Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to […]
A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a […]
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A […]
TeamPCP, the threat actor behind the recent supply chain attack spree, has been linked to the compromise of the npm and PyPI packages from TanStack, […]
A new malware framework called PCPJack is stealing credentials from exposed cloud infrastructure while actively removing TeamPCP’s access to the systems. Among the targeted services […]
Cybersecurity researchers have flagged a fresh set of packages that have been compromised by bad actors to deliver a self-propagating worm that spreads through stolen […]
Following the Trivy supply chain attack, security experts have detected harmful components spread via Docker Hub, indicating a widespread impact on development environments. The last […]
The individuals responsible for the supply chain attack on the Trivy scanner are believed to be launching additional attacks, compromising numerous npm packages with a […]
On March 5, 2026, Wikipedia and its sister projects were placed in read-only mode for approximately two hours following a site-wide attack by a self-propagating JavaScript worm. The […]
© Bulletproof Servers. All rights reserved.