Google's mole inside a hacking crew
Google's threat intelligence team says an undercover analyst spent months inside TeamPCP, watching a supply-chain spree from behind the scenes.
21 results for “supply-chain”
Google's threat intelligence team says an undercover analyst spent months inside TeamPCP, watching a supply-chain spree from behind the scenes.
Trezor says a breach at shipping partner ShipMonk now affects 81,000 customers, a 479% jump from initial estimates.
National Audit Office warns cyber-attacks threaten food supply, adding to costs and price inflation.
Attackers exploited routing and TLS flaws to abuse a hijacked /24 block in a 22-hour window.
Attackers are exploiting CVE-2026-82329, a critical Artifactory authentication bypass, to mint admin tokens.
Researchers uncover 13 malicious Packagist packages that inject spyware into streaming sites, stealing crypto wallet seeds.
A 33-hour BGP hijack hit Softaculous, serving malware via Virtualizor updates and prompting credential resets.
Alleged masterminds of TeamPCP, tied to Shai-Hulud worm, arrested in Perth with FBI help.
Attackers abuse npm mirrors to host HTML phishing pages, bypassing security filters by serving from legitimate domains.
Supply-chain attack on Android car head units turns them into proxy nodes and ad fraud tools.
OpenSourceMalware finds 16 typosquatted RubyGems, but the real risk is package name reuse and unvalidated author fields.
SOCRadar says most orgs hit in LiteLLM attack were earlier Trivy victims, not LiteLLM.
A wave of tools claim to strip AI watermarks, but verification is impossible as Anthropic hasn't released details.
CloudSEK details how a Trivy compromise cascaded into LiteLLM, affecting 2,500+ orgs and 434,000 pipelines.
Mozilla replaced the GPG key for Firefox and Thunderbird after an unencrypted copy leaked to a private GitHub repo.
Chainguard webinar examines how security teams can manage risk when AI speeds up code production by 10-50x.
A malicious VS Code extension pack targets developers, exfiltrating wallets, credentials, and API keys via Telegram.
Attackers planted rogue admins and webshells on WordPress sites via a poisoned data feed, not file changes.
A self-propagating malware campaign has compromised over 1,300 npm packages, leveraging legitimate GitHub workflows to spread.
A systemic vulnerability across major AI coding assistants highlights the dangerous failure of human-in-the-loop security protocols.
A malicious npm package injection forced a swift cleanup, highlighting the persistent dangers of compromised build environments.