovers.
Laravel-Lang PHP Packages Compromised: Credential Stealer Alert
Multiple Laravel-Lang PHP packages have been compromised to deliver a cross-platform credential stealer. Learn how to detect and mitigate this supply chain threat.
Megalodon Campaign: 5,561 GitHub Repos Hit by Malicious Workflows
Automated Megalodon attack pushes 5,718 malicious commits to GitHub repositories to exfiltrate secrets via GitHub Actions workflows.
Grafana Codebase Stolen via TanStack Supply Chain Attack
Grafana confirms unauthorized access to private GitHub repositories after a developer token leaked in the TanStack breach was not rotated.
Securing Agentic AI Workflows with Advanced AI BOM Frameworks
Learn why CISOs must transition from traditional SBOMs to Agentic-Ready AI BOMs to manage risks in autonomous AI systems and data supply chains.
Software Supply Chain Security: Addressing Visibility Gaps
An analysis of the growing software supply chain crisis, focusing on the acceleration of vulnerability exploitation and the lack of systemic visibility.
GitHub Repository Breach Linked to TanStack Supply Chain Attack
GitHub confirms the breach of 3,800 internal repositories via a compromised VS Code extension linked to the TanStack npm supply chain attack.
GitHub Internal Repositories Breached via Nx Console VS Code Extension
GitHub confirms internal repository breach after an employee device was compromised by a poisoned Nx Console VS Code extension in a supply chain attack.
AI BOMs in Security: CISO Guide to Usability & Influence
Explore how CISOs can effectively prepare for and integrate AI Bill of Materials (AI BOMs) into their modern security programs, influencing their generation for better…
320+ @antv NPM Packages Compromised in Mini Shai-Hulud Attack
A maintainer account compromise has led to a major supply chain attack against Alibaba’s @antv NPM namespace, impacting over 320 visualization packages.
Typosquatting Evolution: How AI Lookalike Domains Target Supply Chains
Attackers are weaponizing AI-generated lookalike domains within third-party scripts, turning typosquatting into a sophisticated supply chain threat for enterprises.
AI BOM Implementation for Enterprise Security: Bridging Visibility
Analyze the rise of AI Bill of Materials (AIBOMs), regulatory drivers like the EU AI Act, and the technical challenges of securing opaque AI supply chains.
GitHub Repository Breach: 3,800 Repos Accessed via VS Code Extension
GitHub confirms a security incident where a malicious VS Code extension compromised an employee account, leading to the unauthorized access of 3,800 repos.