Skip to main content
← All Articles

Tag

#supply-chain-security

26 articles

Advertisement

DA
HIGH
Data Breach

Trellix Source Code Repository Breach Analysis and Impact

Trellix confirms a data breach following unauthorized access to source code repositories via a third-party service. Learn the impact and mitigation steps.

Runtime Rebel Intel
4 min read·May 4, 2026
AI-Powered Phishing and GitHub RCE: Analyzing Modern Breach Trends
HIGH
Threat Intel

AI-Powered Phishing and GitHub RCE: Analyzing Modern Breach Trends

Threat actors are using AI-powered phishing and GitHub RCE to move from simple breaches to long-term occupation of SaaS and open-source environments.

Runtime Rebel Intel
3 min read·May 4, 2026
TH
HIGH
Threat Intel

FBI Warning: Cyber-Enabled Cargo Theft Losses Surge to $725 Million

FBI alerts logistics firms to a massive rise in cyber-enabled cargo theft involving identity theft and fraudulent carrier profiles. Protect your supply chain.

Runtime Rebel Intel
3 min read·Apr 30, 2026
SU
HIGH
Supply Chain

Bitwarden NPM Supply Chain Attack: Analyzing the TeamPCP Campaign

A malicious npm package impersonating Bitwarden was discovered exfiltrating sensitive data via the Shai-Hulud worm in a recent supply chain attack.

Runtime Rebel Intel
3 min read·Apr 24, 2026
Vercel Breach and QEMU Abuse: Analyzing Modern Trust-Based Attacks
HIGH
Threat Intel

Vercel Breach and QEMU Abuse: Analyzing Modern Trust-Based Attacks

Analysis of the Vercel infrastructure compromise, QEMU-based evasion techniques, and the rise of Android RATs leveraging update channels for delivery.

Runtime Rebel Intel
4 min read·Apr 20, 2026
Third-Party Risk Intelligence: Beyond Legacy Cyber Risk Ratings
INFO
Supply Chain

Third-Party Risk Intelligence: Beyond Legacy Cyber Risk Ratings

Discover why modern cybersecurity strategies are shifting from static vendor risk ratings to dynamic, real-time third-party risk intelligence operations.

Runtime Rebel Intel
4 min read·Apr 10, 2026
36 Malicious npm Packages Target Strapi, Redis, and PostgreSQL
HIGH
Supply Chain

36 Malicious npm Packages Target Strapi, Redis, and PostgreSQL

36 malicious npm packages disguised as Strapi CMS plugins target Redis and PostgreSQL environments to deploy persistent implants and reverse shells.

Runtime Rebel Intel
4 min read·Apr 5, 2026
SU
CRITICAL
Supply Chain

Axios npm Hijack Attempt: Detecting Social Engineering Tactics

North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.

Runtime Rebel Intel
3 min read·Apr 5, 2026
SU
MEDIUM
Supply Chain

FCC Regulates Foreign Consumer Routers Over Supply Chain Risk

The US Executive Branch and FCC have restricted foreign-made consumer routers to mitigate critical infrastructure risks and supply chain vulnerabilities.

Runtime Rebel Intel
3 min read·Apr 3, 2026
Claude Code Source Leaked via npm Packaging Error
MEDIUM
Supply Chain

Claude Code Source Leaked via npm Packaging Error

Anthropic confirms internal Claude Code source code was leaked due to an npm packaging error. Analysis of supply chain risks and mitigation strategies.

Runtime Rebel Intel
4 min read·Apr 1, 2026
Axios npm Supply Chain Attack Attributed to North Korea's UNC1069
CRITICAL
Supply Chain

Axios npm Supply Chain Attack Attributed to North Korea's UNC1069

Google Threat Intelligence attributes a major Axios npm supply chain attack to North Korean group UNC1069, emphasizing risks to developer environments.

Runtime Rebel Intel
3 min read·Apr 1, 2026
GlassWorm: Stolen GitHub Tokens Fuel Python Malware Injection
HIGH
Supply Chain

GlassWorm: Stolen GitHub Tokens Fuel Python Malware Injection

The GlassWorm campaign uses stolen GitHub tokens to inject malicious code into Python repositories, including Django and machine learning projects.

Runtime Rebel Intel
3 min read·Mar 16, 2026