#supply


Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise

May 8, 2026 // 14:08

A previously undocumented Linux implant codenamed Quasar Linux RAT (QLNX) is targeting developers’ systems to establish a silent foothold as well as facilitate a broad […]

Android Apps Get Public Verification System to Stop Supply Chain Attacks

May 6, 2026 // 12:14

Google has announced expanded Binary Transparency for Android as a way to safeguard the ecosystem from supply chain attacks. “This new public ledger ensures the […]

DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware

May 6, 2026 // 00:48

A newly identified supply chain attack targeting DAEMON Tools software has compromised its installers to serve a malicious payload, according to findings from Kaspersky. “These […]

PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials

May 1, 2026 // 00:51

In yet another software supply chain attack, threat actors have managed to compromise the popular Python package Lightning to push two malicious versions to conduct […]

PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials

May 1, 2026 // 00:11

In yet another software supply chain attack, threat actors have managed to compromise the popular Python package Lightning to push two malicious versions to conduct […]

Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

Apr 23, 2026 // 16:49

Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign, according to new findings from Socket. “The affected […]

Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

Apr 22, 2026 // 21:00

Cybersecurity researchers have warned of malicious images pushed to the official “checkmarx/kics” Docker Hub repository. In an alert published today, software supply chain security company […]

Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens

Apr 22, 2026 // 20:40

Cybersecurity researchers have flagged a fresh set of packages that have been compromised by bad actors to deliver a self-propagating worm that spreads through stolen […]

Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain

Apr 20, 2026 // 13:44

Cybersecurity researchers have discovered a critical “by design” weakness in the Model Context Protocol’s (MCP) architecture that could pave the way for remote code execution […]

macOS App Security Revoked After OpenAI Supply Chain Hack, Axios Link.

Apr 13, 2026 // 10:18

OpenAI shared details about a GitHub Actions process used for signing their macOS applications. This process downloaded the harmful Axios library on March 31st. They […]