Tag Archives: Supply chain attack
GitHub Code Breach: TeamPCP and the Shai-Hulud Worm Explained
Discover how the sophisticated Shai-Hulud worm enabled the TeamPCP group to execute a massive GitHub code breach, compromising internal repositories in mere minutes. Continue reading
TanStack Supply Chain Attack Impacts OpenAI and Mistral AI
OpenAI and Mistral AI have disclosed a major security breach following a sophisticated TanStack supply chain attack dubbed Mini Shai-Hulud, which bypassed SLSA provenance standards. Continue reading
JDownloader Supply Chain Compromise: Python-Based RAT Distributed
A major JDownloader supply chain compromise has resulted in the distribution of a Python-based RAT through malicious installer links on the official website. Continue reading
PyTorch Lightning Attack: Supply Chain Breach Steals Developer Credentials
A significant PyTorch Lightning attack has targeted the PyPI ecosystem, deploying malicious versions of the popular machine learning library to steal developer credentials and cloud access tokens. Continue reading
Vimeo Security Breach: Customer Data Exposed via Anodot Vendor
Vimeo confirms a Vimeo security breach involving user metadata and email exposure following a cyberattack on third-party analytics vendor Anodot. Continue reading
Void Dokkaebi campaign: North Korea Targets Developers on GitHub
Researchers have identified the Void Dokkaebi campaign, a self-spreading hacker operation targeting developers through malicious GitHub repositories and fake coding exams. Continue reading
GlassWorm Sleeper Extensions: Malicious Payloads Activated on OpenVSX
Security researchers have identified 73 GlassWorm sleeper extensions on the OpenVSX marketplace that have recently activated malicious payloads to exfiltrate sensitive developer data. Continue reading
Checkmarx Data Leak: API Keys and Credentials Exposed on Dark Web
A confirmed Checkmarx data leak has surfaced on the dark web, exposing sensitive API keys and credentials stolen during a sophisticated supply chain attack. Continue reading
Bitwarden Supply Chain Attack: Trojanized CLI Package Exposed
Security researchers have detailed a critical Bitwarden supply chain attack involving a malicious NPM package designed to exfiltrate developer cloud credentials and SSH material. Continue reading