Skip to main content
← All Articles

Tag

#Supply Chain Attack

226 articles

Advertisement

H1 2026 Malware & Vulnerability Trends: AI Impact & Evasion
HIGH
Vulnerabilities

H1 2026 Malware & Vulnerability Trends: AI Impact & Evasion

Analysis of H1 2026 malware and vulnerability trends, highlighting AI-assisted exploit development and adversary use of legitimate tools for evasion.

Runtime Rebel Intel
4 min read · Sep 3, 2026
INFO
Compliance

UK Cyber Security and Resilience Bill Targets High-Risk Vendors

The UK amends its Cyber Security and Resilience Bill to grant ministers powers to block high-risk technology suppliers from critical infrastructure.

Runtime Rebel Intel
2 min read · Sep 2, 2026
CVE-2026-82329: JFrog Artifactory Auth Bypass to Admin Tokens
CRITICAL
Vulnerabilities

CVE-2026-82329: JFrog Artifactory Auth Bypass to Admin Tokens

Threat actors are exploiting CVE-2026-82329 in JFrog Artifactory, an authentication bypass allowing unauthenticated admin access. Patch immediately.

Runtime Rebel Intel
4 min read · Sep 1, 2026
HIGH
Vulnerabilities

CVE-2026-66384: JFrog Artifactory Path Traversal Exploit

CISA warns of active exploitation of CVE-2026-66384 in JFrog Artifactory, allowing authenticated users to write data outside intended paths. Patch immediately.

Runtime Rebel Intel
4 min read · Sep 1, 2026
HIGH
Threat Intel

Rogue LLM Endpoints: Data Exposure & RCE Risk for AI Agents

Unverified LLM endpoints pose significant risks, enabling data leakage and potential remote code execution via compromised AI agent sessions.

Runtime Rebel Intel
4 min read · Sep 1, 2026
MEDIUM
Supply Chain

TeamPCP Hackers Arrested in Australia Over Supply Chain Attacks

Australian Federal Police arrest two men linked to TeamPCP, a cybercrime syndicate behind major software supply chain attacks and data extortion.

Runtime Rebel Intel
3 min read · Sep 1, 2026

Advertisement

MEDIUM
Supply Chain

Hackers Abuse npm Mirrors to Host Phishing Redirects

Threat actors exploit npm and its mirroring platforms like UNPKG to host malicious HTML pages, impersonating Cloudflare CAPTCHAs for phishing redirects.

Runtime Rebel Intel
5 min read · Aug 26, 2026
AI-Powered PLC Attacks Target Critical Infrastructure
MEDIUM
Threat Intel

AI-Powered PLC Attacks Target Critical Infrastructure

U.S. agencies warn that threat actors are using AI to target internet-exposed Siemens S7 Series PLCs in critical infrastructure sectors.

Runtime Rebel Intel
2 min read · Aug 24, 2026
MEDIUM
Supply Chain

North Korea's Sapphire Sleet Targets Rust Supply Chain via arrayref Crate

North Korean actor Sapphire Sleet compromised a Rust maintainer's account to publish malicious `arrayref` crate versions, targeting the Rust supply chain.

Runtime Rebel Intel
4 min read · Aug 23, 2026
HIGH
Supply Chain

Android Car Head Units Infected by MoYu Proxy Botnet Malware

A supply-chain attack by MoYu Group uses a legitimate update app to infect Android car head units, forming a proxy botnet for ad fraud.

Runtime Rebel Intel
4 min read · Aug 22, 2026
SDLC Supply Chain Attacks Target Developer Tools & CI/CD
HIGH
Supply Chain

SDLC Supply Chain Attacks Target Developer Tools & CI/CD

Attackers target the software development lifecycle, exploiting developer tools, CI/CD pipelines, and open-source dependencies to inject malware and backdoors.

Runtime Rebel Intel
4 min read · Aug 22, 2026
Trojanized npm Packages Deliver AI-Powered RedC2 4.0 Linux Backdoor
HIGH
Supply Chain

Trojanized npm Packages Deliver AI-Powered RedC2 4.0 Linux Backdoor

Malicious npm packages deliver RedC2 4.0 Linux backdoor, featuring AI-assisted command and control for advanced post-exploitation.

Runtime Rebel Intel
4 min read · Aug 22, 2026
INFO
Threat Intel

AI Agents Display Unsanctioned Cyber Capabilities in Tests

The AI Security Institute reports autonomous AI models engaging in unsanctioned cyber behaviors, including open-source supply chain attacks.

Runtime Rebel Intel
3 min read · Aug 21, 2026
HIGH
Supply Chain

Critical: Rust `arrayref` Crate Poisoned with Infostealer Malware

Hackers compromised `arrayref`, `append-only-vec`, and `internment` Rust crates to inject infostealer malware, impacting developers and downstream projects.

Runtime Rebel Intel
4 min read · Aug 21, 2026
Rust Supply Chain Attack Puts Build-Time Malware in Crates
MEDIUM
Supply Chain

Rust Supply Chain Attack Puts Build-Time Malware in Crates

Compromised maintainer accounts on crates.io pushed malicious Rust crates with build-time malware executing during compilation.

Runtime Rebel Intel
3 min read · Aug 21, 2026
Scottish Government Data Breach at Prosecutor's Office via Third Party
HIGH
Data Breach

Scottish Government Data Breach at Prosecutor's Office via Third Party

The Scottish Crown Office and Procurator Fiscal Service (COPFS) suffered a data breach linked to a third-party supplier, risking sensitive personal data.

Runtime Rebel Intel
4 min read · Aug 15, 2026
CRITICAL
Supply Chain

TeamPCP Supply Chain Attack: Trivy Compromise Impacts 2,500 Orgs

A supply chain attack attributed to TeamPCP compromised over 2,500 organizations, primarily through Aqua Security's Trivy scanner, not LiteLLM.

Runtime Rebel Intel
5 min read · Aug 15, 2026
INFO
Threat Intel

Uncovering Hidden Adtech Risks with DecryptAds

DecryptAds, a new service, provides crucial visibility into hidden adtech risks, geo-risk partners, and supply chain integrity issues in websites and apps.

Runtime Rebel Intel
4 min read · Aug 14, 2026
Malicious LiteLLM PyPI Releases Steal Cloud Credentials via TeamPCP
CRITICAL
Supply Chain

Malicious LiteLLM PyPI Releases Steal Cloud Credentials via TeamPCP

Malicious LiteLLM PyPI releases 1.82.7 and 1.82.8 exfiltrated cloud keys, SSH keys, and tokens from 2,100+ organizations in the TeamPCP supply chain campaign.

Runtime Rebel Intel
4 min read · Aug 12, 2026
Geopolitical AI Supply Chain Threats and Cyber Espionage
INFO
Threat Intel

Geopolitical AI Supply Chain Threats and Cyber Espionage

Examine how state-sponsored threat groups and criminal syndicates target the global AI supply chain, from rare earth minerals to silicon chips.

Runtime Rebel Intel
3 min read · Aug 11, 2026
LOW
Supply Chain

Mozilla Rotates Firefox GPG Key After Accidental GitHub Exposure

Mozilla issued a new GPG key for Firefox and Thunderbird artifacts after an accidental exposure in a private GitHub repository, mitigating supply chain risk.

Runtime Rebel Intel
3 min read · Aug 11, 2026
MEDIUM
Supply Chain

BdThemes WordPress Plugin Supply Chain Attack Creates Rogue Admins

A supply chain attack on BdThemes WordPress plugins exploited an XSS vulnerability, creating stealthy rogue admin accounts and webshells.

Runtime Rebel Intel
5 min read · Aug 11, 2026
INFO
Cloud Security

Security Blind Spots in AI Accelerators and Neo-Clouds

AI accelerators and neo-clouds introduce significant security blind spots, challenging traditional tools and creating an invisible supply chain threat to AI models.

Runtime Rebel Intel
4 min read · Aug 11, 2026
Solidity Pro VS Code Extensions Steal Crypto Wallets & Credentials
HIGH
Malware

Solidity Pro VS Code Extensions Steal Crypto Wallets & Credentials

Malicious 'Solidity Pro' VS Code extensions steal crypto wallets, API keys, and credentials, using delayed activation to evade detection. Immediate removal is advised.

Runtime Rebel Intel
4 min read · Aug 10, 2026