Supply Chain Security
11 articles
Advertisement
Articles11
A Poisoned JSON Feed Made Hidden Admins on WordPress Sites
No plugin update was published. Attackers reached BdThemes storage, poisoned a feed the plugins pull into the...
CY
11 Aug
The Breach Was at the Vendor. The Notification Came From Everyone Else.
Valve, Framework and a football club all told customers about a breach this week. None of them was broken into...
KE
10 Aug
A Zero-Day in a Dashboard Tool Took Framework's Entire Customer List
Framework and Tally were both breached on 3 August through a zero-day in Metabase, the business-intelligence t...
KE
9 Aug
N-able's Patch Did Not Hold. The Second Hotfix Came Four Days Later.
N-able patched a critical authentication bypass in N-central, attackers found a path the patch did not block,...
CY
8 Aug
Two Registries Made Time a Security Control. Our Own Files Say When That Works.
GitHub gave Dependabot a three-day cooldown on 14 July and PyPI began rejecting new files on releases older th...
KE
8 Aug
The FCC Barred Imported Humanoid Robots on Security Grounds. Beijing Says It Will Retaliate
The restriction covers bipedal and quadruped machines and applies to new device models rather than units alrea...
EV
3 Aug
The Coldcard Entropy Failure Was a Build-Configuration Bug, Not a Cryptography Bug
A macro was defined and set to zero. One guard tested whether it existed rather than what it held, the linker...
CY
2 Aug
Attackers Sweep 1,367 Bitcoin From Coldcard Wallets After Five-Year Firmware Flaw
Three waves of automated sweeps have taken about $89 million in bitcoin from 4,585 addresses since 30 July. Th...
CY
2 Aug
npm v12 Flips Three Install Defaults From Automatic to Opt-In — Prepare Your Pipelines Now
GitHub's npm v12, due July 2026, turns three things npm install does automatically today into choices you have...
KE
19 Jun
Three supply-chain incidents this week: Megalodon, Robinsons, and the Laravel-Lang Composer compromise
Megalodon pushed 5,718 malicious commits into 5,561 GitHub repos in six hours. The Payload ransomware group li...
JE
25 May
Supply Chain Attacks Hit Record 454,600 Malicious Packages in 2025 — And AI Is to Blame
Malicious packages in public software repositories hit 454,600 in 2025, up from 55,000 in 2022. AI-assisted cr...
CY
28 Apr
Advertisement