<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Supply Chain Security</title><description>Cybersecurity articles tagged #Supply Chain Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CMMC Compliance: Confidence Rises, Proof Lags for DoD Contractors</title><link>https://runtimerebel.com/blog/cmmc-compliance-confidence-rises-proof-lags-for-dod-contractors</link><guid isPermaLink="true">https://runtimerebel.com/blog/cmmc-compliance-confidence-rises-proof-lags-for-dod-contractors</guid><description>DoD contractors report higher confidence in CMMC compliance, yet struggle to provide verifiable proof, leading to legal and contract risks.</description><pubDate>Mon, 24 Aug 2026 00:42:31 GMT</pubDate><category>Supply Chain Security</category><category>Compliance</category><category>CMMC</category><category>DFARS</category><category>DoD</category></item><item><title>Recorded Future Enhances Third-Party Risk with Unified Threat Intel</title><link>https://runtimerebel.com/blog/recorded-future-enhances-third-party-risk-with-unified-threat-intel</link><guid isPermaLink="true">https://runtimerebel.com/blog/recorded-future-enhances-third-party-risk-with-unified-threat-intel</guid><description>Recorded Future integrates threat intelligence and risk ratings into a unified third-party risk management platform to proactively identify vendor compromises.</description><pubDate>Wed, 19 Aug 2026 16:25:18 GMT</pubDate><category>Threat Intelligence</category><category>Third Party Risk Management</category><category>Vendor Risk</category><category>Recorded Future</category><category>Supply Chain Security</category></item><item><title>Nico Waisman: Evolution of Offensive Security and Open Source</title><link>https://runtimerebel.com/blog/nico-waisman-evolution-of-offensive-security-and-open-source</link><guid isPermaLink="true">https://runtimerebel.com/blog/nico-waisman-evolution-of-offensive-security-and-open-source</guid><description>Explore Nico Waisman&apos;s journey from self-taught hacker to pioneering offensive security and leading open source supply chain efforts.</description><pubDate>Tue, 18 Aug 2026 16:21:57 GMT</pubDate><category>Offensive Security</category><category>Open Source Security</category><category>Penetration Testing</category><category>Supply Chain Security</category><category>GitHub Security Lab</category></item><item><title>NC Ports Cyberattack Disrupts Operations at Key Facilities</title><link>https://runtimerebel.com/blog/nc-ports-cyberattack-disrupts-operations-at-key-facilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/nc-ports-cyberattack-disrupts-operations-at-key-facilities</guid><description>North Carolina Ports confirmed a cyberattack disrupting IT systems and operations across its facilities. Recovery efforts are underway, with expected delays.</description><pubDate>Sun, 09 Aug 2026 08:31:30 GMT</pubDate><category>North Carolina Ports</category><category>Cyberattack</category><category>Operational Disruption</category><category>Critical Infrastructure</category><category>Supply Chain Security</category></item><item><title>Emerging Attack Vectors in AI Harnesses: Trust Boundary Exploitation</title><link>https://runtimerebel.com/blog/emerging-attack-vectors-in-ai-harnesses-trust-boundary-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/emerging-attack-vectors-in-ai-harnesses-trust-boundary-exploitation</guid><description>Analysis of potential exploit opportunities within complex AI software stacks due to inter-component trust issues. Understand emerging attack vectors.</description><pubDate>Thu, 30 Jul 2026 21:13:36 GMT</pubDate><category>AI Security</category><category>Machine Learning Security</category><category>Trust Boundaries</category><category>Supply Chain Security</category><category>Emerging Threats</category></item><item><title>FCC Blocks Foreign Robots and Power Inverters via Covered List</title><link>https://runtimerebel.com/blog/fcc-blocks-foreign-robots-and-power-inverters-via-covered-list</link><guid isPermaLink="true">https://runtimerebel.com/blog/fcc-blocks-foreign-robots-and-power-inverters-via-covered-list</guid><description>The FCC has added foreign-produced mobile robots and networked power inverters to the Covered List, citing supply chain risks and national security concerns.</description><pubDate>Thu, 30 Jul 2026 10:26:21 GMT</pubDate><category>FCC</category><category>Covered List</category><category>Mobile Robots</category><category>Power Inverters</category><category>Supply Chain Security</category><category>National Security</category></item><item><title>GitHub and PyPI Policy Updates Target Supply Chain Security</title><link>https://runtimerebel.com/blog/github-and-pypi-policy-updates-target-supply-chain-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-and-pypi-policy-updates-target-supply-chain-security</guid><description>GitHub and PyPI introduce new restrictions to thwart supply chain attacks, including a Dependabot cooldown and limits on historical package file uploads.</description><pubDate>Mon, 27 Jul 2026 14:40:00 GMT</pubDate><category>GitHub</category><category>PyPI</category><category>Supply Chain Security</category><category>Dependabot</category><category>Open Source</category></item><item><title>Lookout MSEC: Tackling Supply Chain Risks via Mobile App SBOMs</title><link>https://runtimerebel.com/blog/lookout-msec-tackling-supply-chain-risks-via-mobile-app-sboms</link><guid isPermaLink="true">https://runtimerebel.com/blog/lookout-msec-tackling-supply-chain-risks-via-mobile-app-sboms</guid><description>Lookout launches the Mobile Security Exposure Center (MSEC) to provide visibility into vulnerable third-party components and mobile app dependencies via SBOMs.</description><pubDate>Mon, 27 Jul 2026 11:26:52 GMT</pubDate><category>Lookout MSEC</category><category>SBOM</category><category>Mobile App Security</category><category>Supply Chain Security</category><category>Application Risk</category></item><item><title>GitHub Dependabot 3-Day Cooldown: Mitigating Supply Chain Attacks</title><link>https://runtimerebel.com/blog/github-dependabot-3-day-cooldown-mitigating-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-dependabot-3-day-cooldown-mitigating-supply-chain-attacks</guid><description>GitHub introduces a 3-day cooldown for Dependabot to prevent the rapid adoption of malicious packages, enhancing supply chain security for developers.</description><pubDate>Mon, 27 Jul 2026 11:25:20 GMT</pubDate><category>GitHub</category><category>Dependabot</category><category>Supply Chain Security</category><category>Malicious Packages</category><category>Open Source</category></item><item><title>GitHub and PyPI Time-Based Defenses Against Supply Chain Attacks</title><link>https://runtimerebel.com/blog/github-and-pypi-time-based-defenses-against-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-and-pypi-time-based-defenses-against-supply-chain-attacks</guid><description>GitHub and PyPI introduce time-based delays in Dependabot to mitigate supply chain attacks by preventing the immediate ingestion of malicious packages.</description><pubDate>Sun, 26 Jul 2026 17:03:02 GMT</pubDate><category>GitHub</category><category>PyPI</category><category>Dependabot</category><category>Supply Chain Security</category><category>Python</category></item><item><title>Risk Ledger Secures $32M Series B for Supply Chain Risk Platform</title><link>https://runtimerebel.com/blog/risk-ledger-secures-32m-series-b-for-supply-chain-risk-platform</link><guid isPermaLink="true">https://runtimerebel.com/blog/risk-ledger-secures-32m-series-b-for-supply-chain-risk-platform</guid><description>Risk Ledger raises $32 million in Series B funding to scale its collaborative supply chain security platform, addressing critical third-party risk management.</description><pubDate>Fri, 17 Jul 2026 10:00:13 GMT</pubDate><category>Risk Ledger</category><category>Supply Chain Security</category><category>TPRM</category><category>Series B Funding</category><category>Cyber Risk Management</category></item><item><title>ThreatsDay Report: Emerging Deception &amp; Rapid Ransomware Threats</title><link>https://runtimerebel.com/blog/threatsday-report-emerging-deception-rapid-ransomware-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/threatsday-report-emerging-deception-rapid-ransomware-threats</guid><description>Analysis of recent threats, including deceptive game cheat spyware, rapid ransomware deployments, and Chrome sync abuse.</description><pubDate>Thu, 16 Jul 2026 17:22:58 GMT</pubDate><category>Spyware</category><category>Ransomware</category><category>Social Engineering</category><category>Supply Chain Security</category><category>Deception</category><category>Chrome</category></item><item><title>2-Click Cursor Exploit: Dev Environment Takeover Risks &amp; Mitigations</title><link>https://runtimerebel.com/blog/2-click-cursor-exploit-dev-environment-takeover-risks-mitigations</link><guid isPermaLink="true">https://runtimerebel.com/blog/2-click-cursor-exploit-dev-environment-takeover-risks-mitigations</guid><description>Analyze the &apos;2-click cursor exploit&apos; leveraging &apos;age-old bugs&apos; to compromise developer environments, risking source code and IP theft.</description><pubDate>Wed, 15 Jul 2026 13:49:23 GMT</pubDate><category>Developer Environments</category><category>Supply Chain Security</category><category>Application Security</category><category>Exploitation</category><category>Source Code Theft</category></item><item><title>Cybersecurity M&amp;A Trends: Implications for Enterprise Security</title><link>https://runtimerebel.com/blog/cybersecurity-m-a-trends-implications-for-enterprise-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/cybersecurity-m-a-trends-implications-for-enterprise-security</guid><description>Analyze the impact of 37 cybersecurity M&amp;A deals in June 2026 on vendor ecosystems, supply chain risks, and security strategy for enterprises.</description><pubDate>Mon, 13 Jul 2026 14:43:37 GMT</pubDate><category>Cybersecurity M a</category><category>Vendor Consolidation</category><category>Supply Chain Security</category><category>Security Strategy</category><category>Industry Trends</category></item><item><title>npm 12 Enhances Supply Chain Security by Disabling Install Scripts</title><link>https://runtimerebel.com/blog/npm-12-enhances-supply-chain-security-by-disabling-install-scripts</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-12-enhances-supply-chain-security-by-disabling-install-scripts</guid><description>npm version 12 introduces critical security defaults, disabling install scripts and deprecating GATs, significantly mitigating JavaScript supply chain risks.</description><pubDate>Thu, 09 Jul 2026 17:57:40 GMT</pubDate><category>NPM</category><category>Supply Chain Security</category><category>Install Scripts</category><category>Security Defaults</category><category>GATs</category><category>2FA</category><category>JavaScript Packages</category></item><item><title>Cyberwarfare Fallout: Global Business Cybersecurity Gameplans</title><link>https://runtimerebel.com/blog/cyberwarfare-fallout-global-business-cybersecurity-gameplans</link><guid isPermaLink="true">https://runtimerebel.com/blog/cyberwarfare-fallout-global-business-cybersecurity-gameplans</guid><description>Businesses globally face increased cyberwarfare risks from geopolitical conflicts.</description><pubDate>Thu, 09 Jul 2026 15:16:21 GMT</pubDate><category>Cyber Warfare</category><category>Geopolitical Risk</category><category>Supply Chain Security</category><category>Critical Infrastructure Protection</category><category>Business Continuity</category><category>Organizational Resilience</category></item><item><title>GitHub Actions Attack Patterns Evade CI Security Scanners</title><link>https://runtimerebel.com/blog/github-actions-attack-patterns-evade-ci-security-scanners</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-actions-attack-patterns-evade-ci-security-scanners</guid><description>Learn how sophisticated GitHub Actions attack patterns bypass traditional CI security scanners, exposing CI/CD pipelines to supply chain risks.</description><pubDate>Tue, 07 Jul 2026 14:38:51 GMT</pubDate><category>GitHub Actions</category><category>CI CD Security</category><category>Supply Chain Security</category><category>Security Scanning</category><category>Code Integrity</category></item><item><title>How Agentjacking Exploits AI Coding Agents via Fake Bug Reports</title><link>https://runtimerebel.com/blog/how-agentjacking-exploits-ai-coding-agents-via-fake-bug-reports</link><guid isPermaLink="true">https://runtimerebel.com/blog/how-agentjacking-exploits-ai-coding-agents-via-fake-bug-reports</guid><description>Researchers demonstrate &apos;Agentjacking,&apos; a technique using indirect prompt injection to hijack AI coding agents through malicious GitHub bug reports.</description><pubDate>Wed, 01 Jul 2026 09:21:10 GMT</pubDate><category>Agentjacking</category><category>Prompt Injection</category><category>AI Security</category><category>Trail of Bits</category><category>Opendevin</category><category>Supply Chain Security</category></item><item><title>Malware Evades AI Analysis with &apos;Forbidden Text&apos; Tactics</title><link>https://runtimerebel.com/blog/malware-evades-ai-analysis-with-forbidden-text-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/malware-evades-ai-analysis-with-forbidden-text-tactics</guid><description>Threat actors embed &apos;forbidden&apos; text in malware to confuse AI analysis tools, targeting bioinformatics and MCP developers.</description><pubDate>Thu, 25 Jun 2026 05:28:25 GMT</pubDate><category>AI Evasion</category><category>Malware Analysis</category><category>Mini Shai Hulud</category><category>Miasma</category><category>Hades Worms</category><category>Bioinformatics Security</category><category>Supply Chain Security</category></item><item><title>Magnitude Secures $10M to Advance AI in Third-Party Risk Management</title><link>https://runtimerebel.com/blog/magnitude-secures-10m-to-advance-ai-in-third-party-risk-management</link><guid isPermaLink="true">https://runtimerebel.com/blog/magnitude-secures-10m-to-advance-ai-in-third-party-risk-management</guid><description>Magnitude emerges from stealth with $10 million in funding to evolve third-party risk management using autonomous AI agents, bolstering supply chain security.</description><pubDate>Tue, 16 Jun 2026 13:58:54 GMT</pubDate><category>Magnitude</category><category>TPRM</category><category>Third Party Risk Management</category><category>AI</category><category>Autonomous Agents</category><category>Supply Chain Security</category></item><item><title>Tech Coalition Athena: Collaborative OSS Vulnerability Pre-Disclosure</title><link>https://runtimerebel.com/blog/tech-coalition-athena-collaborative-oss-vulnerability-pre-disclosure</link><guid isPermaLink="true">https://runtimerebel.com/blog/tech-coalition-athena-collaborative-oss-vulnerability-pre-disclosure</guid><description>The Athena coalition, comprising over two dozen organizations, establishes a shared platform to proactively triage and remediate open-source software vulnerabilities…</description><pubDate>Tue, 16 Jun 2026 10:00:00 GMT</pubDate><category>Athena</category><category>Open Source Software</category><category>Vulnerability Management</category><category>Supply Chain Security</category><category>Pre Disclosure</category></item><item><title>GitHub to Disable npm Install Scripts by Default in Version 12</title><link>https://runtimerebel.com/blog/github-to-disable-npm-install-scripts-by-default-in-version-12</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-to-disable-npm-install-scripts-by-default-in-version-12</guid><description>GitHub announces breaking changes for npm v12, disabling install scripts by default to prevent malicious code execution and enhance supply chain security.</description><pubDate>Thu, 11 Jun 2026 09:37:20 GMT</pubDate><category>NPM</category><category>GitHub</category><category>Npm V12</category><category>Supply Chain Security</category><category>Malware Prevention</category></item><item><title>SoFi Hong Kong Data Breach via Third-Party Vendor Compromise</title><link>https://runtimerebel.com/blog/sofi-hong-kong-data-breach-via-third-party-vendor-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/sofi-hong-kong-data-breach-via-third-party-vendor-compromise</guid><description>Analysis of the SoFi Hong Kong data breach impacting customer information, stemming from a third-party vendor compromise. Includes mitigation strategies.</description><pubDate>Tue, 09 Jun 2026 00:56:25 GMT</pubDate><category>SoFi Hong Kong</category><category>Data Breach</category><category>Third Party Risk</category><category>Supply Chain Security</category><category>Customer Data</category><category>Financial Services</category></item><item><title>VS Code Extension Auto-Update Delay: Mitigating Supply Chain Attacks</title><link>https://runtimerebel.com/blog/vs-code-extension-auto-update-delay-mitigating-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/vs-code-extension-auto-update-delay-mitigating-supply-chain-attacks</guid><description>Microsoft introduces a two-hour delay for VS Code extension auto-updates to prevent rapid compromise during software supply chain attacks.</description><pubDate>Mon, 08 Jun 2026 09:44:07 GMT</pubDate><category>Visual Studio Code</category><category>Microsoft</category><category>Supply Chain Security</category><category>IDE Extensions</category></item><item><title>PAN-OS Exploitation and Linux Auth Flaws: Weekly Threat Recap</title><link>https://runtimerebel.com/blog/pan-os-exploitation-and-linux-auth-flaws-weekly-threat-recap</link><guid isPermaLink="true">https://runtimerebel.com/blog/pan-os-exploitation-and-linux-auth-flaws-weekly-threat-recap</guid><description>An analysis of active PAN-OS exploitation, a new Linux authentication flaw, and the rise of AI-powered OAuth phishing kits targeting enterprise environments.</description><pubDate>Mon, 01 Jun 2026 14:10:36 GMT</pubDate><category>Linux Vulnerability</category><category>PAN OS</category><category>Oauth Phishing</category><category>Supply Chain Security</category></item><item><title>Geopolitical Competition and Cyber Risks of Humanoid Robotics</title><link>https://runtimerebel.com/blog/geopolitical-competition-and-cyber-risks-of-humanoid-robotics</link><guid isPermaLink="true">https://runtimerebel.com/blog/geopolitical-competition-and-cyber-risks-of-humanoid-robotics</guid><description>Analysis of how global competition for humanoid robots and embodied AI introduces physical risks and supply chain vulnerabilities for organizations.</description><pubDate>Mon, 01 Jun 2026 09:57:41 GMT</pubDate><category>Humanoid Robots</category><category>Embodied Ai</category><category>Supply Chain Security</category><category>Industrial Security</category><category>Robotics Security</category></item><item><title>Russian Intelligence Intensifies Tech Procurement and Infrastructure Recon</title><link>https://runtimerebel.com/blog/russian-intelligence-intensifies-tech-procurement-and-infrastructure-recon</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-intelligence-intensifies-tech-procurement-and-infrastructure-recon</guid><description>Russian spies are leveraging front companies and cyber espionage to bypass sanctions and gather intelligence for potential attacks on Western infrastructure.</description><pubDate>Sat, 30 May 2026 16:27:21 GMT</pubDate><category>Russian Intelligence</category><category>Sanctions Evasion</category><category>Industrial Control Systems</category><category>Supply Chain Security</category></item><item><title>Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap</title><link>https://runtimerebel.com/blog/linux-vulnerabilities-and-defender-zero-days-weekly-threat-recap</link><guid isPermaLink="true">https://runtimerebel.com/blog/linux-vulnerabilities-and-defender-zero-days-weekly-threat-recap</guid><description>Weekly intelligence recap covering Linux flaws, Microsoft Defender zero-days, router botnets, and supply chain compromises targeting developer toolchains.</description><pubDate>Mon, 25 May 2026 16:48:57 GMT</pubDate><category>Linux Security</category><category>Microsoft Defender</category><category>Supply Chain Security</category><category>Botnets</category></item><item><title>npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks</title><link>https://runtimerebel.com/blog/npm-staged-publishing-new-2fa-controls-prevent-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-staged-publishing-new-2fa-controls-prevent-supply-chain-attacks</guid><description>GitHub introduces staged publishing for npm, requiring manual 2FA approval for package releases to mitigate malicious automated updates and account takeovers.</description><pubDate>Sat, 23 May 2026 20:21:54 GMT</pubDate><category>NPM</category><category>GitHub</category><category>Supply Chain Security</category><category>Two Factor Authentication</category><category>Staged Publishing</category><category>Application Security</category></item><item><title>Grafana Codebase Stolen via TanStack Supply Chain Attack</title><link>https://runtimerebel.com/blog/grafana-codebase-stolen-via-tanstack-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/grafana-codebase-stolen-via-tanstack-supply-chain-attack</guid><description>Grafana confirms unauthorized access to private GitHub repositories after a developer token leaked in the TanStack breach was not rotated.</description><pubDate>Fri, 22 May 2026 09:17:25 GMT</pubDate><category>Grafana</category><category>TanStack</category><category>Github Token Leak</category><category>Supply Chain Security</category></item><item><title>Securing Agentic AI Workflows with Advanced AI BOM Frameworks</title><link>https://runtimerebel.com/blog/securing-agentic-ai-workflows-with-advanced-ai-bom-frameworks</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-agentic-ai-workflows-with-advanced-ai-bom-frameworks</guid><description>Learn why CISOs must transition from traditional SBOMs to Agentic-Ready AI BOMs to manage risks in autonomous AI systems and data supply chains.</description><pubDate>Fri, 22 May 2026 00:56:56 GMT</pubDate><category>AIBOM</category><category>Agentic AI</category><category>Supply Chain Security</category><category>CycloneDX</category><category>LLM Security</category></item><item><title>AI BOMs in Security: CISO Guide to Usability &amp; Influence</title><link>https://runtimerebel.com/blog/ai-boms-in-security-ciso-guide-to-usability-influence</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-boms-in-security-ciso-guide-to-usability-influence</guid><description>Explore how CISOs can effectively prepare for and integrate AI Bill of Materials (AI BOMs) into their modern security programs, influencing their generation for better…</description><pubDate>Wed, 20 May 2026 13:07:01 GMT</pubDate><category>AI</category><category>AIBOM</category><category>CISO</category><category>Supply Chain Security</category><category>Machine Learning</category><category>Risk Management</category></item><item><title>320+ @antv NPM Packages Compromised in Mini Shai-Hulud Attack</title><link>https://runtimerebel.com/blog/320-antv-npm-packages-compromised-in-mini-shai-hulud-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/320-antv-npm-packages-compromised-in-mini-shai-hulud-attack</guid><description>A maintainer account compromise has led to a major supply chain attack against Alibaba’s @antv NPM namespace, impacting over 320 visualization packages.</description><pubDate>Wed, 20 May 2026 13:06:33 GMT</pubDate><category>NPM</category><category>Mini Shai Hulud</category><category>Antv</category><category>Supply Chain Security</category><category>JavaScript</category></item><item><title>AI BOM Implementation for Enterprise Security: Bridging Visibility</title><link>https://runtimerebel.com/blog/ai-bom-implementation-for-enterprise-security-bridging-visibility</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-bom-implementation-for-enterprise-security-bridging-visibility</guid><description>Analyze the rise of AI Bill of Materials (AIBOMs), regulatory drivers like the EU AI Act, and the technical challenges of securing opaque AI supply chains.</description><pubDate>Wed, 20 May 2026 09:17:00 GMT</pubDate><category>AIBOM</category><category>AI Security</category><category>Supply Chain Security</category><category>EU AI Act</category><category>CycloneDX</category></item><item><title>AI Bills of Materials: Essential for Proactive AI Supply Chain Security</title><link>https://runtimerebel.com/blog/ai-bills-of-materials-essential-for-proactive-ai-supply-chain-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-bills-of-materials-essential-for-proactive-ai-supply-chain-security</guid><description>Explore the emerging necessity of AI Bills of Materials (AI BOMs) to manage complex AI supply chain risks and enhance transparency in AI systems by 2026.</description><pubDate>Tue, 19 May 2026 13:21:34 GMT</pubDate><category>AI BOMs</category><category>AI Security</category><category>Supply Chain Security</category><category>Risk Management</category><category>Artificial Intelligence</category><category>Transparency</category></item><item><title>Grafana GitHub Token Compromise: Codebase Stolen via PAT</title><link>https://runtimerebel.com/blog/grafana-github-token-compromise-codebase-stolen-via-pat</link><guid isPermaLink="true">https://runtimerebel.com/blog/grafana-github-token-compromise-codebase-stolen-via-pat</guid><description>Grafana Labs reports a source code breach after attackers leveraged a stolen GitHub Personal Access Token. Analysis of the impact and mitigation steps.</description><pubDate>Mon, 18 May 2026 17:03:57 GMT</pubDate><category>Grafana</category><category>GitHub</category><category>Credential Theft</category><category>Source Code Exfiltration</category><category>Supply Chain Security</category></item><item><title>Cyber-Enabled Cargo Theft: How Phishing and Identity Theft Hijack Freight</title><link>https://runtimerebel.com/blog/cyber-enabled-cargo-theft-how-phishing-and-identity-theft-hijack-freight</link><guid isPermaLink="true">https://runtimerebel.com/blog/cyber-enabled-cargo-theft-how-phishing-and-identity-theft-hijack-freight</guid><description>Cyber-enabled cargo crime leverages stolen credentials and phishing to reroute freight, replacing traditional hijackings with digital fraud and identity theft.</description><pubDate>Thu, 14 May 2026 16:47:04 GMT</pubDate><category>Cargo Theft</category><category>Supply Chain Security</category><category>Nmfta</category><category>Identity Theft</category><category>Logistics Security</category></item><item><title>RubyGems Suspends Registrations Due to Malicious Package Influx</title><link>https://runtimerebel.com/blog/rubygems-suspends-registrations-due-to-malicious-package-influx</link><guid isPermaLink="true">https://runtimerebel.com/blog/rubygems-suspends-registrations-due-to-malicious-package-influx</guid><description>RubyGems maintainers suspended new user registrations after detecting an automated attack involving over 500 malicious packages targeting platform resources.</description><pubDate>Wed, 13 May 2026 09:09:56 GMT</pubDate><category>RubyGems</category><category>Open Source Security</category><category>Package Manager</category><category>Supply Chain Security</category><category>Malicious Packages</category></item><item><title>FCC Adjusts Foreign Router Ban: Supply Chain Security Implications</title><link>https://runtimerebel.com/blog/fcc-adjusts-foreign-router-ban-supply-chain-security-implications</link><guid isPermaLink="true">https://runtimerebel.com/blog/fcc-adjusts-foreign-router-ban-supply-chain-security-implications</guid><description>The FCC has modified its ban on non-compliant foreign-made routers, extending deadlines for federal agencies. This impacts government supply chain security efforts.</description><pubDate>Tue, 12 May 2026 00:49:17 GMT</pubDate><category>FCC</category><category>Supply Chain Security</category><category>National Security</category><category>Routers</category><category>Federal Procurement</category><category>Secure Networks Act</category></item><item><title>Linux Rootkits and macOS Crypto Stealers Surge in Supply Chain Attacks</title><link>https://runtimerebel.com/blog/linux-rootkits-and-macos-crypto-stealers-surge-in-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/linux-rootkits-and-macos-crypto-stealers-surge-in-supply-chain-attacks</guid><description>Analysis of recent threats involving Linux rootkit persistence, macOS crypto-stealing malware, and the exploitation of poisoned supply chain downloads.</description><pubDate>Mon, 11 May 2026 16:59:33 GMT</pubDate><category>Linux Rootkit</category><category>macOS Malware</category><category>Supply Chain Security</category><category>Crypto Stealer</category><category>Websocket Skimmers</category></item><item><title>Quasar Linux RAT (QLNX) Targets Developers for Supply Chain Attacks</title><link>https://runtimerebel.com/blog/quasar-linux-rat-qlnx-targets-developers-for-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/quasar-linux-rat-qlnx-targets-developers-for-supply-chain-attacks</guid><description>A new Linux implant, Quasar Linux RAT (QLNX), targets developer systems for credential theft and network tunneling to compromise software supply chains.</description><pubDate>Fri, 08 May 2026 12:36:57 GMT</pubDate><category>QLNX</category><category>Quasar Linux RAT</category><category>Supply Chain Security</category><category>Linux Malware</category><category>Credential Theft</category></item><item><title>Boost Security Expands SDLC Defense via Strategic Acquisitions</title><link>https://runtimerebel.com/blog/boost-security-expands-sdlc-defense-via-strategic-acquisitions</link><guid isPermaLink="true">https://runtimerebel.com/blog/boost-security-expands-sdlc-defense-via-strategic-acquisitions</guid><description>Boost Security secures $4 million and acquires SecureIQx and Korbit.ai to streamline automated governance and security within the development lifecycle.</description><pubDate>Thu, 07 May 2026 16:42:57 GMT</pubDate><category>Boost Security</category><category>SDLC</category><category>DevSecOps</category><category>Supply Chain Security</category><category>Automated Governance</category></item><item><title>Trellix Source Code Repository Breach Analysis and Impact</title><link>https://runtimerebel.com/blog/trellix-source-code-repository-breach-analysis-and-impact</link><guid isPermaLink="true">https://runtimerebel.com/blog/trellix-source-code-repository-breach-analysis-and-impact</guid><description>Trellix confirms a data breach following unauthorized access to source code repositories via a third-party service. Learn the impact and mitigation steps.</description><pubDate>Mon, 04 May 2026 16:40:27 GMT</pubDate><category>Trellix</category><category>Source Code</category><category>Data Breach</category><category>Supply Chain Security</category></item><item><title>AI-Powered Phishing and GitHub RCE: Analyzing Modern Breach Trends</title><link>https://runtimerebel.com/blog/ai-powered-phishing-and-github-rce-analyzing-modern-breach-trends</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-powered-phishing-and-github-rce-analyzing-modern-breach-trends</guid><description>Threat actors are using AI-powered phishing and GitHub RCE to move from simple breaches to long-term occupation of SaaS and open-source environments.</description><pubDate>Mon, 04 May 2026 16:39:26 GMT</pubDate><category>AI Phishing</category><category>Github Rce</category><category>Linux Kernel Exploit</category><category>SaaS Security</category><category>Supply Chain Security</category></item><item><title>FBI Warning: Cyber-Enabled Cargo Theft Losses Surge to $725 Million</title><link>https://runtimerebel.com/blog/fbi-warning-cyber-enabled-cargo-theft-losses-surge-to-725-million</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-warning-cyber-enabled-cargo-theft-losses-surge-to-725-million</guid><description>FBI alerts logistics firms to a massive rise in cyber-enabled cargo theft involving identity theft and fraudulent carrier profiles. Protect your supply chain.</description><pubDate>Thu, 30 Apr 2026 16:37:05 GMT</pubDate><category>Cargo Theft</category><category>Logistics Security</category><category>Fraud</category><category>Identity Theft</category><category>Supply Chain Security</category></item><item><title>Bitwarden NPM Supply Chain Attack: Analyzing the TeamPCP Campaign</title><link>https://runtimerebel.com/blog/bitwarden-npm-supply-chain-attack-analyzing-the-teampcp-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/bitwarden-npm-supply-chain-attack-analyzing-the-teampcp-campaign</guid><description>A malicious npm package impersonating Bitwarden was discovered exfiltrating sensitive data via the Shai-Hulud worm in a recent supply chain attack.</description><pubDate>Fri, 24 Apr 2026 08:49:11 GMT</pubDate><category>NPM</category><category>Bitwarden</category><category>TeamPCP</category><category>Shai Hulud</category><category>Supply Chain Security</category></item><item><title>State-Sponsored Cyber Operations Targeting Critical Mineral Supply Chains</title><link>https://runtimerebel.com/blog/state-sponsored-cyber-operations-targeting-critical-mineral-supply-chains</link><guid isPermaLink="true">https://runtimerebel.com/blog/state-sponsored-cyber-operations-targeting-critical-mineral-supply-chains</guid><description>Geopolitical tensions over critical minerals fuel a rising threat of state-sponsored cyber operations targeting the global mining sector and supply chains.</description><pubDate>Thu, 23 Apr 2026 16:46:12 GMT</pubDate><category>Critical Minerals</category><category>Rare Earth Elements</category><category>State Sponsored Cyber</category><category>Mining Sector</category><category>Supply Chain Security</category><category>Geopolitical Cyber Threats</category><category>Resource Competition</category></item><item><title>Cloudsmith Funding Boosts Software Supply Chain Security Efforts</title><link>https://runtimerebel.com/blog/cloudsmith-funding-boosts-software-supply-chain-security-efforts</link><guid isPermaLink="true">https://runtimerebel.com/blog/cloudsmith-funding-boosts-software-supply-chain-security-efforts</guid><description>Cloudsmith secures $72M in Series C funding to accelerate development of its software supply chain management platform, enhancing artifact security and integrity.</description><pubDate>Thu, 23 Apr 2026 16:42:00 GMT</pubDate><category>Cloudsmith</category><category>Supply Chain Security</category><category>Artifact Management</category><category>DevOps</category><category>Funding</category></item><item><title>Vercel Breach and QEMU Abuse: Analyzing Modern Trust-Based Attacks</title><link>https://runtimerebel.com/blog/vercel-breach-and-qemu-abuse-analyzing-modern-trust-based-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/vercel-breach-and-qemu-abuse-analyzing-modern-trust-based-attacks</guid><description>Analysis of the Vercel infrastructure compromise, QEMU-based evasion techniques, and the rise of Android RATs leveraging update channels for delivery.</description><pubDate>Mon, 20 Apr 2026 16:31:44 GMT</pubDate><category>Vercel</category><category>QEMU</category><category>Android RAT</category><category>Push Fraud</category><category>Supply Chain Security</category></item><item><title>Vercel Data Breach: ShinyHunters Claim Theft of Next.js Creator Data</title><link>https://runtimerebel.com/blog/vercel-data-breach-shinyhunters-claim-theft-of-next-js-creator-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/vercel-data-breach-shinyhunters-claim-theft-of-next-js-creator-data</guid><description>Vercel confirms a security incident following claims by ShinyHunters to sell stolen data for $2 million. Analyze the impact on Next.js and supply chains.</description><pubDate>Mon, 20 Apr 2026 08:54:09 GMT</pubDate><category>Vercel</category><category>Next Js</category><category>ShinyHunters</category><category>Data Breach</category><category>Supply Chain Security</category></item></channel></rss>