Advertisement
Axios npm Supply Chain Attack: Malicious Payloads and Mitigation
Axios npm versions 1.14.1 and 0.30.4 compromised via a malicious dependency injecting remote access trojans. Learn how to detect and remediate this threat.
Vercel Breach: Third-Party Context.ai Compromise Leads to Data Exposure
Vercel reports a security incident where a compromised third-party AI tool, Context.ai, allowed attackers to access internal Google Workspace accounts.
Asia's Digital Supply Chain Security: Regulatory Differences & AI Risks
Analyzes unique security risks in Asia's digital supply chain, highlighting challenges from regulatory disparities, interconnected ecosystems, and the rise of AI.
TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud
TeamPCP leverages supply chain attacks to compromise trusted software, facilitating large-scale credential harvesting, logistics theft, and payroll fraud.
Microsoft Windows Hardware Program Fast-Track Reinstatement Guide
Microsoft launches a fast-track process for developers to recover Windows Hardware Program accounts suspended during recent driver-signing security audits.
Trojanized CPU-Z and HWMonitor Distributed via CPUID Site Hack
Russian-speaking threat actors compromised the CPUID website to distribute STX RAT through trojanized versions of CPU-Z and HWMonitor diagnostic tools.
OpenAI Revokes macOS App Certificate Following Supply Chain Attack
OpenAI revokes its macOS app signing certificate after a GitHub Actions workflow downloaded a malicious Axios library version during a supply chain incident.
CPUID Supply Chain Attack: Trojanized CPU-Z Distributes STX RAT
Attackers compromised the CPUID website to distribute malicious versions of CPU-Z and HWMonitor containing the STX RAT during a 24-hour breach window.
GlassWorm Campaign: Zig Dropper Infects Developer IDEs via Open VSX
The GlassWorm campaign exploits the Open VSX registry with a malicious Zig-based dropper, impersonating WakaTime to compromise multiple developer IDEs.
Third-Party Risk Intelligence: Beyond Legacy Cyber Risk Ratings
Discover why modern cybersecurity strategies are shifting from static vendor risk ratings to dynamic, real-time third-party risk intelligence operations.
CVE-2024-21390: EngageLab SDK Vulnerability Risks Android Crypto Wallets
Microsoft reveals a vulnerability in the EngageLab SDK affecting millions of Android crypto wallet users, potentially allowing for private key theft.
Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack
Nextend's Smart Slider 3 Pro version 3.5.1.35 was compromised via a supply chain attack. Learn how to identify and remediate the backdoor today.
Microsoft Developer Account Suspensions Block OSS Security Patches
Microsoft's suspension of high-profile open-source developer accounts disrupts security patch delivery and introduces significant supply chain risks for Windows.
TeamPCP Supply Chain Campaign: Cisco Source Code Stolen, UNC6780 Activity
Analysis of the TeamPCP supply chain campaign, including the theft of Cisco source code and over 1,000 compromised SaaS environments tracked by Google GTIG as UNC6780.
litellm 1.82.8 Supply Chain Compromise via Malicious .pth File
Security analysis of a supply chain compromise in litellm 1.82.8 on PyPI, where a malicious .pth file enables automatic code execution on Python startup.
North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI
North Korean threat actors expand the Contagious Interview campaign, deploying 1,700 malicious packages across npm, PyPI, Go, and Rust ecosystems.
Snowflake Data Theft Via SaaS Integrator Breach: Mitigation
Snowflake customers face data theft due to compromised third-party SaaS integrators and stolen authentication tokens. Learn to secure integrations and detect compromise.
Axios Attack: Industrialized Social Engineering on NPM Maintainers
An analysis of the Axios NPM package attack reveals advanced, scaled social engineering campaigns targeting open-source maintainers, elevating supply chain risk.
AI-Assisted Supply Chain Attack Targets GitHub Misconfigurations
Analysis of the AI-assisted PRT-scan supply chain attack targeting GitHub misconfigurations. Learn about automated threats and securing repositories.
North Korean Social Engineering Targets Node.js Maintainers
North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.
Guardarian Users Targeted via 36 Malicious Strapi npm Packages
Analysis of a supply chain attack involving 36 malicious npm packages posing as Strapi plugins to target Guardarian users and harvest sensitive credentials.
36 Malicious npm Packages Target Strapi, Redis, and PostgreSQL
36 malicious npm packages disguised as Strapi CMS plugins target Redis and PostgreSQL environments to deploy persistent implants and reverse shells.
Axios npm Hijack Attempt: Detecting Social Engineering Tactics
North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.
European Commission AWS Breach: Trivy Supply Chain Attack Analysis
The European Commission confirms a 300GB data breach in its AWS environment linked to a Trivy supply chain attack. Learn about the impact and mitigations.