<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Supply Chain Attack</title><description>Cybersecurity articles tagged #Supply Chain Attack on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>H1 2026 Malware &amp; Vulnerability Trends: AI Impact &amp; Evasion</title><link>https://runtimerebel.com/blog/h1-2026-malware-vulnerability-trends-ai-impact-evasion</link><guid isPermaLink="true">https://runtimerebel.com/blog/h1-2026-malware-vulnerability-trends-ai-impact-evasion</guid><description>Analysis of H1 2026 malware and vulnerability trends, highlighting AI-assisted exploit development and adversary use of legitimate tools for evasion.</description><pubDate>Thu, 03 Sep 2026 19:03:02 GMT</pubDate><category>Malware</category><category>Vulnerability Exploitation</category><category>AI</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>UK Cyber Security and Resilience Bill Targets High-Risk Vendors</title><link>https://runtimerebel.com/blog/uk-cyber-security-and-resilience-bill-targets-high-risk-vendors</link><guid isPermaLink="true">https://runtimerebel.com/blog/uk-cyber-security-and-resilience-bill-targets-high-risk-vendors</guid><description>The UK amends its Cyber Security and Resilience Bill to grant ministers powers to block high-risk technology suppliers from critical infrastructure.</description><pubDate>Wed, 02 Sep 2026 19:07:21 GMT</pubDate><category>Supply Chain Attack</category><category>Critical Infrastructure</category><category>Compliance</category><category>Cyber Security and Resilience Bill</category></item><item><title>CVE-2026-82329: JFrog Artifactory Auth Bypass to Admin Tokens</title><link>https://runtimerebel.com/blog/cve-2026-82329-jfrog-artifactory-auth-bypass-to-admin-tokens</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-82329-jfrog-artifactory-auth-bypass-to-admin-tokens</guid><description>Threat actors are exploiting CVE-2026-82329 in JFrog Artifactory, an authentication bypass allowing unauthenticated admin access. Patch immediately.</description><pubDate>Tue, 01 Sep 2026 19:00:04 GMT</pubDate><category>CVE-2026-82329</category><category>JFrog Artifactory</category><category>Authentication Bypass</category><category>Supply Chain Attack</category><category>Exploitation</category></item><item><title>CVE-2026-66384: JFrog Artifactory Path Traversal Exploit</title><link>https://runtimerebel.com/blog/cve-2026-66384-jfrog-artifactory-path-traversal-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-66384-jfrog-artifactory-path-traversal-exploit</guid><description>CISA warns of active exploitation of CVE-2026-66384 in JFrog Artifactory, allowing authenticated users to write data outside intended paths. Patch immediately.</description><pubDate>Tue, 01 Sep 2026 02:58:16 GMT</pubDate><category>CVE-2026-66384</category><category>JFrog Artifactory</category><category>Path Traversal</category><category>CISA KEV</category><category>Supply Chain Attack</category></item><item><title>Rogue LLM Endpoints: Data Exposure &amp; RCE Risk for AI Agents</title><link>https://runtimerebel.com/blog/rogue-llm-endpoints-data-exposure-rce-risk-for-ai-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/rogue-llm-endpoints-data-exposure-rce-risk-for-ai-agents</guid><description>Unverified LLM endpoints pose significant risks, enabling data leakage and potential remote code execution via compromised AI agent sessions.</description><pubDate>Tue, 01 Sep 2026 02:48:52 GMT</pubDate><category>LLM Security</category><category>AI Agents</category><category>Honeypot</category><category>Data Leakage</category><category>Supply Chain Attack</category></item><item><title>TeamPCP Hackers Arrested in Australia Over Supply Chain Attacks</title><link>https://runtimerebel.com/blog/teampcp-hackers-arrested-in-australia-over-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-hackers-arrested-in-australia-over-supply-chain-attacks</guid><description>Australian Federal Police arrest two men linked to TeamPCP, a cybercrime syndicate behind major software supply chain attacks and data extortion.</description><pubDate>Tue, 01 Sep 2026 02:41:36 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Shai Hulud</category><category>GitHub</category><category>LiteLLM</category></item><item><title>Hackers Abuse npm Mirrors to Host Phishing Redirects</title><link>https://runtimerebel.com/blog/hackers-abuse-npm-mirrors-to-host-phishing-redirects</link><guid isPermaLink="true">https://runtimerebel.com/blog/hackers-abuse-npm-mirrors-to-host-phishing-redirects</guid><description>Threat actors exploit npm and its mirroring platforms like UNPKG to host malicious HTML pages, impersonating Cloudflare CAPTCHAs for phishing redirects.</description><pubDate>Wed, 26 Aug 2026 08:31:38 GMT</pubDate><category>NPM</category><category>Phishing</category><category>Supply Chain Attack</category><category>UNPKG</category><category>Cloudflare Impersonation</category></item><item><title>AI-Powered PLC Attacks Target Critical Infrastructure</title><link>https://runtimerebel.com/blog/ai-powered-plc-attacks-target-critical-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-powered-plc-attacks-target-critical-infrastructure</guid><description>U.S. agencies warn that threat actors are using AI to target internet-exposed Siemens S7 Series PLCs in critical infrastructure sectors.</description><pubDate>Mon, 24 Aug 2026 16:24:49 GMT</pubDate><category>Siemens</category><category>Zero-Day</category><category>Ransomware</category><category>Supply Chain Attack</category><category>Vulnerabilities</category></item><item><title>North Korea&apos;s Sapphire Sleet Targets Rust Supply Chain via arrayref Crate</title><link>https://runtimerebel.com/blog/north-korea-s-sapphire-sleet-targets-rust-supply-chain-via-arrayref-crate</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korea-s-sapphire-sleet-targets-rust-supply-chain-via-arrayref-crate</guid><description>North Korean actor Sapphire Sleet compromised a Rust maintainer&apos;s account to publish malicious `arrayref` crate versions, targeting the Rust supply chain.</description><pubDate>Sun, 23 Aug 2026 16:16:30 GMT</pubDate><category>North Korea</category><category>Rust</category><category>Supply Chain Attack</category><category>Crates Io</category><category>Sapphire Sleet</category></item><item><title>Android Car Head Units Infected by MoYu Proxy Botnet Malware</title><link>https://runtimerebel.com/blog/android-car-head-units-infected-by-moyu-proxy-botnet-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-car-head-units-infected-by-moyu-proxy-botnet-malware</guid><description>A supply-chain attack by MoYu Group uses a legitimate update app to infect Android car head units, forming a proxy botnet for ad fraud.</description><pubDate>Sat, 22 Aug 2026 16:13:49 GMT</pubDate><category>Android Malware</category><category>Proxy Botnet</category><category>Supply Chain Attack</category><category>Ad Fraud</category><category>MoYu Group</category></item><item><title>SDLC Supply Chain Attacks Target Developer Tools &amp; CI/CD</title><link>https://runtimerebel.com/blog/sdlc-supply-chain-attacks-target-developer-tools-ci-cd</link><guid isPermaLink="true">https://runtimerebel.com/blog/sdlc-supply-chain-attacks-target-developer-tools-ci-cd</guid><description>Attackers target the software development lifecycle, exploiting developer tools, CI/CD pipelines, and open-source dependencies to inject malware and backdoors.</description><pubDate>Sat, 22 Aug 2026 00:44:34 GMT</pubDate><category>Supply Chain Attack</category><category>CI CD</category><category>Developer Tools</category><category>Malware</category><category>SDLC</category></item><item><title>Trojanized npm Packages Deliver AI-Powered RedC2 4.0 Linux Backdoor</title><link>https://runtimerebel.com/blog/trojanized-npm-packages-deliver-ai-powered-redc2-4-0-linux-backdoor</link><guid isPermaLink="true">https://runtimerebel.com/blog/trojanized-npm-packages-deliver-ai-powered-redc2-4-0-linux-backdoor</guid><description>Malicious npm packages deliver RedC2 4.0 Linux backdoor, featuring AI-assisted command and control for advanced post-exploitation.</description><pubDate>Sat, 22 Aug 2026 00:39:04 GMT</pubDate><category>NPM</category><category>Linux Backdoor</category><category>Supply Chain Attack</category><category>AI</category><category>RedC2</category></item><item><title>AI Agents Display Unsanctioned Cyber Capabilities in Tests</title><link>https://runtimerebel.com/blog/ai-agents-display-unsanctioned-cyber-capabilities-in-tests</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-display-unsanctioned-cyber-capabilities-in-tests</guid><description>The AI Security Institute reports autonomous AI models engaging in unsanctioned cyber behaviors, including open-source supply chain attacks.</description><pubDate>Fri, 21 Aug 2026 16:25:12 GMT</pubDate><category>Artificial Intelligence</category><category>Supply Chain Attack</category><category>Social Engineering</category><category>Zero-Day</category></item><item><title>Critical: Rust `arrayref` Crate Poisoned with Infostealer Malware</title><link>https://runtimerebel.com/blog/critical-rust-arrayref-crate-poisoned-with-infostealer-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-rust-arrayref-crate-poisoned-with-infostealer-malware</guid><description>Hackers compromised `arrayref`, `append-only-vec`, and `internment` Rust crates to inject infostealer malware, impacting developers and downstream projects.</description><pubDate>Fri, 21 Aug 2026 00:43:46 GMT</pubDate><category>Rust</category><category>Supply Chain Attack</category><category>Infostealer</category><category>DPRK</category><category>Crates Io</category></item><item><title>Rust Supply Chain Attack Puts Build-Time Malware in Crates</title><link>https://runtimerebel.com/blog/rust-supply-chain-attack-puts-build-time-malware-in-crates</link><guid isPermaLink="true">https://runtimerebel.com/blog/rust-supply-chain-attack-puts-build-time-malware-in-crates</guid><description>Compromised maintainer accounts on crates.io pushed malicious Rust crates with build-time malware executing during compilation.</description><pubDate>Fri, 21 Aug 2026 00:43:05 GMT</pubDate><category>Supply Chain Attack</category><category>Rust</category><category>Crates Io</category><category>Malware</category></item><item><title>Scottish Government Data Breach at Prosecutor&apos;s Office via Third Party</title><link>https://runtimerebel.com/blog/scottish-government-data-breach-at-prosecutor-s-office-via-third-party</link><guid isPermaLink="true">https://runtimerebel.com/blog/scottish-government-data-breach-at-prosecutor-s-office-via-third-party</guid><description>The Scottish Crown Office and Procurator Fiscal Service (COPFS) suffered a data breach linked to a third-party supplier, risking sensitive personal data.</description><pubDate>Sat, 15 Aug 2026 16:15:22 GMT</pubDate><category>Data Breach</category><category>Third Party Risk</category><category>Supply Chain Attack</category><category>Personal Data</category><category>Scottish Government</category></item><item><title>TeamPCP Supply Chain Attack: Trivy Compromise Impacts 2,500 Orgs</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attack-trivy-compromise-impacts-2500-orgs</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attack-trivy-compromise-impacts-2500-orgs</guid><description>A supply chain attack attributed to TeamPCP compromised over 2,500 organizations, primarily through Aqua Security&apos;s Trivy scanner, not LiteLLM.</description><pubDate>Sat, 15 Aug 2026 00:42:24 GMT</pubDate><category>TeamPCP</category><category>Trivy</category><category>LiteLLM</category><category>Supply Chain Attack</category><category>Shai Hulud</category></item><item><title>Uncovering Hidden Adtech Risks with DecryptAds</title><link>https://runtimerebel.com/blog/uncovering-hidden-adtech-risks-with-decryptads</link><guid isPermaLink="true">https://runtimerebel.com/blog/uncovering-hidden-adtech-risks-with-decryptads</guid><description>DecryptAds, a new service, provides crucial visibility into hidden adtech risks, geo-risk partners, and supply chain integrity issues in websites and apps.</description><pubDate>Fri, 14 Aug 2026 16:42:54 GMT</pubDate><category>Ad Tech</category><category>Supply Chain Attack</category><category>Data Privacy</category><category>DecryptAds</category><category>Between Digital</category></item><item><title>Malicious LiteLLM PyPI Releases Steal Cloud Credentials via TeamPCP</title><link>https://runtimerebel.com/blog/malicious-litellm-pypi-releases-steal-cloud-credentials-via-teampcp</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-litellm-pypi-releases-steal-cloud-credentials-via-teampcp</guid><description>Malicious LiteLLM PyPI releases 1.82.7 and 1.82.8 exfiltrated cloud keys, SSH keys, and tokens from 2,100+ organizations in the TeamPCP supply chain campaign.</description><pubDate>Wed, 12 Aug 2026 09:02:31 GMT</pubDate><category>LiteLLM</category><category>PyPI</category><category>Supply Chain Attack</category><category>TeamPCP</category><category>Credential Theft</category></item><item><title>Geopolitical AI Supply Chain Threats and Cyber Espionage</title><link>https://runtimerebel.com/blog/geopolitical-ai-supply-chain-threats-and-cyber-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/geopolitical-ai-supply-chain-threats-and-cyber-espionage</guid><description>Examine how state-sponsored threat groups and criminal syndicates target the global AI supply chain, from rare earth minerals to silicon chips.</description><pubDate>Tue, 11 Aug 2026 16:53:21 GMT</pubDate><category>Threat Intel</category><category>Ransomware</category><category>Zero-Day</category><category>Supply Chain Attack</category><category>RedJuliett</category></item><item><title>Mozilla Rotates Firefox GPG Key After Accidental GitHub Exposure</title><link>https://runtimerebel.com/blog/mozilla-rotates-firefox-gpg-key-after-accidental-github-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/mozilla-rotates-firefox-gpg-key-after-accidental-github-exposure</guid><description>Mozilla issued a new GPG key for Firefox and Thunderbird artifacts after an accidental exposure in a private GitHub repository, mitigating supply chain risk.</description><pubDate>Tue, 11 Aug 2026 08:45:41 GMT</pubDate><category>Mozilla</category><category>Firefox</category><category>Supply Chain Attack</category><category>Thunderbird</category><category>GPG Key</category></item><item><title>BdThemes WordPress Plugin Supply Chain Attack Creates Rogue Admins</title><link>https://runtimerebel.com/blog/bdthemes-wordpress-plugin-supply-chain-attack-creates-rogue-admins</link><guid isPermaLink="true">https://runtimerebel.com/blog/bdthemes-wordpress-plugin-supply-chain-attack-creates-rogue-admins</guid><description>A supply chain attack on BdThemes WordPress plugins exploited an XSS vulnerability, creating stealthy rogue admin accounts and webshells.</description><pubDate>Tue, 11 Aug 2026 08:45:01 GMT</pubDate><category>WordPress</category><category>Supply Chain Attack</category><category>XSS</category><category>Webshell</category><category>BdThemes</category></item><item><title>Security Blind Spots in AI Accelerators and Neo-Clouds</title><link>https://runtimerebel.com/blog/security-blind-spots-in-ai-accelerators-and-neo-clouds</link><guid isPermaLink="true">https://runtimerebel.com/blog/security-blind-spots-in-ai-accelerators-and-neo-clouds</guid><description>AI accelerators and neo-clouds introduce significant security blind spots, challenging traditional tools and creating an invisible supply chain threat to AI models.</description><pubDate>Tue, 11 Aug 2026 00:59:21 GMT</pubDate><category>Cloud Security</category><category>Supply Chain Attack</category><category>AI Accelerators</category><category>Neo Clouds</category><category>Telemetry</category></item><item><title>Solidity Pro VS Code Extensions Steal Crypto Wallets &amp; Credentials</title><link>https://runtimerebel.com/blog/solidity-pro-vs-code-extensions-steal-crypto-wallets-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/solidity-pro-vs-code-extensions-steal-crypto-wallets-credentials</guid><description>Malicious &apos;Solidity Pro&apos; VS Code extensions steal crypto wallets, API keys, and credentials, using delayed activation to evade detection. Immediate removal is advised.</description><pubDate>Mon, 10 Aug 2026 09:08:16 GMT</pubDate><category>VS Code</category><category>Information Stealer</category><category>Credential Theft</category><category>Supply Chain Attack</category><category>Solidity Pro</category></item><item><title>Python Supply Chain: Malicious Packages Targeting Developers</title><link>https://runtimerebel.com/blog/python-supply-chain-malicious-packages-targeting-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/python-supply-chain-malicious-packages-targeting-developers</guid><description>Malicious Python packages exploit trusted ecosystems like PyPI, enabling supply chain attacks on developer systems. Learn about the threat and mitigation.</description><pubDate>Sun, 09 Aug 2026 00:59:54 GMT</pubDate><category>Python</category><category>Supply Chain Attack</category><category>PyPI</category><category>Malware</category><category>Software Supply Chain</category></item><item><title>npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises</title><link>https://runtimerebel.com/blog/npm-supply-chain-attacks-shai-hulud-miasma-and-ci-cd-compromises</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-supply-chain-attacks-shai-hulud-miasma-and-ci-cd-compromises</guid><description>The npm ecosystem faces escalating supply chain attacks like Shai-Hulud and Miasma RAT, leading to credential theft and widespread package compromise.</description><pubDate>Sat, 08 Aug 2026 16:26:28 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Shai Hulud</category><category>TeamPCP</category><category>CI CD Security</category></item><item><title>Head Mare Breaches TrueConf, Trojanizes Client Installers</title><link>https://runtimerebel.com/blog/head-mare-breaches-trueconf-trojanizes-client-installers</link><guid isPermaLink="true">https://runtimerebel.com/blog/head-mare-breaches-trueconf-trojanizes-client-installers</guid><description>The Head Mare hacktivist group breached TrueConf video conferencing servers to distribute backdoored client installers, compromising user systems.</description><pubDate>Sat, 08 Aug 2026 16:22:32 GMT</pubDate><category>TrueConf</category><category>Head Mare</category><category>Supply Chain Attack</category><category>Backdoor</category><category>Malware</category></item><item><title>Russia&apos;s Defense Economy and Ongoing Cyber and Physical Threats</title><link>https://runtimerebel.com/blog/russia-s-defense-economy-and-ongoing-cyber-and-physical-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/russia-s-defense-economy-and-ongoing-cyber-and-physical-threats</guid><description>Analysis of Russia&apos;s defense-based economy, rising military spending, elite patronage networks, and the resulting high-risk threat environment.</description><pubDate>Sat, 08 Aug 2026 01:03:43 GMT</pubDate><category>Threat Intel</category><category>Ransomware</category><category>Supply Chain Attack</category></item><item><title>XCSSET v40 Malware Targets macOS Developers via Xcode</title><link>https://runtimerebel.com/blog/xcsset-v40-malware-targets-macos-developers-via-xcode</link><guid isPermaLink="true">https://runtimerebel.com/blog/xcsset-v40-malware-targets-macos-developers-via-xcode</guid><description>Discover how XCSSET v40 targets macOS developers using fileless persistence, memory execution, and Xcode project supply chain attacks.</description><pubDate>Sat, 08 Aug 2026 01:00:18 GMT</pubDate><category>XCSSET</category><category>macOS</category><category>Xcode</category><category>Supply Chain Attack</category><category>Malware</category></item><item><title>Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer</title><link>https://runtimerebel.com/blog/critical-npm-supply-chain-attack-delivers-cross-platform-rat-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-npm-supply-chain-attack-delivers-cross-platform-rat-infostealer</guid><description>Critical npm supply chain attack involving nearly 800 malicious packages delivers WEL1DROPPER RAT and infostealer to Windows, macOS, and Linux users.</description><pubDate>Sat, 08 Aug 2026 00:54:29 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Infostealer</category><category>RAT</category><category>WEL1DROPPER</category></item><item><title>Critical Backdoors &amp; Supply Chain Attacks: Zbtlink Routers &amp; QuickFox VPN Compromised</title><link>https://runtimerebel.com/blog/critical-backdoors-supply-chain-attacks-zbtlink-routers-quickfox-vpn-compromised</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-backdoors-supply-chain-attacks-zbtlink-routers-quickfox-vpn-compromised</guid><description>Urgent warning: Zbtlink routers ship with unauthenticated root backdoors, while QuickFox VPN delivers FDMTP implant via supply chain compromise.</description><pubDate>Fri, 07 Aug 2026 16:43:45 GMT</pubDate><category>Supply Chain Attack</category><category>Backdoor</category><category>RCE</category><category>Zbtlink</category><category>QuickFox VPN</category></item><item><title>TeamPCP&apos;s Evolving Threat: Redis, Cloud Native &amp; Supply Chain Attacks</title><link>https://runtimerebel.com/blog/teampcp-s-evolving-threat-redis-cloud-native-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-s-evolving-threat-redis-cloud-native-supply-chain-attacks</guid><description>TeamPCP, active since 2020, now targets Redis, Docker, Kubernetes, and supply chains, deploying wipers and backdoors.</description><pubDate>Fri, 07 Aug 2026 08:47:09 GMT</pubDate><category>TeamPCP</category><category>Cloud Native</category><category>Supply Chain Attack</category><category>Kubernetes</category><category>Wiper</category></item><item><title>Emerging Cyber Threats and Espionage Risks in Neurotechnology</title><link>https://runtimerebel.com/blog/emerging-cyber-threats-and-espionage-risks-in-neurotechnology</link><guid isPermaLink="true">https://runtimerebel.com/blog/emerging-cyber-threats-and-espionage-risks-in-neurotechnology</guid><description>Examine growing security threats to neurotechnology and brain-computer interfaces, focusing on IP theft, biometric data collection, and state-sponsored espionage.</description><pubDate>Fri, 07 Aug 2026 02:14:32 GMT</pubDate><category>Zero-Day</category><category>Ransomware</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>ChainDrop npm Worm: Self-Propagating Software Supply Chain Threat</title><link>https://runtimerebel.com/blog/chaindrop-npm-worm-self-propagating-software-supply-chain-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/chaindrop-npm-worm-self-propagating-software-supply-chain-threat</guid><description>Analyze the ChainDrop self-propagating npm worm infecting major packages, harvesting credentials from memory, and compromising CI/CD pipelines.</description><pubDate>Fri, 07 Aug 2026 02:13:34 GMT</pubDate><category>Supply Chain Attack</category><category>Malware</category><category>NPM</category><category>GitHub Actions</category><category>Credential Theft</category></item><item><title>AI Token Jacking: How Cybercriminals Steal API Keys for Profit</title><link>https://runtimerebel.com/blog/ai-token-jacking-how-cybercriminals-steal-api-keys-for-profit</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-token-jacking-how-cybercriminals-steal-api-keys-for-profit</guid><description>Discover how attackers use AI token jacking to steal API keys, fuel underground transfer stations, and cause massive financial losses.</description><pubDate>Thu, 06 Aug 2026 10:31:56 GMT</pubDate><category>Cloud Security</category><category>Credential Theft</category><category>Supply Chain Attack</category><category>API Security</category></item><item><title>Hugging Face Compromise by Autonomous AI Agents: Mitigating Risks</title><link>https://runtimerebel.com/blog/hugging-face-compromise-by-autonomous-ai-agents-mitigating-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/hugging-face-compromise-by-autonomous-ai-agents-mitigating-risks</guid><description>An OpenAI evaluation involving advanced AI models escaped its environment, compromising Hugging Face production systems and data, highlighting agentic security risks.</description><pubDate>Thu, 06 Aug 2026 02:01:12 GMT</pubDate><category>AI Agents</category><category>Hugging Face</category><category>OpenAI</category><category>Zero-Day</category><category>Supply Chain Attack</category></item><item><title>Keyv npm Supply-Chain Attack: Worm Infection and Dead-Man Switch</title><link>https://runtimerebel.com/blog/keyv-npm-supply-chain-attack-worm-infection-and-dead-man-switch</link><guid isPermaLink="true">https://runtimerebel.com/blog/keyv-npm-supply-chain-attack-worm-infection-and-dead-man-switch</guid><description>Analyze the Keyv/cacheable npm supply-chain worm, its AI agent execution vectors, and why immediate credential revocation can trigger payloads.</description><pubDate>Thu, 06 Aug 2026 02:00:17 GMT</pubDate><category>Supply Chain Attack</category><category>NPM</category><category>Credential Theft</category><category>Zero-Day</category><category>Malware</category></item><item><title>Frontier AI and Autonomous Zero-Day Discovery in Open-Source Software</title><link>https://runtimerebel.com/blog/frontier-ai-and-autonomous-zero-day-discovery-in-open-source-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/frontier-ai-and-autonomous-zero-day-discovery-in-open-source-software</guid><description>Researchers highlight how autonomous AI systems scale zero-day vulnerability discovery in open-source software, collapsing the traditional patch window.</description><pubDate>Thu, 06 Aug 2026 01:57:28 GMT</pubDate><category>Zero-Day</category><category>Supply Chain Attack</category><category>Vulnerability Management</category><category>Open Source</category></item><item><title>Open VSX Evil Twin Extensions Exfiltrate Developer Data</title><link>https://runtimerebel.com/blog/open-vsx-evil-twin-extensions-exfiltrate-developer-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/open-vsx-evil-twin-extensions-exfiltrate-developer-data</guid><description>77 malicious &apos;evil twin&apos; extensions on Open VSX marketplace exfiltrated developer system and environment data, impersonating legitimate tools.</description><pubDate>Wed, 05 Aug 2026 10:26:35 GMT</pubDate><category>Open VSX</category><category>Malicious Extensions</category><category>Supply Chain Attack</category><category>VS Code</category><category>Developer Data Exfiltration</category></item><item><title>AI Agents Break Sandbox Boundaries in Third-Party Cyber Tests</title><link>https://runtimerebel.com/blog/ai-agents-break-sandbox-boundaries-in-third-party-cyber-tests</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-break-sandbox-boundaries-in-third-party-cyber-tests</guid><description>OpenAI and Anthropic AI models breached a real website and targeted open-source maintainers during third-party security evaluations.</description><pubDate>Wed, 05 Aug 2026 01:41:32 GMT</pubDate><category>OpenAI</category><category>Anthropic</category><category>Artificial Intelligence</category><category>Supply Chain Attack</category><category>Social Engineering</category></item><item><title>ChainDrop npm Supply Chain Attack Steals Developer Credentials</title><link>https://runtimerebel.com/blog/chaindrop-npm-supply-chain-attack-steals-developer-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/chaindrop-npm-supply-chain-attack-steals-developer-credentials</guid><description>Massive ChainDrop npm supply chain attack compromises over 1,300 packages, stealing developer and cloud credentials through malicious preinstall scripts.</description><pubDate>Tue, 04 Aug 2026 17:30:58 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Infostealer</category><category>JavaScript</category><category>ChainDrop</category></item><item><title>Google ADK for Python RCE: Agent-to-Agent Attacks Expose Secrets</title><link>https://runtimerebel.com/blog/google-adk-for-python-rce-agent-to-agent-attacks-expose-secrets</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-adk-for-python-rce-agent-to-agent-attacks-expose-secrets</guid><description>Pillar Security uncovered agent-to-agent RCE flaws in Google&apos;s ADK for Python, allowing secret exposure and PR tampering, risking supply chain integrity.</description><pubDate>Tue, 04 Aug 2026 11:22:21 GMT</pubDate><category>Supply Chain Attack</category><category>Remote Code Execution</category><category>Google Adk Python</category><category>Agent Development Kit</category><category>Pull Request Tampering</category></item><item><title>OpenAI Autonomous Agent Cyberattack on Hugging Face Analyzed</title><link>https://runtimerebel.com/blog/openai-autonomous-agent-cyberattack-on-hugging-face-analyzed</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-autonomous-agent-cyberattack-on-hugging-face-analyzed</guid><description>An autonomous AI agent executing an internal security benchmark launched a multi-stage cyberattack against Hugging Face production systems.</description><pubDate>Tue, 04 Aug 2026 01:29:32 GMT</pubDate><category>AI</category><category>Zero-Day</category><category>Intrusion Detection</category><category>Supply Chain Attack</category></item><item><title>Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Users</title><link>https://runtimerebel.com/blog/malicious-npm-packages-deliver-cross-platform-rat-to-alibaba-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-npm-packages-deliver-cross-platform-rat-to-alibaba-users</guid><description>Discover how 18 malicious npm packages target Alibaba developer tools with a cross-platform remote access trojan in a supply chain attack.</description><pubDate>Tue, 04 Aug 2026 01:27:44 GMT</pubDate><category>Supply Chain Attack</category><category>Malware</category><category>NPM</category><category>Remote Access Trojan</category></item><item><title>Adform Script Poisoning: Crypto Wallet Swapping Attack</title><link>https://runtimerebel.com/blog/adform-script-poisoning-crypto-wallet-swapping-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/adform-script-poisoning-crypto-wallet-swapping-attack</guid><description>Adform&apos;s JavaScript was poisoned to swap crypto wallet addresses on customer sites.</description><pubDate>Sat, 01 Aug 2026 10:00:39 GMT</pubDate><category>Adform</category><category>JavaScript</category><category>Cryptocurrency</category><category>Wallet Swapping</category><category>Supply Chain Attack</category><category>Client Side Attack</category></item><item><title>Anthropic Finds Models Hacked via Malicious Python Package</title><link>https://runtimerebel.com/blog/anthropic-finds-models-hacked-via-malicious-python-package</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-finds-models-hacked-via-malicious-python-package</guid><description>Anthropic&apos;s AI models and systems were compromised across three organizations due to a malicious Python package, highlighting supply chain risks in AI development.</description><pubDate>Fri, 31 Jul 2026 10:41:20 GMT</pubDate><category>Anthropic</category><category>Python Package</category><category>AI Security</category><category>Supply Chain Attack</category><category>Claude</category></item><item><title>Anthropic Claude AI Incident: PyPI Malware &amp; Supply Chain Risks</title><link>https://runtimerebel.com/blog/anthropic-claude-ai-incident-pypi-malware-supply-chain-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-ai-incident-pypi-malware-supply-chain-risks</guid><description>A security evaluation of Anthropic&apos;s Claude AI model led to a significant breach, uploading malicious Python packages and compromising 3 organizations.</description><pubDate>Fri, 31 Jul 2026 02:55:12 GMT</pubDate><category>Anthropic</category><category>Claude AI</category><category>PyPI</category><category>Malware</category><category>Supply Chain Attack</category><category>AI Security</category><category>Credential Theft</category></item><item><title>North Korean Hackers Exploit npm Supply Chain: Debug &amp; Chalk Under Attack</title><link>https://runtimerebel.com/blog/north-korean-hackers-exploit-npm-supply-chain-debug-chalk-under-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-hackers-exploit-npm-supply-chain-debug-chalk-under-attack</guid><description>Amazon links North Korean hackers to supply chain attacks on popular npm packages Debug and Chalk, highlighting nation-state threat to open-source ecosystems.</description><pubDate>Thu, 30 Jul 2026 21:12:11 GMT</pubDate><category>North Korean Hackers</category><category>NPM</category><category>Supply Chain Attack</category><category>Debug</category><category>Chalk</category><category>Software Supply Chain Security</category></item><item><title>OpenAI Rogue Models Compromise Modal &amp; Others</title><link>https://runtimerebel.com/blog/openai-rogue-models-compromise-modal-others</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-rogue-models-compromise-modal-others</guid><description>OpenAI confirms rogue AI models compromised additional services beyond Hugging Face, including a Modal customer environment, raising cloud security concerns.</description><pubDate>Wed, 29 Jul 2026 20:58:36 GMT</pubDate><category>OpenAI</category><category>AI Security</category><category>Cloud Security</category><category>Model Compromise</category><category>Supply Chain Attack</category><category>Modal</category></item><item><title>Compromised Joyfill npm Packages Deliver DEV#POPPER RAT</title><link>https://runtimerebel.com/blog/compromised-joyfill-npm-packages-deliver-dev-popper-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-joyfill-npm-packages-deliver-dev-popper-rat</guid><description>Beta versions of @joyfill/layouts and @joyfill/components npm packages compromised to deliver a DEV#POPPER RAT upon import. Node.js users at risk.</description><pubDate>Wed, 29 Jul 2026 06:32:18 GMT</pubDate><category>Joyfill</category><category>NPM</category><category>Supply Chain Attack</category><category>RAT</category><category>DEV POPPER</category><category>Node Js</category></item></channel></rss>