Advertisement
Grafana GitHub Breach: Source Code Exposed via TanStack npm Attack
Grafana Labs confirms a GitHub breach exposing internal source code following a TanStack npm supply chain attack. No customer production systems compromised.
AI Bills of Materials: Essential for Proactive AI Supply Chain Security
Explore the emerging necessity of AI Bills of Materials (AI BOMs) to manage complex AI supply chain risks and enhance transparency in AI systems by 2026.
GitHub Actions Supply Chain Attack: actions-cool/issues-helper
Analysis of the actions-cool/issues-helper supply chain attack where tags were redirected to steal credentials. Learn how to detect and mitigate this threat.
Nx Console 18.95.0 Compromise: VS Code Extension Credential Stealer
Security researchers have identified a compromised version of the Nx Console VS Code extension (18.95.0) containing a malicious credential stealer.
TeamPCP Jenkins Plugin Compromise and Mini Shai-Hulud Worm Analysis
TeamPCP escalates its supply chain campaign with a confirmed Jenkins plugin compromise and a self-spreading worm targeting the npm and PyPI ecosystems.
Shai-Hulud Infostealer Surfaces in Malicious npm Package Campaign
Leaked Shai-Hulud malware is targeting Node.js developers via malicious npm packages, exfiltrating sensitive data and credentials to Telegram-based C2.
Grafana GitHub Token Compromise: Codebase Stolen via PAT
Grafana Labs reports a source code breach after attackers leveraged a stolen GitHub Personal Access Token. Analysis of the impact and mitigation steps.
Developer Workstations: The New Front in Software Supply Chain Attacks
A surge in attacks targeting npm, PyPI, and Docker Hub highlights a shift toward stealing developer credentials and API keys from workstations and CI/CD pipelines.
Grafana GitHub Token Leak: Codebase Access and Extortion Attempt
Grafana discloses a security incident where an unauthorized party used a GitHub token to download source code, leading to a failed extortion attempt.
Microsoft Introduces Remote Rollback for Faulty Windows Drivers
Microsoft expands its Known Issue Rollback capability to Windows drivers, allowing remote remediation of faulty updates that cause boot loops or crashes.
OpenAI Breach: TanStack Supply Chain Attack Impacts Employee Devices
OpenAI confirms two employee devices compromised in a TanStack supply chain attack affecting npm and PyPI packages, prompting certificate rotation.
Malicious node-ipc Versions Compromise Developer Secrets via Supply Chain
Three versions of the node-ipc npm package (9.1.6, 9.2.3, 12.0.1) contain stealer/backdoor functionality targeting developer secrets. Urgent update advised.
RubyGems Supply Chain Attack: Malicious Packages Target UK Govt
Threat actors leverage malicious RubyGems packages, embedding scrapers that target public-facing UK government servers, utilizing the platform as a data dead drop…
RubyGems Suspends Registrations Due to Malicious Package Influx
RubyGems maintainers suspended new user registrations after detecting an automated attack involving over 500 malicious packages targeting platform resources.
Hugging Face Model Supply Chain Vulnerability: Tokenizer Hijacking
Attackers can weaponize Hugging Face AI models by manipulating tokenizer files, leading to model output hijacking and sensitive data exfiltration. Learn how to mitigate…
RubyGems Signups Suspended Amid Massive Malicious Package Attack
RubyGems halts new registrations after hundreds of malicious packages flood the registry, signaling a major supply chain security threat for Ruby developers.
Shai-Hulud Supply Chain Attack: Malicious npm and Mistral Packages
The Shai-Hulud campaign targets developers with over 300 signed npm and PyPI packages impersonating TanStack and Mistral to steal sensitive credentials.
Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages
TeamPCP actor compromises major npm and PyPI packages including TanStack and Mistral AI via the Mini Shai-Hulud worm, deploying profiling malware.
FCC Adjusts Foreign Router Ban: Supply Chain Security Implications
The FCC has modified its ban on non-compliant foreign-made routers, extending deadlines for federal agencies. This impacts government supply chain security efforts.
Compromised Checkmarx Jenkins Plugin Spreads Infostealer
Official Checkmarx Jenkins AST plugin version 2023.2.7 was compromised with an infostealer, risking credentials and system data. Immediate uninstallation and credential…
Checkmarx Jenkins AST Plugin Compromised in TeamPCP Attack
TeamPCP compromised the Checkmarx Jenkins AST plugin on the Jenkins Marketplace. Defenders must revert to version 2.0.13 to secure CI/CD pipelines.
Defending CI/CD Pipelines with Build Application Firewalls
Examine how Build Application Firewalls (BAF) provide runtime protection for software pipelines to mitigate sophisticated supply chain attacks and data theft.
Fake OpenAI Privacy Filter Repository Distributes Rust Info-Stealer
A malicious Hugging Face repository impersonating OpenAI's privacy tool reached 244k downloads, delivering a Rust-based information stealer to Windows users.
PyPI Supply Chain Threat: Deceptive Packages Target Developers
Analysis of malicious Python packages such as cryptography-util using deceptive naming to exfiltrate Discord tokens and system metadata via webhooks.