TeamPCP arrests expose supply chain risk
Alleged masterminds of TeamPCP, tied to Shai-Hulud worm, arrested in Perth with FBI help.
30 results for “supply chain”
Alleged masterminds of TeamPCP, tied to Shai-Hulud worm, arrested in Perth with FBI help.
Executive Order 14420 bars risky foreign grid gear, empowering DOE to vet or remove equipment.
Researchers uncover 14 malicious npm packages delivering RedC2 4.0, an AI-assisted Linux backdoor, via stealthy loader.
Wiz links a crates.io compromise to Sapphire Sleet, warning of broad developer exposure.
Two flaws in JFrog Artifactory could let low-privileged users tamper with package metadata and compromise software supply chains.
OpenSourceMalware finds 16 typosquatted RubyGems, but the real risk is package name reuse and unvalidated author fields.
Pokémon Center UK cancels orders after logistics partner CEVA suffers cyberattack, exposing customer data.
Anthropic and OpenAI trade narratives of accidental sandbox escapes, raising questions about the safety of their frontier models.
Scotland's prosecution service warns 300 staff their personal data may be exposed in a cyberattack on a third-party supplier.
Kyoto Fusioneering lands U.S. grants to build a fuel breeding device at Oak Ridge.
Sonatype finds six npm packages reading C2 addresses from an Ethereum wallet transaction linked to DPRK.
A Ceva Logistics data breach affecting European clients shows how supply chain attacks ripple outward.
Attackers planted rogue admins and webshells on WordPress sites via a poisoned data feed, not file changes.
New campaigns targeting Python packages highlight the growing vulnerability of AI infrastructure and developer environments.
Expert Edna Conway argues that true digital resilience requires moving past checkbox compliance to address complex supply chain risks.
New npm malware hides command-and-control infrastructure within zero-value Ethereum transfer addresses to bypass traditional detection.
A malicious campaign on the Open VSX marketplace deployed 77 counterfeit extensions to harvest developer metadata.
Researchers identify a recurring security flaw where AI agents blindly execute commands based on predictable, hallucinated names.
Researchers find top AI models consistently inventing identical, non-existent library names that attackers could potentially weaponize.
The Swiss train manufacturer confirms it rejected a multi-million dollar extortion attempt following a third-party data breach.
A campaign dubbed FakeGit uses 7,600 fake GitHub repositories to trick AI agents into installing the SmartLoader malware family.
A compromised third-party support platform has led to the exposure of client tax files at professional services giant Ernst & Young.
A new campaign targeting Vite developers uses a four-tier blockchain infrastructure to bypass traditional security takedown efforts.
Skyrocketing memory costs for AI infrastructure are forcing handset price hikes and stifling shipment volumes in the Indian market.
A Chinese sub-group's infiltration of DigiCert reveals how stolen code-signing certificates are weaponized against the industry.
North Korean threat actors are using fake coding tests and steganography to compromise developer systems and steal sensitive data.
London-based Risk Ledger plans to expand its network-first security platform into the US following a successful Series B raise.
A major cyberattack on Japanese food giant Nichirei exposes the fragility of global cold storage and automated shipping networks.
Compromised AsyncAPI and Jscrambler packages expose developers to credential theft via automated malicious injection.
A cyberattack targeting Fairlife has forced an immediate, temporary suspension of production for the Coca-Cola dairy subsidiary.