Skip to main content
← All Articles

Tag

#Supply Chain

11 articles

Advertisement

"Adblock for YouTube" Extension: Dormant Script Injection Threat
HIGH
Malware

"Adblock for YouTube" Extension: Dormant Script Injection Threat

A popular Chrome ad blocker, "Adblock for YouTube," with over 10 million installs, contains a dormant capability for arbitrary JavaScript injection, posing a significant

Runtime Rebel Intel
4 min read·Jun 25, 2026
North Korean APT Targets Developers via Malicious Tooling
CRITICAL
Threat Intel

North Korean APT Targets Developers via Malicious Tooling

North Korean threat cluster Contagious Interview exploits developer recruitment and code review phishing to deliver malware via tainted dev tools.

Runtime Rebel Intel
4 min read·Jun 16, 2026
CL
CRITICAL
Cloud Security

CISA Contractor Leaked AWS GovCloud Keys on GitHub: Critical Exposure

A CISA contractor publicly exposed highly privileged AWS GovCloud and internal system credentials on GitHub, detailing CISA's software development. This leak poses a

Runtime Rebel Intel
5 min read·May 19, 2026
DA
HIGH
Data Breach

Foxconn North America Ransomware Attack: Nitrogen Group Data Theft

Foxconn's North American operations confirm a ransomware attack by Nitrogen group, resulting in 8TB of data theft, including confidential documents.

Runtime Rebel Intel
4 min read·May 13, 2026
ScarCruft Supply Chain Attack: BirdCall Malware Targets Windows & Android
HIGH
Threat Intel

ScarCruft Supply Chain Attack: BirdCall Malware Targets Windows & Android

ScarCruft compromised a video game platform to deploy BirdCall malware against users in China, marking a shift to cross-platform mobile espionage.

Runtime Rebel Intel
4 min read·May 5, 2026
VU
HIGH
Vulnerabilities

WordPress Quick Page/Post Redirect Backdoor: Arbitrary Code Injection

A dormant backdoor in the Quick Page/Post Redirect WordPress plugin allowed arbitrary code injection for five years on over 70,000 sites. Learn mitigation.

Runtime Rebel Intel
5 min read·Apr 30, 2026
Open VSX Registry Security Bypass: Malicious VS Code Extensions Risk
HIGH
Supply Chain

Open VSX Registry Security Bypass: Malicious VS Code Extensions Risk

A logic error in the Open VSX pre-publish scanning pipeline allowed malicious VS Code extensions to bypass security checks. Read our technical analysis.

Runtime Rebel Intel
3 min read·Mar 27, 2026
TH
MEDIUM
Threat Intel

Sentencing in $24 Million Microsoft Licensing Fraud Scheme

A Florida woman has been sentenced to 22 months in prison for a multi-million dollar scheme involving stolen Microsoft Certificate of Authenticity labels.

Runtime Rebel Intel
3 min read·Mar 2, 2026
DA
HIGH
Data Breach

ManoMano Data Breach: Third-Party Compromise Impacts 3.8M Customers

European DIY giant ManoMano suffers a supply chain data breach affecting 3.8 million customers after an unauthorized access to a third-party service provider.

Runtime Rebel Intel
4 min read·Feb 26, 2026
TH
MEDIUM
Threat Intel

OpenClaw Underground Trends: Assessing Hype vs. Operational Risk

Flare telemetry reveals a gap between high OpenClaw chatter on Telegram and actual exploitation, highlighting the need to distinguish hype from threat.

Runtime Rebel Intel
4 min read·Feb 25, 2026
Securing AI Infrastructure: Mitigation Strategies for Lifecycle Vulnerabilities
HIGH
Cloud Security

Securing AI Infrastructure: Mitigation Strategies for Lifecycle Vulnerabilities

An assessment of architectural risks in AI deployments, emphasizing infrastructure-level threats and model supply chain vulnerabilities over application-layer prompt injection.

Runtime Rebel Intel
2 min read·Feb 23, 2026