#chain


Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

Jun 26, 2026 // 14:08

Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised […]

LastPass confirms data breach in Klue supply chain attack

Jun 23, 2026 // 17:17

LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company’s OAuth tokens in the Klue supply chain attack earlier this […]

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

Jun 22, 2026 // 21:04

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and […]

Microsoft links Mastra AI supply chain attack to North Korean hackers

Jun 20, 2026 // 19:57

Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, […]

Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

Jun 19, 2026 // 21:40

Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple’s A12 and A13 chips. That code […]

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

Jun 15, 2026 // 22:49

A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at […]

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

Jun 12, 2026 // 12:57

Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution. LangGraph […]

GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks

Jun 11, 2026 // 10:17

GitHub has announced what it said are “breaking changes” coming to npm version 12, one of which turns off install scripts by default to combat […]

VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

Jun 8, 2026 // 09:10

Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development environment (IDE) are updated automatically […]

Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

Jun 6, 2026 // 11:48

Microsoft’s GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repositories […]

Previous 1 2 3 4 5 6 … 8 Next