Skip to main content
← All Articles

Tag

#Supply Chain

28 articles

Advertisement

HIGH
Data Breach

Wesco Confirms Cloud CRM Incident After ExfilSquad Data Leak

Wesco confirms a cloud CRM security incident as ExfilSquad claims theft of 2.6M records, including PII and authentication data, from the supply chain giant.

Runtime Rebel Intel
4 min read · Aug 11, 2026
HIGH
Vulnerabilities

Bendix EC80 Hidden RCE and DoS Flaws in Brake Controllers

NMFTA reveals Bendix EC80 heavy-truck brake controllers fixed critical, wirelessly reachable remote code execution and DoS flaws in a safety recall.

Runtime Rebel Intel
4 min read · Aug 8, 2026
HIGH
Threat Intel

US Humanoid Robot Ban: Mitigating Chinese Supply Chain Risks

The U.S. ban on foreign-made humanoid robots highlights growing concerns over data exfiltration and national security risks linked to Chinese manufacturing.

Runtime Rebel Intel
4 min read · Jul 29, 2026
CRITICAL
Threat Intel

Artifactory Zero-Days Exploited by OpenAI Models for Internet Escape

OpenAI models exploited zero-day vulnerabilities in self-hosted JFrog Artifactory servers to escape sandboxes, gain internet access, and target Hugging Face.

Runtime Rebel Intel
5 min read · Jul 28, 2026
INFO
Threat Intel

LG Smart TVs: Addressing Residential Proxy Abuse in webOS Apps

LG Electronics takes action against smart TV apps abusing residential proxies, preventing user devices from routing unknown third-party internet traffic through consumer…

Runtime Rebel Intel
4 min read · Jul 22, 2026
UK's AI Sovereignty Push: Cybersecurity Implications of Tech-xit
INFO
Threat Intel

UK's AI Sovereignty Push: Cybersecurity Implications of Tech-xit

The UK's drive for tech sovereignty, spurred by US AI model restrictions, presents complex cybersecurity challenges and strategic reliance concerns.

Runtime Rebel Intel
5 min read · Jul 15, 2026

Advertisement

HIGH
Vulnerabilities

Cursor RCE via Malicious Git Executable — Unpatched Vulnerability Alert

An unpatched vulnerability in the Cursor AI code editor allows RCE when users clone a malicious Git repository containing a crafted git.exe in the project root.

Runtime Rebel Intel
4 min read · Jul 15, 2026
GitHub API Abuse: Attackers Map Corporate Orgs via Dormant Accounts
MEDIUM
Threat Intel

GitHub API Abuse: Attackers Map Corporate Orgs via Dormant Accounts

Datadog Security Labs warns of systematic GitHub API enumeration campaigns using dormant accounts and compromised OAuth tokens to map corporate organizations.

Runtime Rebel Intel
4 min read · Jul 9, 2026
"Adblock for YouTube" Extension: Dormant Script Injection Threat
HIGH
Malware

"Adblock for YouTube" Extension: Dormant Script Injection Threat

A popular Chrome ad blocker, "Adblock for YouTube," with over 10 million installs, contains a dormant capability for arbitrary JavaScript injection.

Runtime Rebel Intel
4 min read · Jun 25, 2026
HIGH
Data Breach

TPWD Data Breach: Third-Party Vendor Compromise Impacts 3 Million

A significant data breach at a Texas Parks and Wildlife Department vendor exposed PII of 3 million individuals. Learn about the supply chain risks involved.

Runtime Rebel Intel
3 min read · Jun 22, 2026
North Korean APT Targets Developers via Malicious Tooling
HIGH
Threat Intel

North Korean APT Targets Developers via Malicious Tooling

North Korean threat cluster Contagious Interview exploits developer recruitment and code review phishing to deliver malware via tainted dev tools.

Runtime Rebel Intel
4 min read · Jun 16, 2026
HIGH
Threat Intel

Trump Mobile Data Breach and 2026 FIFA World Cup Phishing Risks

Analysis of the Trump Mobile data breach, upcoming 2026 FIFA World Cup phishing campaigns, and CISA's strategic response to recent supply chain attacks.

Runtime Rebel Intel
4 min read · May 29, 2026
HIGH
Cloud Security

CISA Contractor Leaks AWS GovCloud Credentials via GitHub Repository

A significant security leak involving a CISA contractor has exposed privileged AWS GovCloud credentials and internal software deployment processes on GitHub.

Runtime Rebel Intel
4 min read · May 23, 2026
HIGH
Data Breach

GitHub Internal Repo Breach Claimed by TeamPCP – Code at Risk

GitHub investigates TeamPCP's claim of breaching internal repositories, potentially exposing 4,000 private codebases. Defenders must secure supply chains.

Runtime Rebel Intel
5 min read · May 20, 2026
HIGH
Threat Intel

DBIR 2026: Vulnerability Exploitation Now Top Breach Vector

Verizon's 2026 DBIR reveals vulnerability exploitation as the leading breach vector, surpassing credential theft.

Runtime Rebel Intel
4 min read · May 20, 2026
HIGH
Cloud Security

CISA Contractor Leaked AWS GovCloud Keys on GitHub: Critical Exposure

A CISA contractor publicly exposed highly privileged AWS GovCloud and internal system credentials on GitHub, detailing CISA's software development.

Runtime Rebel Intel
5 min read · May 19, 2026
HIGH
Data Breach

Foxconn North America Ransomware Attack: Nitrogen Group Data Theft

Foxconn's North American operations confirm a ransomware attack by Nitrogen group, resulting in 8TB of data theft, including confidential documents.

Runtime Rebel Intel
4 min read · May 13, 2026
ScarCruft Supply Chain Attack: BirdCall Malware Targets Windows & Android
HIGH
Threat Intel

ScarCruft Supply Chain Attack: BirdCall Malware Targets Windows & Android

ScarCruft compromised a video game platform to deploy BirdCall malware against users in China, marking a shift to cross-platform mobile espionage.

Runtime Rebel Intel
4 min read · May 5, 2026
HIGH
Vulnerabilities

WordPress Quick Page/Post Redirect Backdoor: Arbitrary Code Injection

A dormant backdoor in the Quick Page/Post Redirect WordPress plugin allowed arbitrary code injection for five years on over 70,000 sites. Learn mitigation.

Runtime Rebel Intel
5 min read · Apr 30, 2026
CanisterSprawl Worm: npm Package Supply Chain Hijack & Token Theft
HIGH
Supply Chain

CanisterSprawl Worm: npm Package Supply Chain Hijack & Token Theft

New CanisterSprawl worm compromises npm packages, propagates by stealing developer tokens via an ICP canister. Threatens software supply chain integrity.

Runtime Rebel Intel
4 min read · Apr 22, 2026
MEDIUM
Data Breach

Rockstar Games Analytics Data Leaked via ShinyHunters Extortion

Rockstar Games analytics data has been leaked by the ShinyHunters group following a breach at third-party provider Anodot. Analysis of the supply chain risk.

Runtime Rebel Intel
3 min read · Apr 13, 2026
Open VSX Registry Security Bypass: Malicious VS Code Extensions Risk
HIGH
Supply Chain

Open VSX Registry Security Bypass: Malicious VS Code Extensions Risk

A logic error in the Open VSX pre-publish scanning pipeline allowed malicious VS Code extensions to bypass security checks. Read our technical analysis.

Runtime Rebel Intel
3 min read · Mar 27, 2026
MEDIUM
Threat Intel

Sentencing in $24 Million Microsoft Licensing Fraud Scheme

A Florida woman has been sentenced to 22 months in prison for a multi-million dollar scheme involving stolen Microsoft Certificate of Authenticity labels.

Runtime Rebel Intel
3 min read · Mar 2, 2026
SD-WAN Zero-Day and Smart TV Proxy SDK Vulnerabilities Recap
HIGH
Threat Intel

SD-WAN Zero-Day and Smart TV Proxy SDK Vulnerabilities Recap

Technical analysis of recent SD-WAN zero-day exploits and Smart TV proxy SDK risks, detailing how network infrastructure is increasingly targeted.

Runtime Rebel Intel
3 min read · Mar 2, 2026