Tag Archives: supply chain
Nx Console Attack: GitHub Source Code Breached via Malicious VS Code Extension
A major supply-chain Nx Console attack exploited a compromised VS Code extension to breach GitHub internal repositories, exposing sensitive developer credentials. Continue reading
Mini Shai-Hulud Worm: TeamPCP Targets GitHub and npm
The Mini Shai-Hulud worm has launched a massive software supply chain campaign, targeting GitHub and npm registries to harvest credentials and exfiltrate corporate data. Continue reading
Trellix Source Code Breach Confirmed After Repository Compromise
Cybersecurity firm Trellix has officially confirmed a Trellix source code breach after identifying unauthorized access to its internal development repositories in May 2026. Continue reading
Amtrak Data Breach: Millions of Customer Records Exposed in 2026 Incident
The recent Amtrak data breach has compromised up to 9.4 million records, exposing sensitive customer information through a vulnerability in a third-party CRM integration. Continue reading
AI Infrastructure Security: CVE-2026-33626 and Vercel Breach
The rapid weaponization of CVE-2026-33626 and the Vercel data breach highlight critical gaps in AI infrastructure security as attackers leverage LLMs to accelerate exploit development. Continue reading
Bitwarden CLI Breach: Critical Supply Chain Attack Targets Developers
A critical Bitwarden CLI breach has been identified in version 2026.4.0, involving a malicious GitHub Action that exfiltrates sensitive developer credentials and cloud secrets. Continue reading
Vercel Supply Chain Breach: AI-Augmented Attack via Context.ai
The recent Vercel supply chain breach highlights the growing risk of AI-augmented cyberattacks, as attackers exploited Context.ai to compromise internal systems and environment variables. Continue reading
Void Dokkaebi Supply Chain Worm Targets Developers via Fake Interviews
Security researchers have uncovered a Void Dokkaebi supply chain worm that spreads through malicious VS Code tasks and fraudulent job recruitment interviews targeting software developers. Continue reading
Cargo Theft Hackers Use ClickFix Tactics to Target Logistics Firms
New security reports reveal that cargo theft hackers are deploying ClickFix social engineering and Remote Access Trojans to compromise freight load boards and redirect high-value shipments. Continue reading