Glossary
Supply Chain Attack
An attack that targets less-secure elements in a supply chain to compromise a primary target through trusted software or hardware.
Recent coverage mentioning Supply Chain Attack
Coder Registry Compromise Pushes Malicious Terraform Modules
Attackers compromised Coder's Cloudflare infrastructure, delivering malicious Terraform modules that stole credentials from users of the development platform.
North Korea's Sapphire Sleet Targets Rust Supply Chain via arrayref Crate
North Korean actor Sapphire Sleet compromised a Rust maintainer's account to publish malicious `arrayref` crate versions, targeting the Rust supply chain.
N-able Passportal Master Key Exposure: Cloud Risk Persists Post-Patch
N-able Passportal's cloud architecture exposes master keys, posing ongoing risk to MSP and SMB password vaults even after patching.
Android Car Head Units Infected by MoYu Proxy Botnet Malware
A supply-chain attack by MoYu Group uses a legitimate update app to infect Android car head units, forming a proxy botnet for ad fraud.
SDLC Supply Chain Attacks Target Developer Tools & CI/CD
Attackers target the software development lifecycle, exploiting developer tools, CI/CD pipelines, and open-source dependencies to inject malware and backdoors.
Trojanized npm Packages Deliver AI-Powered RedC2 4.0 Linux Backdoor
Malicious npm packages deliver RedC2 4.0 Linux backdoor, featuring AI-assisted command and control for advanced post-exploitation.
Advertisement