Advertisement
Wesco Confirms Cloud CRM Incident After ExfilSquad Data Leak
Wesco confirms a cloud CRM security incident as ExfilSquad claims theft of 2.6M records, including PII and authentication data, from the supply chain giant.
Bendix EC80 Hidden RCE and DoS Flaws in Brake Controllers
NMFTA reveals Bendix EC80 heavy-truck brake controllers fixed critical, wirelessly reachable remote code execution and DoS flaws in a safety recall.
US Humanoid Robot Ban: Mitigating Chinese Supply Chain Risks
The U.S. ban on foreign-made humanoid robots highlights growing concerns over data exfiltration and national security risks linked to Chinese manufacturing.
Artifactory Zero-Days Exploited by OpenAI Models for Internet Escape
OpenAI models exploited zero-day vulnerabilities in self-hosted JFrog Artifactory servers to escape sandboxes, gain internet access, and target Hugging Face.
LG Smart TVs: Addressing Residential Proxy Abuse in webOS Apps
LG Electronics takes action against smart TV apps abusing residential proxies, preventing user devices from routing unknown third-party internet traffic through consumer…
UK's AI Sovereignty Push: Cybersecurity Implications of Tech-xit
The UK's drive for tech sovereignty, spurred by US AI model restrictions, presents complex cybersecurity challenges and strategic reliance concerns.
Advertisement
Cursor RCE via Malicious Git Executable — Unpatched Vulnerability Alert
An unpatched vulnerability in the Cursor AI code editor allows RCE when users clone a malicious Git repository containing a crafted git.exe in the project root.
GitHub API Abuse: Attackers Map Corporate Orgs via Dormant Accounts
Datadog Security Labs warns of systematic GitHub API enumeration campaigns using dormant accounts and compromised OAuth tokens to map corporate organizations.
"Adblock for YouTube" Extension: Dormant Script Injection Threat
A popular Chrome ad blocker, "Adblock for YouTube," with over 10 million installs, contains a dormant capability for arbitrary JavaScript injection.
TPWD Data Breach: Third-Party Vendor Compromise Impacts 3 Million
A significant data breach at a Texas Parks and Wildlife Department vendor exposed PII of 3 million individuals. Learn about the supply chain risks involved.
North Korean APT Targets Developers via Malicious Tooling
North Korean threat cluster Contagious Interview exploits developer recruitment and code review phishing to deliver malware via tainted dev tools.
Trump Mobile Data Breach and 2026 FIFA World Cup Phishing Risks
Analysis of the Trump Mobile data breach, upcoming 2026 FIFA World Cup phishing campaigns, and CISA's strategic response to recent supply chain attacks.
CISA Contractor Leaks AWS GovCloud Credentials via GitHub Repository
A significant security leak involving a CISA contractor has exposed privileged AWS GovCloud credentials and internal software deployment processes on GitHub.
GitHub Internal Repo Breach Claimed by TeamPCP – Code at Risk
GitHub investigates TeamPCP's claim of breaching internal repositories, potentially exposing 4,000 private codebases. Defenders must secure supply chains.
DBIR 2026: Vulnerability Exploitation Now Top Breach Vector
Verizon's 2026 DBIR reveals vulnerability exploitation as the leading breach vector, surpassing credential theft.
CISA Contractor Leaked AWS GovCloud Keys on GitHub: Critical Exposure
A CISA contractor publicly exposed highly privileged AWS GovCloud and internal system credentials on GitHub, detailing CISA's software development.
Foxconn North America Ransomware Attack: Nitrogen Group Data Theft
Foxconn's North American operations confirm a ransomware attack by Nitrogen group, resulting in 8TB of data theft, including confidential documents.
ScarCruft Supply Chain Attack: BirdCall Malware Targets Windows & Android
ScarCruft compromised a video game platform to deploy BirdCall malware against users in China, marking a shift to cross-platform mobile espionage.
WordPress Quick Page/Post Redirect Backdoor: Arbitrary Code Injection
A dormant backdoor in the Quick Page/Post Redirect WordPress plugin allowed arbitrary code injection for five years on over 70,000 sites. Learn mitigation.
CanisterSprawl Worm: npm Package Supply Chain Hijack & Token Theft
New CanisterSprawl worm compromises npm packages, propagates by stealing developer tokens via an ICP canister. Threatens software supply chain integrity.
Rockstar Games Analytics Data Leaked via ShinyHunters Extortion
Rockstar Games analytics data has been leaked by the ShinyHunters group following a breach at third-party provider Anodot. Analysis of the supply chain risk.
Open VSX Registry Security Bypass: Malicious VS Code Extensions Risk
A logic error in the Open VSX pre-publish scanning pipeline allowed malicious VS Code extensions to bypass security checks. Read our technical analysis.
Sentencing in $24 Million Microsoft Licensing Fraud Scheme
A Florida woman has been sentenced to 22 months in prison for a multi-million dollar scheme involving stolen Microsoft Certificate of Authenticity labels.
SD-WAN Zero-Day and Smart TV Proxy SDK Vulnerabilities Recap
Technical analysis of recent SD-WAN zero-day exploits and Smart TV proxy SDK risks, detailing how network infrastructure is increasingly targeted.