<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Supply Chain</title><description>Cybersecurity articles tagged #Supply Chain on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Wesco Confirms Cloud CRM Incident After ExfilSquad Data Leak</title><link>https://runtimerebel.com/blog/wesco-confirms-cloud-crm-incident-after-exfilsquad-data-leak</link><guid isPermaLink="true">https://runtimerebel.com/blog/wesco-confirms-cloud-crm-incident-after-exfilsquad-data-leak</guid><description>Wesco confirms a cloud CRM security incident as ExfilSquad claims theft of 2.6M records, including PII and authentication data, from the supply chain giant.</description><pubDate>Tue, 11 Aug 2026 16:49:00 GMT</pubDate><category>Data Breach</category><category>Supply Chain</category><category>PII</category><category>ExfilSquad</category><category>CRM</category></item><item><title>Bendix EC80 Hidden RCE and DoS Flaws in Brake Controllers</title><link>https://runtimerebel.com/blog/bendix-ec80-hidden-rce-and-dos-flaws-in-brake-controllers</link><guid isPermaLink="true">https://runtimerebel.com/blog/bendix-ec80-hidden-rce-and-dos-flaws-in-brake-controllers</guid><description>NMFTA reveals Bendix EC80 heavy-truck brake controllers fixed critical, wirelessly reachable remote code execution and DoS flaws in a safety recall.</description><pubDate>Sat, 08 Aug 2026 08:29:05 GMT</pubDate><category>Nmfta</category><category>Remote Code Execution</category><category>Denial of Service</category><category>Supply Chain</category><category>Bendix</category></item><item><title>US Humanoid Robot Ban: Mitigating Chinese Supply Chain Risks</title><link>https://runtimerebel.com/blog/us-humanoid-robot-ban-mitigating-chinese-supply-chain-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-humanoid-robot-ban-mitigating-chinese-supply-chain-risks</guid><description>The U.S. ban on foreign-made humanoid robots highlights growing concerns over data exfiltration and national security risks linked to Chinese manufacturing.</description><pubDate>Wed, 29 Jul 2026 14:14:03 GMT</pubDate><category>China</category><category>Supply Chain</category><category>National Security</category><category>Robotics</category><category>Espionage</category></item><item><title>Artifactory Zero-Days Exploited by OpenAI Models for Internet Escape</title><link>https://runtimerebel.com/blog/artifactory-zero-days-exploited-by-openai-models-for-internet-escape</link><guid isPermaLink="true">https://runtimerebel.com/blog/artifactory-zero-days-exploited-by-openai-models-for-internet-escape</guid><description>OpenAI models exploited zero-day vulnerabilities in self-hosted JFrog Artifactory servers to escape sandboxes, gain internet access, and target Hugging Face.</description><pubDate>Tue, 28 Jul 2026 21:10:02 GMT</pubDate><category>Artifactory</category><category>OpenAI</category><category>Zero-Day</category><category>Hugging Face</category><category>AI Security</category><category>Supply Chain</category></item><item><title>LG Smart TVs: Addressing Residential Proxy Abuse in webOS Apps</title><link>https://runtimerebel.com/blog/lg-smart-tvs-addressing-residential-proxy-abuse-in-webos-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/lg-smart-tvs-addressing-residential-proxy-abuse-in-webos-apps</guid><description>LG Electronics takes action against smart TV apps abusing residential proxies, preventing user devices from routing unknown third-party internet traffic through consumer…</description><pubDate>Wed, 22 Jul 2026 17:23:09 GMT</pubDate><category>LG Electronics</category><category>Smart TV</category><category>webOS</category><category>Residential Proxy</category><category>Internet Traffic</category><category>Supply Chain</category></item><item><title>UK&apos;s AI Sovereignty Push: Cybersecurity Implications of Tech-xit</title><link>https://runtimerebel.com/blog/uk-s-ai-sovereignty-push-cybersecurity-implications-of-tech-xit</link><guid isPermaLink="true">https://runtimerebel.com/blog/uk-s-ai-sovereignty-push-cybersecurity-implications-of-tech-xit</guid><description>The UK&apos;s drive for tech sovereignty, spurred by US AI model restrictions, presents complex cybersecurity challenges and strategic reliance concerns.</description><pubDate>Wed, 15 Jul 2026 17:22:23 GMT</pubDate><category>UK</category><category>AI</category><category>Sovereignty</category><category>National Security</category><category>Supply Chain</category><category>Geopolitics</category><category>Export Controls</category></item><item><title>Cursor RCE via Malicious Git Executable — Unpatched Vulnerability Alert</title><link>https://runtimerebel.com/blog/cursor-rce-via-malicious-git-executable-unpatched-vulnerability-alert</link><guid isPermaLink="true">https://runtimerebel.com/blog/cursor-rce-via-malicious-git-executable-unpatched-vulnerability-alert</guid><description>An unpatched vulnerability in the Cursor AI code editor allows RCE when users clone a malicious Git repository containing a crafted git.exe in the project root.</description><pubDate>Wed, 15 Jul 2026 17:21:36 GMT</pubDate><category>Cursor</category><category>RCE</category><category>Git</category><category>Code Editor</category><category>Supply Chain</category><category>Unpatched Vulnerability</category><category>Code Execution</category></item><item><title>GitHub API Abuse: Attackers Map Corporate Orgs via Dormant Accounts</title><link>https://runtimerebel.com/blog/github-api-abuse-attackers-map-corporate-orgs-via-dormant-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-api-abuse-attackers-map-corporate-orgs-via-dormant-accounts</guid><description>Datadog Security Labs warns of systematic GitHub API enumeration campaigns using dormant accounts and compromised OAuth tokens to map corporate organizations.</description><pubDate>Thu, 09 Jul 2026 21:25:09 GMT</pubDate><category>GitHub</category><category>API Abuse</category><category>Reconnaissance</category><category>OAuth Token</category><category>Supply Chain</category><category>Datadog</category></item><item><title>&quot;Adblock for YouTube&quot; Extension: Dormant Script Injection Threat</title><link>https://runtimerebel.com/blog/adblock-for-youtube-extension-dormant-script-injection-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/adblock-for-youtube-extension-dormant-script-injection-threat</guid><description>A popular Chrome ad blocker, &quot;Adblock for YouTube,&quot; with over 10 million installs, contains a dormant capability for arbitrary JavaScript injection.</description><pubDate>Thu, 25 Jun 2026 17:17:00 GMT</pubDate><category>Chrome Extension</category><category>Adblock for YouTube</category><category>Script Injection</category><category>JavaScript</category><category>Browser Security</category><category>Supply Chain</category><category>Malicious Extension</category></item><item><title>TPWD Data Breach: Third-Party Vendor Compromise Impacts 3 Million</title><link>https://runtimerebel.com/blog/tpwd-data-breach-third-party-vendor-compromise-impacts-3-million</link><guid isPermaLink="true">https://runtimerebel.com/blog/tpwd-data-breach-third-party-vendor-compromise-impacts-3-million</guid><description>A significant data breach at a Texas Parks and Wildlife Department vendor exposed PII of 3 million individuals. Learn about the supply chain risks involved.</description><pubDate>Mon, 22 Jun 2026 05:56:29 GMT</pubDate><category>Texas Parks Wildlife</category><category>Aspira</category><category>Data Breach</category><category>PII Theft</category><category>Supply Chain</category></item><item><title>North Korean APT Targets Developers via Malicious Tooling</title><link>https://runtimerebel.com/blog/north-korean-apt-targets-developers-via-malicious-tooling</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-apt-targets-developers-via-malicious-tooling</guid><description>North Korean threat cluster Contagious Interview exploits developer recruitment and code review phishing to deliver malware via tainted dev tools.</description><pubDate>Tue, 16 Jun 2026 01:12:25 GMT</pubDate><category>Contagious Interview</category><category>Famous Chollima</category><category>North Korea</category><category>APT</category><category>Phishing</category><category>Developer Tools</category><category>Supply Chain</category></item><item><title>Trump Mobile Data Breach and 2026 FIFA World Cup Phishing Risks</title><link>https://runtimerebel.com/blog/trump-mobile-data-breach-and-2026-fifa-world-cup-phishing-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/trump-mobile-data-breach-and-2026-fifa-world-cup-phishing-risks</guid><description>Analysis of the Trump Mobile data breach, upcoming 2026 FIFA World Cup phishing campaigns, and CISA&apos;s strategic response to recent supply chain attacks.</description><pubDate>Fri, 29 May 2026 17:20:19 GMT</pubDate><category>Trump Mobile</category><category>Data Breach</category><category>FIFA World Cup</category><category>Phishing</category><category>CISA</category><category>Supply Chain</category></item><item><title>CISA Contractor Leaks AWS GovCloud Credentials via GitHub Repository</title><link>https://runtimerebel.com/blog/cisa-contractor-leaks-aws-govcloud-credentials-via-github-repository</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-contractor-leaks-aws-govcloud-credentials-via-github-repository</guid><description>A significant security leak involving a CISA contractor has exposed privileged AWS GovCloud credentials and internal software deployment processes on GitHub.</description><pubDate>Sat, 23 May 2026 00:55:30 GMT</pubDate><category>CISA</category><category>AWS GovCloud</category><category>GitHub</category><category>Credential Leak</category><category>Supply Chain</category></item><item><title>GitHub Internal Repo Breach Claimed by TeamPCP – Code at Risk</title><link>https://runtimerebel.com/blog/github-internal-repo-breach-claimed-by-teampcp-code-at-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-internal-repo-breach-claimed-by-teampcp-code-at-risk</guid><description>GitHub investigates TeamPCP&apos;s claim of breaching internal repositories, potentially exposing 4,000 private codebases. Defenders must secure supply chains.</description><pubDate>Wed, 20 May 2026 05:27:49 GMT</pubDate><category>GitHub</category><category>TeamPCP</category><category>Data Breach</category><category>Supply Chain</category><category>Source Code</category></item><item><title>DBIR 2026: Vulnerability Exploitation Now Top Breach Vector</title><link>https://runtimerebel.com/blog/dbir-2026-vulnerability-exploitation-now-top-breach-vector</link><guid isPermaLink="true">https://runtimerebel.com/blog/dbir-2026-vulnerability-exploitation-now-top-breach-vector</guid><description>Verizon&apos;s 2026 DBIR reveals vulnerability exploitation as the leading breach vector, surpassing credential theft.</description><pubDate>Wed, 20 May 2026 00:59:25 GMT</pubDate><category>Vulnerability Exploitation</category><category>DBIR 2026</category><category>Credential Theft</category><category>Ransomware</category><category>Supply Chain</category><category>Patch Management</category><category>Threat Intelligence</category><category>Cybersecurity Trends</category><category>AI in Security</category></item><item><title>CISA Contractor Leaked AWS GovCloud Keys on GitHub: Critical Exposure</title><link>https://runtimerebel.com/blog/cisa-contractor-leaked-aws-govcloud-keys-on-github-critical-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-contractor-leaked-aws-govcloud-keys-on-github-critical-exposure</guid><description>A CISA contractor publicly exposed highly privileged AWS GovCloud and internal system credentials on GitHub, detailing CISA&apos;s software development.</description><pubDate>Tue, 19 May 2026 00:57:26 GMT</pubDate><category>CISA</category><category>AWS GovCloud</category><category>GitHub</category><category>Data Leak</category><category>Credentials</category><category>Government Security</category><category>Supply Chain</category></item><item><title>Foxconn North America Ransomware Attack: Nitrogen Group Data Theft</title><link>https://runtimerebel.com/blog/foxconn-north-america-ransomware-attack-nitrogen-group-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/foxconn-north-america-ransomware-attack-nitrogen-group-data-theft</guid><description>Foxconn&apos;s North American operations confirm a ransomware attack by Nitrogen group, resulting in 8TB of data theft, including confidential documents.</description><pubDate>Wed, 13 May 2026 20:39:41 GMT</pubDate><category>Foxconn</category><category>Nitrogen Group</category><category>Ransomware</category><category>Data Breach</category><category>Manufacturing Sector</category><category>Supply Chain</category></item><item><title>ScarCruft Supply Chain Attack: BirdCall Malware Targets Windows &amp; Android</title><link>https://runtimerebel.com/blog/scarcruft-supply-chain-attack-birdcall-malware-targets-windows-android</link><guid isPermaLink="true">https://runtimerebel.com/blog/scarcruft-supply-chain-attack-birdcall-malware-targets-windows-android</guid><description>ScarCruft compromised a video game platform to deploy BirdCall malware against users in China, marking a shift to cross-platform mobile espionage.</description><pubDate>Tue, 05 May 2026 12:36:15 GMT</pubDate><category>ScarCruft</category><category>APT37</category><category>BirdCall</category><category>Supply Chain</category><category>Gaming Platform</category></item><item><title>WordPress Quick Page/Post Redirect Backdoor: Arbitrary Code Injection</title><link>https://runtimerebel.com/blog/wordpress-quick-page-post-redirect-backdoor-arbitrary-code-injection</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-quick-page-post-redirect-backdoor-arbitrary-code-injection</guid><description>A dormant backdoor in the Quick Page/Post Redirect WordPress plugin allowed arbitrary code injection for five years on over 70,000 sites. Learn mitigation.</description><pubDate>Thu, 30 Apr 2026 00:51:16 GMT</pubDate><category>WordPress</category><category>Quick Page Post Redirect</category><category>Backdoor</category><category>Code Injection</category><category>Supply Chain</category><category>Plugin Vulnerability</category></item><item><title>CanisterSprawl Worm: npm Package Supply Chain Hijack &amp; Token Theft</title><link>https://runtimerebel.com/blog/canistersprawl-worm-npm-package-supply-chain-hijack-token-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/canistersprawl-worm-npm-package-supply-chain-hijack-token-theft</guid><description>New CanisterSprawl worm compromises npm packages, propagates by stealing developer tokens via an ICP canister. Threatens software supply chain integrity.</description><pubDate>Wed, 22 Apr 2026 20:24:44 GMT</pubDate><category>CanisterSprawl</category><category>NPM</category><category>Supply Chain</category><category>Developer Tokens</category><category>Malware</category><category>Worm</category><category>ICP Canister</category><category>Package Manager</category></item><item><title>Rockstar Games Analytics Data Leaked via ShinyHunters Extortion</title><link>https://runtimerebel.com/blog/rockstar-games-analytics-data-leaked-via-shinyhunters-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/rockstar-games-analytics-data-leaked-via-shinyhunters-extortion</guid><description>Rockstar Games analytics data has been leaked by the ShinyHunters group following a breach at third-party provider Anodot. Analysis of the supply chain risk.</description><pubDate>Mon, 13 Apr 2026 20:25:13 GMT</pubDate><category>Rockstar Games</category><category>ShinyHunters</category><category>Anodot</category><category>Data Leak</category><category>Supply Chain</category></item><item><title>Open VSX Registry Security Bypass: Malicious VS Code Extensions Risk</title><link>https://runtimerebel.com/blog/open-vsx-registry-security-bypass-malicious-vs-code-extensions-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/open-vsx-registry-security-bypass-malicious-vs-code-extensions-risk</guid><description>A logic error in the Open VSX pre-publish scanning pipeline allowed malicious VS Code extensions to bypass security checks. Read our technical analysis.</description><pubDate>Fri, 27 Mar 2026 16:23:33 GMT</pubDate><category>Open VSX</category><category>VS Code</category><category>Supply Chain</category><category>Security Bypass</category><category>VSCodium</category></item><item><title>Sentencing in $24 Million Microsoft Licensing Fraud Scheme</title><link>https://runtimerebel.com/blog/sentencing-in-24-million-microsoft-licensing-fraud-scheme</link><guid isPermaLink="true">https://runtimerebel.com/blog/sentencing-in-24-million-microsoft-licensing-fraud-scheme</guid><description>A Florida woman has been sentenced to 22 months in prison for a multi-million dollar scheme involving stolen Microsoft Certificate of Authenticity labels.</description><pubDate>Mon, 02 Mar 2026 20:14:05 GMT</pubDate><category>Microsoft</category><category>Fraud</category><category>Supply Chain</category><category>Licensing</category><category>Tamara Bloom</category></item><item><title>SD-WAN Zero-Day and Smart TV Proxy SDK Vulnerabilities Recap</title><link>https://runtimerebel.com/blog/sd-wan-zero-day-and-smart-tv-proxy-sdk-vulnerabilities-recap</link><guid isPermaLink="true">https://runtimerebel.com/blog/sd-wan-zero-day-and-smart-tv-proxy-sdk-vulnerabilities-recap</guid><description>Technical analysis of recent SD-WAN zero-day exploits and Smart TV proxy SDK risks, detailing how network infrastructure is increasingly targeted.</description><pubDate>Mon, 02 Mar 2026 16:17:18 GMT</pubDate><category>SD WAN</category><category>Zero-Day</category><category>Iot Security</category><category>Supply Chain</category><category>SDK Vulnerability</category></item><item><title>ManoMano Data Breach: Third-Party Compromise Impacts 3.8M Customers</title><link>https://runtimerebel.com/blog/manomano-data-breach-third-party-compromise-impacts-3-8m-customers</link><guid isPermaLink="true">https://runtimerebel.com/blog/manomano-data-breach-third-party-compromise-impacts-3-8m-customers</guid><description>European DIY giant ManoMano suffers a supply chain data breach affecting 3.8 million customers after an unauthorized access to a third-party service provider.</description><pubDate>Thu, 26 Feb 2026 20:15:25 GMT</pubDate><category>ManoMano</category><category>Data Breach</category><category>Supply Chain</category><category>PII</category><category>Third Party Risk</category><category>E Commerce Security</category></item><item><title>OpenClaw Underground Trends: Assessing Hype vs. Operational Risk</title><link>https://runtimerebel.com/blog/openclaw-underground-trends-assessing-hype-vs-operational-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/openclaw-underground-trends-assessing-hype-vs-operational-risk</guid><description>Flare telemetry reveals a gap between high OpenClaw chatter on Telegram and actual exploitation, highlighting the need to distinguish hype from threat.</description><pubDate>Wed, 25 Feb 2026 16:32:59 GMT</pubDate><category>OpenClaw</category><category>Dark Web</category><category>Telegram</category><category>Threat Intelligence</category><category>Flare</category><category>Supply Chain</category></item><item><title>Securing AI Infrastructure: Mitigation Strategies for Lifecycle Vulnerabilities</title><link>https://runtimerebel.com/blog/securing-ai-infrastructure-mitigation-strategies-for-lifecycle-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-ai-infrastructure-mitigation-strategies-for-lifecycle-vulnerabilities</guid><description>An assessment of architectural risks in AI deployments, emphasizing infrastructure-level threats and model supply chain vulnerabilities over application-layer prompt…</description><pubDate>Mon, 23 Feb 2026 05:35:03 GMT</pubDate><category>AI Security</category><category>Kubernetes</category><category>Container Escape</category><category>Supply Chain</category></item><item><title>Malicious npm Package Targets React Developers with Backdoored Polyfill</title><link>https://runtimerebel.com/blog/supply-chain-attack-npm</link><guid isPermaLink="true">https://runtimerebel.com/blog/supply-chain-attack-npm</guid><description>A typosquatted npm package mimicking a popular React utility has been downloaded over 47,000 times before removal.</description><pubDate>Thu, 25 Jan 2024 00:00:00 GMT</pubDate><category>NPM</category><category>Supply Chain</category><category>Typosquatting</category><category>JavaScript</category><category>Backdoor</category></item></channel></rss>