#supply


How Financial Services Companies Can Modernize Their Software Supply Chain

Oct 1, 2026 // 14:50

Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. […]

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

Sep 7, 2026 // 17:42

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It […]

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

Aug 27, 2026 // 15:00

The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the […]

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

Aug 20, 2026 // 23:44

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a […]

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Aug 11, 2026 // 10:16

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform’s plugins team to temporarily […]

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

Aug 7, 2026 // 09:58

A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating […]

GitHub, PyPI add time-based defenses against supply chain attacks

Jul 26, 2026 // 23:37

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit […]

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

Jul 9, 2026 // 19:55

GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to […]

What Changes When Your Software Supply Chain Includes AI Writing Your Code?

Jul 7, 2026 // 14:43

Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, “software supply chain security” meant one question: what’s in […]

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Jul 2, 2026 // 22:26

Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. “Although tactics differ […]

1 2 3 … 5 Next