Tag

Supply Chain Security

11 articles
Advertisement
Articles11
A WordPress logo rendered over website code — illustrating the plugin ecosystem through which this compromise reached site dashboards. Cybersecurity 7 min A Poisoned JSON Feed Made Hidden Admins on WordPress Sites No plugin update was published. Attackers reached BdThemes storage, poisoned a feed the plugins pull into the... CY Cyber Team 11 Aug Stacked shipping containers beside gantry cranes at a port — illustrating the logistics contractor whose compromise reached several retailers' customers. Cloud & Infra 8 min The Breach Was at the Vendor. The Notification Came From Everyone Else. Valve, Framework and a football club all told customers about a breach this week. None of them was broken into... KE Kenji Tanaka 10 Aug Rows of servers in a darkened data-centre rack, a hand reaching into one unit — illustrating the hosted reporting platform whose compromise reached its customers' databases. Cybersecurity 9 min A Zero-Day in a Dashboard Tool Took Framework's Entire Customer List Framework and Tally were both breached on 3 August through a zero-day in Metabase, the business-intelligence t... KE Kenji Tanaka 9 Aug Rack-mounted servers in a data centre aisle, illustrating the managed estates an MSP console reaches. Cybersecurity 8 min N-able's Patch Did Not Hold. The Second Hotfix Came Four Days Later. N-able patched a critical authentication bypass in N-central, attackers found a path the patch did not block,... CY Cyber Team 8 Aug Hourglass on a desk with the sand part-run, illustrating the waiting periods these two registry rules impose. Developer Tools 9 min Two Registries Made Time a Security Control. Our Own Files Say When That Works. GitHub gave Dependabot a three-day cooldown on 14 July and PyPI began rejecting new files on releases older th... KE Kenji Tanaka 8 Aug Stacked shipping containers at a port under a bright sky Business 5 min The FCC Barred Imported Humanoid Robots on Security Grounds. Beijing Says It Will Retaliate The restriction covers bipedal and quadruped machines and applies to new device models rather than units alrea... EV Eva Chin 3 Aug A small microcontroller board resting on hand-drawn circuit design sketches beside its enclosure Cybersecurity 14 min The Coldcard Entropy Failure Was a Build-Configuration Bug, Not a Cryptography Bug A macro was defined and set to zero. One guard tested whether it existed rather than what it held, the linker... CY Cyber Team 2 Aug A hand holding a bare printed circuit board with its main controller chip visible Cybersecurity 6 min Attackers Sweep 1,367 Bitcoin From Coldcard Wallets After Five-Year Firmware Flaw Three waves of automated sweeps have taken about $89 million in bitcoin from 4,585 addresses since 30 July. Th... CY Cyber Team 2 Aug A close-up of a laptop on a table, displaying a book on test-driven software with Python, set in a comfortable environment. Developer Tools 5 min npm v12 Flips Three Install Defaults From Automatic to Opt-In — Prepare Your Pipelines Now GitHub's npm v12, due July 2026, turns three things npm install does automatically today into choices you have... KE Kenji Tanaka 19 Jun Close-up of a computer screen displaying HTML, CSS, and JavaScript code (Photo: Саша Алалыкин / Pexels) Cybersecurity 6 min Three supply-chain incidents this week: Megalodon, Robinsons, and the Laravel-Lang Composer compromise Megalodon pushed 5,718 malicious commits into 5,561 GitHub repos in six hours. The Payload ransomware group li... JE Jeffrey Tan 25 May A laptop and yellow-lit keyboard on a cluttered desk with cables Cybersecurity 5 min Supply Chain Attacks Hit Record 454,600 Malicious Packages in 2025 — And AI Is to Blame Malicious packages in public software repositories hit 454,600 in 2025, up from 55,000 in 2022. AI-assisted cr... CY Cyber Team 28 Apr
Advertisement