Threats Tagged 'supply-chain'
View all threats tagged with 'supply-chain'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'supply-chain'
Click on any threat for detailed analysis and mitigation recommendations
In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street 0 Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing. The post In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street appeared first on SecurityWeek . Join the discussion | SecurityWeek | 08/07/2026, 14:26:42 UTC Added: 08/07/2026, 14:41:12 UTC |
Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway 0 (Video) In this podcast, we share insights from Edna Conway, a recognized leader in cybersecurity and supply chain resilience with over 40 years of experience in the field. The post Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway appeared first on SecurityWeek . Join the discussion | SecurityWeek | 08/06/2026, 12:00:00 UTC Added: 08/07/2026, 05:40:25 UTC |
ChainDrop: Inside a Self-Propagating npm Worm 0 Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42 . Join the discussion | Palo Alto Unit 42 | 08/06/2026, 22:26:39 UTC Added: 08/06/2026, 22:40:03 UTC |
ChainDrop supply chain compromise: Anatomy of a self-propagating worm 0 In this article Attack chain overview Mitigation and protection guidance Indicators of compromise (IOC) Microsoft Defender XDR detections Advanced hunting queries Learn more Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including packages associated with major enterprise software ecosystems such as keyv, flat-cache, cache-manager, and others. The malicious releases contain a Mini Shai-Hulud variant, a self-propagating credential-stealing worm delivered through a large, heavily obfuscated Bun-based JavaScript payload. The malware typically executes automatically through an npm preinstall lifecycle hook before package installation completes. Once executed, the malware searches developer workstations and continuous integration and continuous delivery (CI/CD) environments for npm, GitHub, cloud, and infrastructure credentials. It uses recovered identities to authenticate to npm, GitHub, Amazon Web Services (AWS), Kubernetes, and HashiCorp Vault, enabling it to enumerate packages, repositories, workflow secrets, cloud parameters, and secret-store values. Collected data is encrypted and transmitted through an attacker-controlled HTTPS endpoint, with GitHub repositories serving as a fallback exfiltration channel. The payload’s most significant capability is automated propagation. After obtaining an npm publishing token, it enumerates packages available to the compromised identity, downloads their latest tarballs, inserts the malware and setup loader, adds a preinstall hook, increments the patch version, and republishes the modified packages. The malware can also use stolen GitHub credentials to inject Claude and Visual Studio Code configuration files into repositories, establishing persistence and creating an additional developer-to-developer infection path. In this blog, we’re sharing our analysis of this supply chain attack, along with protection, detection, amd hunting guidance. Organizations that installed an affected package with lifecycle scripts enabled should treat the associated developer workstation or build runner as potentially compromised. Investigations should prioritize credentials accessible to the affected identity, unauthorized npm releases, unexpected repository or workflow modifications, suspicious cloud and secret-store access, and artifacts produced by affected build systems. Organizations should revoke and rotate exposed credentials from a known-clean environment and rebuild affected systems and downstream artifacts from trusted sources. Attack chain overview The campaign appeared as a rapid sequence of unauthorized patch releases across more than 400 npm packages maintained by otherwise unrelated publishers. Many malicious versions had no corresponding source-code commit, pull request, tag, or legitimate release, indicating that the attackers modified and published package tarballs directly rather than compromising each public source repository. Affected releases typically added a preinstall lifecycle script that launched a malicious file, setup.mjs, contained within the package, which launched the large, obfuscated Bun JavaScript bundle included in the package. Because npm runs preinstall scripts before installation completes, the payload could execute on developer workstations and build runners before application tests or conventional security checks began. After execution, the malware performs the following actions: Determines whether it is running on a developer workstation or in a CI/CD environment. On workstations, it detaches itself to continue after installation; on CI/CD systems, it remains in the active job to access workflow secrets, runner credentials, and OpenID Connect (OIDC) publishing permissions. Both paths could support further package or repository propagation when suitable credentials are found. Collects credentials from local files, environment variables, command-line tools, and GitHub A… Join the discussion | Microsoft Security Blog | 08/04/2026, 23:46:41 UTC Added: 08/05/2026, 18:39:32 UTC |
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th) 0 When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv/cacheable compromise that has been unfolding since yesterday, it is the one thing you should not do first — because revoking the stolen token is exactly what arms the payload. Join the discussion | SANS ISC Handlers Diary | 08/05/2026, 17:56:15 UTC Added: 08/05/2026, 17:56:13 UTC |
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack 0 The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek . Join the discussion | SecurityWeek | 08/05/2026, 08:56:58 UTC Added: 08/05/2026, 09:11:12 UTC |
Massive ChainDrop npm supply-chain attack infects hundreds of packages 0 Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. [...] Join the discussion | Bleeping Computer | 08/04/2026, 15:24:35 UTC Added: 08/04/2026, 16:27:38 UTC |
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software 0 Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software appeared first on Unit 42 . Join the discussion | Palo Alto Unit 42 | 08/04/2026, 13:00:11 UTC Added: 08/04/2026, 13:55:51 UTC |
Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security 0 Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance. Key takeaways: Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active Querying for isolated, hard-to-reach process-control systems, enables operators to establish a required security baseline. Predictive Vulnerability Priority Rating (VPR) scoring helps you prioritize and focus limited resources on the critical flaws that actually threaten physical safety and uptime. Advanced multi-detection engines and seamless IT workflow integrations accelerate mean-time-to-respond (MTTR) to help both security teams and operators align with a strict 72-hour reporting requirement. With the enactment of Canada’s Critical Cyber Systems Protection Act (CCSPA), commonly known as Bill C-8, the Canadian federal government is laying down a clear framework to protect the cyber-physical systems that are vital to national critical infrastructure security. For designated operators in telecommunications, energy, transportation, and banking, the mandate is clear: Establish formalized cybersecurity programs, mitigate supply chain risks, and — most critically — report cyber incidents to authorities within 72 hours. Failure to comply carries heavy consequences, including penalties that can reach up to $15 million Canadian dollars (CAD). But beyond the threat of fines, Bill C-8 highlights a fundamental operational challenge that many industrial organizations are still struggling to solve: How can you detect, investigate, and report a breach in 72 hours when you lack unified visibility across your converged IT and OT environments? Requirements for meeting Bill C-8's 72-hour incident reporting mandate In modern industrial operations and critical infrastructure, the line between IT and OT continues to blur. The introduction of connectivity (e.g., IoT-connected cameras and building management systems) has optimized processes and service delivery, but it has also introduced new cyber exposures. Today, threat actors do not honor traditional network silos; they frequently compromise a web-facing IT asset or IoT device and move laterally into the operational technology (OT) environment to disrupt physical processes. Meeting a 72-hour incident reporting window is nearly impossible if your security team is relying on fragmented point solutions. Solutions that focus exclusively on passive OT network monitoring often leave massive blind spots — especially considering that IT and IoT devices can constitute up to 50% of an industrial environment. When an incident occurs, teams waste precious hours manually correlating alerts across disconnected tools rather than actively investigating the root cause. To comply with CCSPA and protect uptime, critical national infrastructure (CNI) operators must bridge the IT/OT security divide. Establish your CCSPA cybersecurity baseline The CCSPA requires operators to implement formalized cybersecurity programs. The foundation of any mature security program is a comprehensive asset inventory — you cannot secure what you cannot see. The Tenable One Exposure Management Platform helps organizations eliminate security blind spots by building a complete, unified inventory of all OT, IoT, and IT assets. Tenable goes beyond passive-only network monitoring with our proprietary Safe Active Query technology. This hybrid approach safely communicates with industrial devices in their native protocols to uncover significantly more assets than passive monitoring alone — including dormant process control systems, shadow IT, and unmanaged IoT — without disrupting process integrity or impacting equipment uptime. Prioritize what matter… Join the discussion | Tenable Research | 07/30/2026, 16:05:00 UTC Added: 07/30/2026, 16:20:43 UTC |
CVE-2026-13723: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Develar app-builderCVE-2026-13723 0 A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization Collision combined with symlink following behavior. APFS treats certain Unicode equivalent filenames as identical (e.g., ß ↔ ss), while app builder performs no canonical normalization before validating or writing paths. As a result, a crafted ZIP archive containing: • a symlink entry named ss pointing to a target file, and • a regular file named ß containing attacker controlled data, will cause the second write to follow the symlink and overwrite the target file. Join the discussion | CVE Database V5 | 07/29/2026, 17:25:22 UTC Added: 07/29/2026, 17:37:52 UTC |
Showing 1 to 10 of 17 results