#chain


TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

Aug 7, 2026 // 09:58

A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating […]

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

Jul 30, 2026 // 13:40

The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting […]

GitHub, PyPI add time-based defenses against supply chain attacks

Jul 26, 2026 // 23:37

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit […]

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

Jul 10, 2026 // 17:25

Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege […]

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

Jul 9, 2026 // 19:55

GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to […]

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

Jul 9, 2026 // 18:15

Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because […]

What Changes When Your Software Supply Chain Includes AI Writing Your Code?

Jul 7, 2026 // 14:43

Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, “software supply chain security” meant one question: what’s in […]

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Jul 2, 2026 // 22:26

Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. “Although tactics differ […]

VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer

Jul 2, 2026 // 02:16

Cybersecurity researchers have flagged a new multi-stage malware delivery attack chain that uses social engineering and Blogger pages to deliver an information stealer called PureLogs. […]

VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer

Jul 1, 2026 // 23:04

Cybersecurity researchers have flagged a new multi-stage malware delivery attack chain that uses social engineering and Blogger pages to deliver an information stealer called PureLogs. […]

Previous 1 2 3 4 5 … 8 Next