supply chain security
49 stories on supply chain security, newest first, from 50 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting. Where several outlets covered the same event, the rest sit under it as extra coverage.
- Old Malicious GitHub Actions Briefly Reactivated, Reviving Mini Shai-Hulud Threat
- Google Warns: Attackers Are Targeting Your Software Build Pipelines
- GitLab's Auto-Generated Email Addresses Could Open Door to Supply Chain Attacks
- Leaked GitLab Email Address Could Let Attackers Push Code and Run Jobs as You
- Study Finds Hundreds of Leaked GitHub App Keys Still Work, Some With Admin Access
- Old CDN Domain Resold: Thousands of Sites Still Loading Code From a Stranger
- Fake 'Bug Bounty Hunter' Used AI-Written Malware to Raid npm Developer Secrets
- New BambooToken Malware Hijacks IoT Protocol to Control Windows and Linux Machines
- PhantomRaven: An AI-Written Info Stealer Hidden in npm Packages, Used to Hunt Bug Bounties
- Maximum-Severity GitLab Flaw Threatens Software Supply Chains
- WordPress Adds Automated Security Scans to Catch Malicious Plugin Updates Before They Go Live
- Researchers Chained Two Bugs to Hijack OpenAI Staff Accounts via Help Forum
- Trezor Shipping Partner Breach Exposes 80,000+ Hardware Wallet Customers
- Report: OpenAI Agent Swarm Linked to May Attack on RubyGems Package Repository
- China-Linked Hacking Group Exploited Popular Chinese Typing Tool to Plant Backdoor
- Chainguard Hits 1 Billion Build Manifests: What It Means for Software Supply Chain Security
- Trezor Data Breach Grows Nearly Fivefold to 81,000 Affected Customers
- Coldcard Wallet Hack: Stolen $7.7M in Bitcoin Being Laundered via CoinJoin and THORChain
- Trezor Reveals Further 67,000 Customers Affected by ShipMonk Data Breach
- Shai-Hulud Worm Expands Credential Theft Reach Dramatically
- Fake Software Download Sites Used to Disable Windows Security Defences
- UK Moves to Ban Risky Tech Vendors from Critical Infrastructure
- CrowdStrike Beefs Up Endpoint Protection to Guard Against Supply Chain Attacks
-
Critical Flaw in JFrog Artifactory Under Active Attack—Patch Now
Also covered by Security Week
- Hackers Race to Exploit Critical JFrog Artifactory Bug Just Days After Patch Release
- Ledger Patches Ethereum App Flaw That Could Have Let Attackers Swap Transactions
- US Order Targets Hidden Backdoors in Power Grid Equipment
- Cyber Costs Are Skyrocketing—And Small Businesses Are Being Left Behind
- Fake npm Packages Used to Host Phishing CAPTCHA Scams
- Hackers Are Now Targeting the Tools Behind Your Software, Not Just the Code
- Defense Contractors Feel Ready for CMMC—But Can They Prove It?
- Trusted Tools, New Tricks: This Week's Cyber Threats Exploit What You Already Rely On
- Cl0p Ransomware Gang Exposes 40+ Victims in Major Software Exploit Campaign
- SafePal Data Exposure Hits Nearly 40,000 Customers Due to Order-Tracking Flaw
- GitHub Workflow Flaw in Snowflake Repo Shows Risk of Automated Issue Handling
- Weekly Threat Recap: Old Bugs, Exposed Services and Browser Hijacks Keep Costing Businesses
- SafePal Discloses Data Exposure Linked to Plugin Security Flaw
- Scottish Prosecutor's Office Data Breach Linked to Third-Party Vendor
- Security Scanner Bug, Not LiteLLM, Behind Breach Affecting 2,500 Organisations
- Trezor Warns 14,000 Customers After Data Breach at Shipping Partner ShipMonk
- Uber Freight Investigating Alleged Data Breach Claimed by Hacking Group
- Weekly Threat Recap: AI Risks, a Metabase Zero-Day, and Router Backdoors Highlight Basic Security Gaps
- Weekly Roundup: Low-Quality AI Bug Reports, Port Cyberattacks, and Wall Street Targeted by Hackers
- Hacking Group 'TeamPCP' Has Been Quietly Attacking Servers Since 2020, Researchers Find
- Why Ticking Compliance Boxes Won't Stop Cyberattacks
- 77 Fake Extensions Caught Stealing Developer Data from Open VSX Marketplace
- Nidec Reports Update on Ransomware Attack at Taiwanese Subsidiary
- New York Invests $9 Million to Shore Up Cybersecurity at 153 Water Utilities
- New Global Guidance Aims to Strengthen Software Supply Chain Transparency