<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — Supply Chain</title><description>Cybersecurity articles in Supply Chain on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CISA&apos;s Updated SBOM Guidance: Enhancing Software Supply Chain Transparency</title><link>https://runtimerebel.com/blog/cisa-s-updated-sbom-guidance-enhancing-software-supply-chain-transparency</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-s-updated-sbom-guidance-enhancing-software-supply-chain-transparency</guid><description>CISA has released updated SBOM guidance, refining field definitions for greater software supply chain transparency. Debate continues on its impact on risk management.</description><pubDate>Sat, 01 Aug 2026 10:01:00 GMT</pubDate><category>SBOM</category><category>CISA</category><category>Software Supply Chain</category><category>Guidance</category><category>Cybersecurity Policy</category></item><item><title>Adform Script Poisoning: Crypto Wallet Swapping Attack</title><link>https://runtimerebel.com/blog/adform-script-poisoning-crypto-wallet-swapping-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/adform-script-poisoning-crypto-wallet-swapping-attack</guid><description>Adform&apos;s JavaScript was poisoned to swap crypto wallet addresses on customer sites. Understand this supply chain attack and how to protect against client-side script…</description><pubDate>Sat, 01 Aug 2026 10:00:39 GMT</pubDate><category>Adform</category><category>JavaScript</category><category>Cryptocurrency</category><category>Wallet Swapping</category><category>Supply Chain Attack</category><category>Client Side Attack</category></item><item><title>North Korean Hackers Exploit npm Supply Chain: Debug &amp; Chalk Under Attack</title><link>https://runtimerebel.com/blog/north-korean-hackers-exploit-npm-supply-chain-debug-chalk-under-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-hackers-exploit-npm-supply-chain-debug-chalk-under-attack</guid><description>Amazon links North Korean hackers to supply chain attacks on popular npm packages Debug and Chalk, highlighting nation-state threat to open-source ecosystems.</description><pubDate>Thu, 30 Jul 2026 21:12:11 GMT</pubDate><category>North Korean Hackers</category><category>NPM</category><category>Supply Chain Attack</category><category>Debug</category><category>Chalk</category><category>Software Supply Chain Security</category></item><item><title>Defending Against the 1,444% Surge in Open Source Supply Chain Attacks</title><link>https://runtimerebel.com/blog/defending-against-the-1444-surge-in-open-source-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/defending-against-the-1444-surge-in-open-source-supply-chain-attacks</guid><description>GTIG reports a massive 1,444% spike in open source repository compromises. Learn how to mitigate threats from actors like UNC6780 and MIDNIGHT NEPTUNE.</description><pubDate>Thu, 30 Jul 2026 14:10:41 GMT</pubDate><category>UNC6780</category><category>MIDNIGHT NEPTUNE</category><category>Open Source Security</category><category>GitHub Actions</category><category>NPM Security</category></item><item><title>FCC Blocks Foreign Robots and Power Inverters via Covered List</title><link>https://runtimerebel.com/blog/fcc-blocks-foreign-robots-and-power-inverters-via-covered-list</link><guid isPermaLink="true">https://runtimerebel.com/blog/fcc-blocks-foreign-robots-and-power-inverters-via-covered-list</guid><description>The FCC has added foreign-produced mobile robots and networked power inverters to the Covered List, citing supply chain risks and national security concerns.</description><pubDate>Thu, 30 Jul 2026 10:26:21 GMT</pubDate><category>FCC</category><category>Covered List</category><category>Mobile Robots</category><category>Power Inverters</category><category>Supply Chain Security</category><category>National Security</category></item><item><title>Compromised Joyfill npm Packages Deliver DEV#POPPER RAT</title><link>https://runtimerebel.com/blog/compromised-joyfill-npm-packages-deliver-dev-popper-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-joyfill-npm-packages-deliver-dev-popper-rat</guid><description>Beta versions of @joyfill/layouts and @joyfill/components npm packages compromised to deliver a DEV#POPPER RAT upon import. Node.js users at risk.</description><pubDate>Wed, 29 Jul 2026 06:32:18 GMT</pubDate><category>Joyfill</category><category>NPM</category><category>Supply Chain Attack</category><category>RAT</category><category>DEV POPPER</category><category>Node Js</category></item><item><title>CubePilot DNS Hijacking: How Attackers Intercepted UAV Flight Data</title><link>https://runtimerebel.com/blog/cubepilot-dns-hijacking-how-attackers-intercepted-uav-flight-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/cubepilot-dns-hijacking-how-attackers-intercepted-uav-flight-data</guid><description>CubePilot drone software developer hit by DNS hijacking attack. Learn how to detect the exploit and verify ArduPilot firmware integrity in this guide.</description><pubDate>Wed, 29 Jul 2026 02:45:31 GMT</pubDate><category>CubePilot</category><category>DNS Hijacking</category><category>UAV Security</category><category>ArduPilot</category><category>Supply Chain Attack</category></item><item><title>GitHub and PyPI Policy Updates Target Supply Chain Security</title><link>https://runtimerebel.com/blog/github-and-pypi-policy-updates-target-supply-chain-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-and-pypi-policy-updates-target-supply-chain-security</guid><description>GitHub and PyPI introduce new restrictions to thwart supply chain attacks, including a Dependabot cooldown and limits on historical package file uploads.</description><pubDate>Mon, 27 Jul 2026 14:40:00 GMT</pubDate><category>GitHub</category><category>PyPI</category><category>Supply Chain Security</category><category>Dependabot</category><category>Open Source</category></item><item><title>Lookout MSEC: Tackling Supply Chain Risks via Mobile App SBOMs</title><link>https://runtimerebel.com/blog/lookout-msec-tackling-supply-chain-risks-via-mobile-app-sboms</link><guid isPermaLink="true">https://runtimerebel.com/blog/lookout-msec-tackling-supply-chain-risks-via-mobile-app-sboms</guid><description>Lookout launches the Mobile Security Exposure Center (MSEC) to provide visibility into vulnerable third-party components and mobile app dependencies via SBOMs.</description><pubDate>Mon, 27 Jul 2026 11:26:52 GMT</pubDate><category>Lookout MSEC</category><category>SBOM</category><category>Mobile App Security</category><category>Supply Chain Security</category><category>Application Risk</category></item><item><title>GitHub Dependabot 3-Day Cooldown: Mitigating Supply Chain Attacks</title><link>https://runtimerebel.com/blog/github-dependabot-3-day-cooldown-mitigating-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-dependabot-3-day-cooldown-mitigating-supply-chain-attacks</guid><description>GitHub introduces a 3-day cooldown for Dependabot to prevent the rapid adoption of malicious packages, enhancing supply chain security for developers.</description><pubDate>Mon, 27 Jul 2026 11:25:20 GMT</pubDate><category>GitHub</category><category>Dependabot</category><category>Supply Chain Security</category><category>Malicious Packages</category><category>Open Source</category></item><item><title>VS Code Marketplace Abuse: Detecting Malicious Developer Extensions</title><link>https://runtimerebel.com/blog/vs-code-marketplace-abuse-detecting-malicious-developer-extensions</link><guid isPermaLink="true">https://runtimerebel.com/blog/vs-code-marketplace-abuse-detecting-malicious-developer-extensions</guid><description>Researchers identify malicious Visual Studio Code extensions exfiltrating source code and credentials. Learn how to secure your development environment.</description><pubDate>Mon, 27 Jul 2026 03:19:47 GMT</pubDate><category>VS Code</category><category>Marketplace Security</category><category>Developer Security</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>GitHub and PyPI Time-Based Defenses Against Supply Chain Attacks</title><link>https://runtimerebel.com/blog/github-and-pypi-time-based-defenses-against-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-and-pypi-time-based-defenses-against-supply-chain-attacks</guid><description>GitHub and PyPI introduce time-based delays in Dependabot to mitigate supply chain attacks by preventing the immediate ingestion of malicious packages.</description><pubDate>Sun, 26 Jul 2026 17:03:02 GMT</pubDate><category>GitHub</category><category>PyPI</category><category>Dependabot</category><category>Supply Chain Security</category><category>Python</category></item><item><title>GitHub Actions Runners Weaponized to Attack cPanel and WHM Servers</title><link>https://runtimerebel.com/blog/github-actions-runners-weaponized-to-attack-cpanel-and-whm-servers</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-actions-runners-weaponized-to-attack-cpanel-and-whm-servers</guid><description>Attackers are leveraging GitHub Actions runners and compromised Packagist packages to launch distributed attacks against cPanel and WHM server instances.</description><pubDate>Thu, 23 Jul 2026 14:05:01 GMT</pubDate><category>GitHub Actions</category><category>Packagist</category><category>cPanel</category><category>WHM</category><category>Supply Chain Attack</category><category>PHP</category></item><item><title>Trojanized Newtonsoft.Json Fork: Game-Rigging via NuGet Typosquatting</title><link>https://runtimerebel.com/blog/trojanized-newtonsoft-json-fork-game-rigging-via-nuget-typosquatting</link><guid isPermaLink="true">https://runtimerebel.com/blog/trojanized-newtonsoft-json-fork-game-rigging-via-nuget-typosquatting</guid><description>A trojanized &apos;Newtonsoftt.Json.Net&apos; NuGet package, disguised as &apos;Newtonsoft.Json&apos;, rigs live game results on Digitain, highlighting supply chain risks.</description><pubDate>Wed, 22 Jul 2026 06:29:48 GMT</pubDate><category>Newtonsoft Json</category><category>NuGet</category><category>Typosquatting</category><category>Supply Chain Attack</category><category>Digitain</category><category>Malware</category></item><item><title>Sandworm&apos;s AI Toolchain Threat: Detecting SANDWORM_MODE</title><link>https://runtimerebel.com/blog/sandworm-s-ai-toolchain-threat-detecting-sandworm-mode</link><guid isPermaLink="true">https://runtimerebel.com/blog/sandworm-s-ai-toolchain-threat-detecting-sandworm-mode</guid><description>Analyzing Sandworm&apos;s potential to compromise AI/ML supply chains via the &apos;SANDWORM_MODE&apos; attack method, focusing on detection and mitigation strategies.</description><pubDate>Tue, 21 Jul 2026 17:24:33 GMT</pubDate><category>Sandworm</category><category>APT28</category><category>Supply Chain Attack</category><category>AI Security</category><category>Machine Learning</category><category>Open Source Security</category><category>SANDWORM MODE</category></item><item><title>Hugging Face Infrastructure Breach: Analyzing Autonomous AI Agent TTPs</title><link>https://runtimerebel.com/blog/hugging-face-infrastructure-breach-analyzing-autonomous-ai-agent-ttps</link><guid isPermaLink="true">https://runtimerebel.com/blog/hugging-face-infrastructure-breach-analyzing-autonomous-ai-agent-ttps</guid><description>Hugging Face discloses a breach where autonomous AI agents compromised production infrastructure, exposing internal datasets and secrets. Learn how to mitigate.</description><pubDate>Mon, 20 Jul 2026 14:19:12 GMT</pubDate><category>Hugging Face</category><category>Autonomous AI Agent</category><category>Credential Exposure</category><category>MLOps Security</category><category>Data Breach</category></item><item><title>SleeperGem: Malicious RubyGems Target Developer Environments</title><link>https://runtimerebel.com/blog/sleepergem-malicious-rubygems-target-developer-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/sleepergem-malicious-rubygems-target-developer-environments</guid><description>The SleeperGem supply chain attack uses malicious RubyGems packages like git_credential_manager to compromise developers and deliver secondary payloads.</description><pubDate>Mon, 20 Jul 2026 06:48:55 GMT</pubDate><category>RubyGems</category><category>SleeperGem</category><category>Git Credential Manager</category><category>Supply Chain Attack</category><category>Malware</category></item><item><title>Malicious Vite npm Packages Deliver RAT via Blockchain C2</title><link>https://runtimerebel.com/blog/malicious-vite-npm-packages-deliver-rat-via-blockchain-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-vite-npm-packages-deliver-rat-via-blockchain-c2</guid><description>Seven malicious npm packages target Vite frontend projects. Dubbed ViteVenom, this software supply chain attack uses a four-tier blockchain C2 to deploy a RAT.</description><pubDate>Fri, 17 Jul 2026 20:57:56 GMT</pubDate><category>ViteVenom</category><category>ChainVeil</category><category>NPM</category><category>Vite</category><category>Software Supply Chain Attack</category><category>RAT</category><category>Blockchain C2</category></item><item><title>Risk Ledger Secures $32M Series B for Supply Chain Risk Platform</title><link>https://runtimerebel.com/blog/risk-ledger-secures-32m-series-b-for-supply-chain-risk-platform</link><guid isPermaLink="true">https://runtimerebel.com/blog/risk-ledger-secures-32m-series-b-for-supply-chain-risk-platform</guid><description>Risk Ledger raises $32 million in Series B funding to scale its collaborative supply chain security platform, addressing critical third-party risk management.</description><pubDate>Fri, 17 Jul 2026 10:00:13 GMT</pubDate><category>Risk Ledger</category><category>Supply Chain Security</category><category>TPRM</category><category>Series B Funding</category><category>Cyber Risk Management</category></item><item><title>AsyncAPI npm packages infected with credential-stealing malware</title><link>https://runtimerebel.com/blog/asyncapi-npm-packages-infected-with-credential-stealing-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/asyncapi-npm-packages-infected-with-credential-stealing-malware</guid><description>Five malicious versions of AsyncAPI npm packages deployed a credential-stealing remote access trojan via a supply chain attack. Learn detection and mitigation.</description><pubDate>Wed, 15 Jul 2026 17:20:00 GMT</pubDate><category>NPM</category><category>Asyncapi</category><category>Supply Chain Attack</category><category>Credential Stealing</category><category>Malware</category><category>Trojan</category></item><item><title>2-Click Cursor Exploit: Dev Environment Takeover Risks &amp; Mitigations</title><link>https://runtimerebel.com/blog/2-click-cursor-exploit-dev-environment-takeover-risks-mitigations</link><guid isPermaLink="true">https://runtimerebel.com/blog/2-click-cursor-exploit-dev-environment-takeover-risks-mitigations</guid><description>Analyze the &apos;2-click cursor exploit&apos; leveraging &apos;age-old bugs&apos; to compromise developer environments, risking source code and IP theft.</description><pubDate>Wed, 15 Jul 2026 13:49:23 GMT</pubDate><category>Developer Environments</category><category>Supply Chain Security</category><category>Application Security</category><category>Exploitation</category><category>Source Code Theft</category></item><item><title>Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware</title><link>https://runtimerebel.com/blog/compromised-asyncapi-npm-packages-deliver-multi-stage-botnet-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-asyncapi-npm-packages-deliver-multi-stage-botnet-malware</guid><description>Official AsyncAPI npm packages have been compromised to distribute botnet malware. Learn how to detect and mitigate these supply chain attacks.</description><pubDate>Wed, 15 Jul 2026 10:04:34 GMT</pubDate><category>Npm Malware</category><category>Asyncapi</category><category>Supply Chain Attack</category><category>Botnet</category><category>Javascript Security</category></item><item><title>Jscrambler NPM Packages Poisoned in Supply Chain Attack</title><link>https://runtimerebel.com/blog/jscrambler-npm-packages-poisoned-in-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/jscrambler-npm-packages-poisoned-in-supply-chain-attack</guid><description>Attackers poisoned official Jscrambler NPM packages to distribute cross-platform credential stealers. Learn the impact and how to remediate the threat.</description><pubDate>Tue, 14 Jul 2026 10:01:24 GMT</pubDate><category>Jscrambler</category><category>NPM</category><category>Supply Chain Attack</category><category>Malware</category><category>Credential Stealer</category></item><item><title>xAI Grok Build Repository Upload Risks: Analyzing CLI Data Exposure</title><link>https://runtimerebel.com/blog/xai-grok-build-repository-upload-risks-analyzing-cli-data-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/xai-grok-build-repository-upload-risks-analyzing-cli-data-exposure</guid><description>xAI&apos;s Grok Build CLI version 0.2.93 discovered uploading entire Git repositories, including history and secrets, to remote storage without user consent.</description><pubDate>Tue, 14 Jul 2026 09:59:54 GMT</pubDate><category>Xai</category><category>Grok Build</category><category>Git Security</category><category>Data Exfiltration</category><category>AI Security</category></item><item><title>Klue Security Incident: Analyzing Third-Party Supply Chain Impact</title><link>https://runtimerebel.com/blog/klue-security-incident-analyzing-third-party-supply-chain-impact</link><guid isPermaLink="true">https://runtimerebel.com/blog/klue-security-incident-analyzing-third-party-supply-chain-impact</guid><description>An analysis of the Klue security incident affecting Recorded Future, highlighting the risks of third-party SaaS vendors and competitive intelligence data.</description><pubDate>Tue, 14 Jul 2026 06:12:08 GMT</pubDate><category>Klue</category><category>Recorded Future</category><category>Supply Chain Risk</category><category>SaaS Security</category><category>Third Party Breach</category></item><item><title>Jscrambler npm Package Backdoored with Infostealer Malware</title><link>https://runtimerebel.com/blog/jscrambler-npm-package-backdoored-with-infostealer-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/jscrambler-npm-package-backdoored-with-infostealer-malware</guid><description>A malicious version of the Jscrambler npm package, 5.0.0-beta-1, was backdoored with infostealer malware, affecting 1,500 downloads. Immediate action needed.</description><pubDate>Mon, 13 Jul 2026 20:59:06 GMT</pubDate><category>Jscrambler</category><category>NPM</category><category>Supply Chain Attack</category><category>Infostealer</category><category>Malware</category><category>Node Js</category></item><item><title>ModHeader Extension Pulled Over Dormant Browsing Data Collector</title><link>https://runtimerebel.com/blog/modheader-extension-pulled-over-dormant-browsing-data-collector</link><guid isPermaLink="true">https://runtimerebel.com/blog/modheader-extension-pulled-over-dormant-browsing-data-collector</guid><description>ModHeader, a popular browser extension with 1.6M installs on Chrome and Edge, was pulled by Google and Microsoft after a dormant browsing history collector was found.</description><pubDate>Mon, 13 Jul 2026 20:58:15 GMT</pubDate><category>ModHeader</category><category>Browser Extension</category><category>Chrome</category><category>Edge</category><category>Supply Chain Attack</category><category>Data Collection</category><category>Malware</category></item><item><title>Lidl Data Breach: Service Provider Hack Exposes Customer Info</title><link>https://runtimerebel.com/blog/lidl-data-breach-service-provider-hack-exposes-customer-info</link><guid isPermaLink="true">https://runtimerebel.com/blog/lidl-data-breach-service-provider-hack-exposes-customer-info</guid><description>Lidl notifies customers in Germany, Belgium, and Netherlands after a third-party service provider breach exposed personal data and order histories.</description><pubDate>Mon, 13 Jul 2026 14:40:17 GMT</pubDate><category>Lidl Breach</category><category>Third Party Risk</category><category>Supply Chain Attack</category><category>Retail Security</category><category>Data Exfiltration</category></item><item><title>jscrambler 8.14.0 Compromised: Rust Infostealer Supply Chain Attack</title><link>https://runtimerebel.com/blog/jscrambler-8-14-0-compromised-rust-infostealer-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/jscrambler-8-14-0-compromised-rust-infostealer-supply-chain-attack</guid><description>The jscrambler 8.14.0 npm release was compromised with a malicious preinstall hook dropping a cross-platform Rust infostealer. Mitigate the threat now.</description><pubDate>Sat, 11 Jul 2026 20:50:45 GMT</pubDate><category>Jscrambler</category><category>NPM</category><category>Supply Chain Attack</category><category>Rust Malware</category><category>Infostealer</category></item><item><title>Injective Labs npm Package Compromise Steals Crypto Keys</title><link>https://runtimerebel.com/blog/injective-labs-npm-package-compromise-steals-crypto-keys</link><guid isPermaLink="true">https://runtimerebel.com/blog/injective-labs-npm-package-compromise-steals-crypto-keys</guid><description>Critical supply chain attack compromises Injective Labs SDK on GitHub, distributing malicious npm package `@injectivelabs/sdk-ts@1.20.21` to steal crypto wallet keys.</description><pubDate>Fri, 10 Jul 2026 17:48:42 GMT</pubDate><category>Injective Labs</category><category>NPM</category><category>Supply Chain Attack</category><category>Cryptocurrency</category><category>Wallet Theft</category><category>Malicious Package</category><category>SDK</category></item><item><title>Injective SDK npm Compromise: Crypto Wallet Stealer Detected</title><link>https://runtimerebel.com/blog/injective-sdk-npm-compromise-crypto-wallet-stealer-detected</link><guid isPermaLink="true">https://runtimerebel.com/blog/injective-sdk-npm-compromise-crypto-wallet-stealer-detected</guid><description>A malicious version of the Injective SDK (injective-js) on npm was published via a GitHub compromise, deploying a crypto wallet stealer. Developers are at risk.</description><pubDate>Fri, 10 Jul 2026 03:32:02 GMT</pubDate><category>Injective SDK</category><category>NPM</category><category>Cryptocurrency</category><category>Wallet Stealer</category><category>Supply Chain Attack</category><category>Malware</category><category>Injective Js</category></item><item><title>OpenMandriva Insider Sabotage: Risks of Contributor Access Misuse</title><link>https://runtimerebel.com/blog/openmandriva-insider-sabotage-risks-of-contributor-access-misuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/openmandriva-insider-sabotage-risks-of-contributor-access-misuse</guid><description>OpenMandriva Linux reports an attempted internal sabotage by a disgruntled contributor, highlighting critical risks of insider threats in open-source projects.</description><pubDate>Fri, 10 Jul 2026 03:31:37 GMT</pubDate><category>OpenMandriva</category><category>Insider Threat</category><category>Open Source Security</category><category>Supply Chain Attack</category></item><item><title>npm 12 Enhances Supply Chain Security by Disabling Install Scripts</title><link>https://runtimerebel.com/blog/npm-12-enhances-supply-chain-security-by-disabling-install-scripts</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-12-enhances-supply-chain-security-by-disabling-install-scripts</guid><description>npm version 12 introduces critical security defaults, disabling install scripts and deprecating GATs, significantly mitigating JavaScript supply chain risks.</description><pubDate>Thu, 09 Jul 2026 17:57:40 GMT</pubDate><category>NPM</category><category>Supply Chain Security</category><category>Install Scripts</category><category>Security Defaults</category><category>GATs</category><category>2FA</category><category>JavaScript Packages</category></item><item><title>Fake Paysafe/Skrill SDKs on npm &amp; PyPI Steal Credentials</title><link>https://runtimerebel.com/blog/fake-paysafe-skrill-sdks-on-npm-pypi-steal-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-paysafe-skrill-sdks-on-npm-pypi-steal-credentials</guid><description>Malicious packages impersonating Paysafe and Skrill SDKs on npm and PyPI platforms are stealing credentials from developers and users. Threat intelligence analysis.</description><pubDate>Wed, 08 Jul 2026 21:35:17 GMT</pubDate><category>NPM</category><category>PyPI</category><category>Supply Chain Attack</category><category>Credential Theft</category><category>Paysafe</category><category>Skrill</category><category>Neteller</category><category>Malware</category></item><item><title>GitHub Actions Attack Patterns Evade CI Security Scanners</title><link>https://runtimerebel.com/blog/github-actions-attack-patterns-evade-ci-security-scanners</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-actions-attack-patterns-evade-ci-security-scanners</guid><description>Learn how sophisticated GitHub Actions attack patterns bypass traditional CI security scanners, exposing CI/CD pipelines to supply chain risks. Understand the threats…</description><pubDate>Tue, 07 Jul 2026 14:38:51 GMT</pubDate><category>GitHub Actions</category><category>CI CD Security</category><category>Supply Chain Security</category><category>Security Scanning</category><category>Code Integrity</category></item><item><title>PolinRider: North Korean Hackers Push 108 Malicious Packages</title><link>https://runtimerebel.com/blog/polinrider-north-korean-hackers-push-108-malicious-packages</link><guid isPermaLink="true">https://runtimerebel.com/blog/polinrider-north-korean-hackers-push-108-malicious-packages</guid><description>Analysis of the PolinRider campaign where North Korean actors published 108 malicious packages and extensions across npm, Go, and Chrome ecosystems.</description><pubDate>Sat, 04 Jul 2026 13:37:02 GMT</pubDate><category>PolinRider</category><category>Lazarus Group</category><category>NPM</category><category>Chrome Web Store</category><category>Supply Chain Attack</category><category>North Korea</category></item><item><title>N. Korea-Linked npm Packages Mimic Rollup Polyfills for Data Theft</title><link>https://runtimerebel.com/blog/n-korea-linked-npm-packages-mimic-rollup-polyfills-for-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/n-korea-linked-npm-packages-mimic-rollup-polyfills-for-data-theft</guid><description>North Korea-linked actors use malicious npm packages (&apos;rollup-packages-polyfill-core&apos;, &apos;rollup-runtime-polyfill-core&apos;) to steal developer secrets, mimicking Rollup…</description><pubDate>Fri, 03 Jul 2026 17:27:44 GMT</pubDate><category>NPM</category><category>Rollup</category><category>Supply Chain Attack</category><category>North Korea Linked</category><category>Developer Secrets</category><category>Malicious Packages</category></item><item><title>Auditing AI-Driven Software Development: Security Governance Strategies</title><link>https://runtimerebel.com/blog/auditing-ai-driven-software-development-security-governance-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/auditing-ai-driven-software-development-security-governance-strategies</guid><description>Learn how to audit AI-generated code and govern AI tool usage to mitigate security risks in modern software development lifecycles.</description><pubDate>Fri, 03 Jul 2026 07:29:45 GMT</pubDate><category>AI Security</category><category>Software Development Lifecycle</category><category>Governance</category><category>LLM Security</category></item><item><title>Windows 11 Emoji Panel GIF Fix Highlights Supply Chain Dependency</title><link>https://runtimerebel.com/blog/windows-11-emoji-panel-gif-fix-highlights-supply-chain-dependency</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-11-emoji-panel-gif-fix-highlights-supply-chain-dependency</guid><description>Microsoft resolves Windows 11 Emoji Panel GIF functionality after provider shutdown, underscoring third-party service dependencies in OS features.</description><pubDate>Wed, 01 Jul 2026 13:05:33 GMT</pubDate><category>Windows 11</category><category>Emoji Panel</category><category>GIF</category><category>Microsoft</category><category>Service Disruption</category><category>Supply Chain Dependency</category></item><item><title>Education Sector Third-Party Risk: Protecting Student Data</title><link>https://runtimerebel.com/blog/education-sector-third-party-risk-protecting-student-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/education-sector-third-party-risk-protecting-student-data</guid><description>The education sector confronts growing third-party breach threats, endangering student data. This article details vendor risk mitigation strategies against ransomware…</description><pubDate>Sat, 27 Jun 2026 16:29:33 GMT</pubDate><category>Education Sector</category><category>Third Party Risk</category><category>Vendor Risk Management</category><category>Student Data Protection</category><category>Ransomware</category><category>Data Breach</category></item><item><title>Linux Foundation&apos;s Project Akrites: Bolstering Open Source Security</title><link>https://runtimerebel.com/blog/linux-foundation-s-project-akrites-bolstering-open-source-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/linux-foundation-s-project-akrites-bolstering-open-source-security</guid><description>Project Akrites aims to streamline vulnerability management across open source projects, enhancing reporting, patching, and disclosure processes for critical software.</description><pubDate>Fri, 26 Jun 2026 12:52:09 GMT</pubDate><category>Linux Foundation</category><category>Akrites</category><category>Open Source Security</category><category>Vulnerability Management</category><category>Software Supply Chain</category></item><item><title>Cordyceps CI/CD Flaws: Supply Chain Attacks on GitHub Repositories</title><link>https://runtimerebel.com/blog/cordyceps-ci-cd-flaws-supply-chain-attacks-on-github-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/cordyceps-ci-cd-flaws-supply-chain-attacks-on-github-repositories</guid><description>Novee Security uncovered Cordyceps, a critical CI/CD workflow flaw exposing over 300 GitHub repositories to supply chain compromise, affecting major organizations.</description><pubDate>Wed, 24 Jun 2026 16:50:14 GMT</pubDate><category>Cordyceps</category><category>CI CD</category><category>GitHub</category><category>Supply Chain Attack</category><category>Novee Security</category><category>Repository Compromise</category></item><item><title>Cordyceps: Defending Against Malicious Pull Requests in CI/CD</title><link>https://runtimerebel.com/blog/cordyceps-defending-against-malicious-pull-requests-in-ci-cd</link><guid isPermaLink="true">https://runtimerebel.com/blog/cordyceps-defending-against-malicious-pull-requests-in-ci-cd</guid><description>The Cordyceps campaign highlights critical CI/CD vulnerabilities in GitHub Actions, targeting high-profile projects like Apache Doris and Cloudflare Workers SDK.</description><pubDate>Wed, 24 Jun 2026 09:23:01 GMT</pubDate><category>GitHub Actions</category><category>CI CD Security</category><category>Supply Chain Attack</category><category>DevSecOps</category><category>Cordyceps</category></item><item><title>OAuth Token Theft: How Icarus Targets Salesforce via Klue Breach</title><link>https://runtimerebel.com/blog/oauth-token-theft-how-icarus-targets-salesforce-via-klue-breach</link><guid isPermaLink="true">https://runtimerebel.com/blog/oauth-token-theft-how-icarus-targets-salesforce-via-klue-breach</guid><description>Attackers known as Icarus are exploiting compromised OAuth tokens from Klue to exfiltrate sensitive Salesforce data. Learn how to mitigate supply chain risks.</description><pubDate>Wed, 24 Jun 2026 09:21:31 GMT</pubDate><category>Salesforce</category><category>Klue</category><category>Icarus</category><category>OAuth Token Theft</category><category>Supply Chain Attack</category></item><item><title>Malicious npm Packages Impersonate PostCSS to Deliver Windows RAT</title><link>https://runtimerebel.com/blog/malicious-npm-packages-impersonate-postcss-to-deliver-windows-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-npm-packages-impersonate-postcss-to-deliver-windows-rat</guid><description>Security researchers uncover malicious npm packages such as postcss-minify-selector-parser delivering Windows RATs via supply chain attacks. Audit your builds.</description><pubDate>Tue, 23 Jun 2026 13:10:31 GMT</pubDate><category>NPM</category><category>PostCSS</category><category>Typosquatting</category><category>RAT</category><category>JavaScript</category></item><item><title>ShapedPlugin Supply Chain Attack: WordPress Pro Plugins Backdoored</title><link>https://runtimerebel.com/blog/shapedplugin-supply-chain-attack-wordpress-pro-plugins-backdoored</link><guid isPermaLink="true">https://runtimerebel.com/blog/shapedplugin-supply-chain-attack-wordpress-pro-plugins-backdoored</guid><description>Attackers compromised ShapedPlugin&apos;s distribution pipeline to inject backdoors into Pro WordPress plugins. Learn how to detect and remediate this supply chain threat.</description><pubDate>Tue, 23 Jun 2026 00:57:15 GMT</pubDate><category>ShapedPlugin</category><category>WordPress</category><category>Supply Chain Attack</category><category>Backdoor</category><category>Wordfence</category></item><item><title>North Korean Sapphire Sleet Compromises 140+ Mastra AI npm Packages</title><link>https://runtimerebel.com/blog/north-korean-sapphire-sleet-compromises-140-mastra-ai-npm-packages</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-sapphire-sleet-compromises-140-mastra-ai-npm-packages</guid><description>Microsoft attributes the Mastra AI supply chain attack to Sapphire Sleet (BlueNoroff), involving 140+ malicious npm packages targeting AI developers.</description><pubDate>Sat, 20 Jun 2026 16:38:13 GMT</pubDate><category>Sapphire Sleet</category><category>BlueNoroff</category><category>Mastra AI</category><category>NPM</category><category>Supply Chain Attack</category><category>Lazarus Group</category></item><item><title>Klue Security Incident: Mitigating Third-Party Risk in Intelligence</title><link>https://runtimerebel.com/blog/klue-security-incident-mitigating-third-party-risk-in-intelligence</link><guid isPermaLink="true">https://runtimerebel.com/blog/klue-security-incident-mitigating-third-party-risk-in-intelligence</guid><description>Analyze the impact of the Klue security incident on Recorded Future. Learn how to secure SaaS integrations and improve third-party vendor risk management.</description><pubDate>Fri, 19 Jun 2026 09:54:33 GMT</pubDate><category>Klue</category><category>Recorded Future</category><category>Supply Chain Attack</category><category>Third Party Risk</category><category>Data Breach</category></item><item><title>Novo Nordisk Breach: Securing Secrets in GitHub Development Pipelines</title><link>https://runtimerebel.com/blog/novo-nordisk-breach-securing-secrets-in-github-development-pipelines</link><guid isPermaLink="true">https://runtimerebel.com/blog/novo-nordisk-breach-securing-secrets-in-github-development-pipelines</guid><description>Analysis of the Novo Nordisk GitHub token leak and why secrets management must transition from static tools to identity-based security frameworks.</description><pubDate>Fri, 19 Jun 2026 09:48:31 GMT</pubDate><category>GitHub</category><category>Secrets Management</category><category>Novo Nordisk</category><category>DevSecOps</category><category>CI CD Security</category></item><item><title>Klue Supply Chain Attack Hits Salesforce Instances of Security Firms</title><link>https://runtimerebel.com/blog/klue-supply-chain-attack-hits-salesforce-instances-of-security-firms</link><guid isPermaLink="true">https://runtimerebel.com/blog/klue-supply-chain-attack-hits-salesforce-instances-of-security-firms</guid><description>Attackers breached competitive intelligence platform Klue, exfiltrating data from Salesforce instances of customers including Huntress and Recorded Future.</description><pubDate>Fri, 19 Jun 2026 09:44:49 GMT</pubDate><category>Klue</category><category>Salesforce</category><category>Huntress</category><category>Recorded Future</category><category>SaaS Security</category><category>Data Exfiltration</category></item></channel></rss>