Threats Tagged 'supply-chain'
View all threats tagged with 'supply-chain'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'supply-chain'
Click on any threat for detailed analysis and mitigation recommendations
This document analyzes multiple cybersecurity incidents involving various threat actors and malicious campaigns. The analysis covers sophisticated attack methodologies including exploitation of vulnerabilities, deployment of specialized malware tools, and targeting of critical infrastructure across multiple sectors. The campaigns demonstrate advanced persistent threat capabilities with focus on data exfiltration, system compromise, and lateral movement within targeted networks. Key observations include the use of social engineering tactics, exploitation of remote access vulnerabilities, and deployment of custom malware frameworks. The threat landscape encompasses government, technology, financial, and defense sectors with significant emphasis on supply chain attacks and credential harvesting operations. Join the discussion | AlienVault OTX General | 09/22/2026, 07:27:17 UTC Added: 09/22/2026, 08:02:57 UTC |
French cybersecurity firm CrowdSec confirmed that approximately 300 of its GitHub repositories, including about 170 private ones, were compromised in a supply chain attack linked to the May 2026 TanStack incident. Source code for CrowdSec's SaaS console, AWS Cloud routines, connectors, and automations was stolen. No customer credentials or data were leaked, and the stolen code cannot be used out of context to cause harm. CrowdSec rotated all potentially affected tokens and credentials immediately after discovery and continues to monitor for abnormal activity. Join the discussion | SecurityWeek | 09/21/2026, 10:55:46 UTC Added: 09/21/2026, 11:01:39 UTC |
A malware campaign involving the npm package 'indexed-btree' demonstrates how attackers evade traditional supply chain defenses by embedding malicious code in the package's runtime behavior instead of installation scripts. This technique allows the malware to bypass install-time security checks and execute malicious actions during normal package usage. Join the discussion | Bleeping Computer | 09/20/2026, 14:11:21 UTC Added: 09/20/2026, 14:16:38 UTC |
Brevo, a customer engagement platform, suffered a supply chain attack where attackers exploited a vulnerability in SAML SSO to gain access to accounts and later used a compromised Cloudflare API key to deploy malicious scripts. These scripts were injected into Brevo's websites and JavaScript files embedded by over 100,000 customer websites. The malicious code showed a fake Cloudflare verification page to visitors, attempting to trick them into running commands on their machines (ClickFix social engineering). The attack lasted about five and a half hours before Brevo revoked the compromised credentials and removed the malicious worker. The incident highlights risks from compromised API keys and supply chain vulnerabilities. Join the discussion | SecurityWeek | 09/18/2026, 09:46:57 UTC Added: 09/18/2026, 10:01:39 UTC |
Brevo experienced a supply-chain attack where attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into Brevo's websites and JavaScript files embedded on customer sites. This injection was used to distribute malware to visitors of affected sites. Join the discussion | Bleeping Computer | 09/17/2026, 17:11:34 UTC Added: 09/17/2026, 17:46:37 UTC |
Ransomware attacks targeting the manufacturing sector surged by 40% in early 2026, exploiting supply chain disruptions caused by operational shutdowns. Mid-sized manufacturers, which serve as suppliers to larger enterprises, are primary targets due to their critical role in production lines. These attacks cause immediate operational impacts, including production halts and disrupted delivery commitments, which strengthen attackers' negotiating positions. The number of ransomware groups is increasing, with new groups like The Gentlemen responsible for a significant portion of attacks. Europe has seen an 85% increase in attacks, particularly in Germany, Italy, the UK, and France. The distribution sector also faces ransomware threats, though at lower volumes. Supply chain victims often cannot patch vulnerabilities themselves, complicating remediation efforts. Legislative efforts, such as the UK’s Cyber Security and Resilience Bill, aim to mitigate supply chain risks by enforcing security standards on providers. Overall, ransomware attacks on manufacturing and distribution sectors are rising, with growing attacker sophistication and expanding attack surfaces. Join the discussion | SecurityWeek | 09/17/2026, 12:29:53 UTC Added: 09/17/2026, 12:31:40 UTC |
0 CVE-2026-91843 is a critical stack-based buffer overflow vulnerability in Checkpoint Quantum Security Management. It occurs during the unauthenticated login process and may allow remote attackers to execute arbitrary code with root privileges. The vulnerability has a CVSS score of 9.8, indicating a high severity with full confidentiality, integrity, and availability impact. No affected versions or patch information are provided in the available data. Join the discussion | CVE Database V5 | 09/16/2026, 13:03:40 UTC Added: 09/16/2026, 13:32:17 UTC |
Oracle released its September 2026 Critical Security Patch Update (CSPU) addressing 672 unique CVEs with 673 patches across 17 product families. The update includes 104 critical severity patches and 503 high severity patches. Oracle E-Business Suite received the highest number of patches (159), followed by Oracle Fusion Middleware (153). Several vulnerabilities can be exploited remotely without authentication. Patches are available in the official advisory. Join the discussion | Tenable Research | 09/15/2026, 21:00:28 UTC Added: 09/15/2026, 21:15:42 UTC |
0 KATARU is an IoT malware variant discovered in August 2026 through Telnet credential brute-forcing against a honeypot from Vietnam. While maintaining traditional Mirai-style botnet capabilities, it distinguishes itself through an extensive feature set including multiple Linux local privilege escalation exploits, comprehensive persistence mechanisms across Linux and embedded platforms, encrypted C2 communications using X25519 and ChaCha20-Poly1305, anti-analysis techniques, and decoy traffic generation. Implementation artifacts strongly suggest AI-assisted development, evidenced by architecture-mismatched x86 shellcode in ARM binaries, RFC test vectors as configuration values, and untested cross-platform persistence logic. The malware attempts various privilege escalation paths through system misconfigurations and public exploits, establishes persistence across numerous startup mechanisms, and supports multiple DDoS attack vectors alongside SSH brute-forcing capabilities. Join the discussion | AlienVault OTX General | 09/11/2026, 17:55:38 UTC Added: 05/04/2026, 14:36:50 UTC |
An attacker operates a semi-autonomous coding agent that identifies poorly secured large language model (LLM) resale gateways, acquires API access through common web vulnerabilities and account farming, validates the inference capacity, and aggregates it behind a single unified gateway. This creates a partially self-expanding supply chain of stolen inference capacity, where the agent continuously harvests and consolidates LLM access to support further operations. The attacker’s infrastructure includes hundreds of compromised endpoints mapped to standard model names, served through a single proxy with failover and load balancing. The operation was uncovered through an AI honeypot that captured the agent’s operational playbook and infrastructure details. Join the discussion | SANS ISC Handlers Diary | 09/11/2026, 14:40:32 UTC Added: 09/11/2026, 14:47:15 UTC |
Showing 1 to 10 of 57 results