Tag

#supply chain

148 stories taggedsupply chain.

Full-frame edge-to-edge overhead photoreal shot of a developer workstation at night: mechanical keyboard, two monitors glowing with abstract code editor windows
Threat Intelligence

Poisoned LiteLLM Packages on PyPI May Have Leaked Secrets From 2,100 Organisations

CloudSEK says a 434,000-file dataset stolen during a 40-minute window in March traces back to two malicious releases of the popular AI gateway library.

3 min read
Full-frame photoreal editorial shot of a laptop screen showing an anonymous online product page with rows of star ratings and review boxes, one review subtly hi
AI Security

The software wrapper around your AI agent is the real security risk

Researchers broke into official AI automation tools from Anthropic, Google, and OpenAI, not by tricking the AI itself, but by exploiting the ordinary code that connects it to the real world.

5 min read
Full-frame edge-to-edge photoreal news-editorial image of a laptop screen showing a generic browser extensions settings page with one entry greyed out and marke
Threat Intelligence

Your GitHub activity logs are a smoke detector you forgot to switch on

Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

4 min read
an abstract image of a digital supply chain with a malicious code hidden within
Threat Intelligence

Banned Chrome Extension Returns With Hidden Affiliate Scam, and Security Researchers Warn the Next Version Could Be Worse

A browser add-on pulled from the Chrome Web Store for stealing AI chat conversations is back, and it is now quietly opening affiliate links on users' computers every time it updates.

4 min read
Full-frame edge-to-edge overhead photoreal shot of a darkened developer workstation at night, dual monitors showing blurred lines of Python source code and a te
Threat Intelligence

Weekly Recap: A Metabase Zero-Day, Poisoned AI Plugins, and Routers Left Wide Open

Old bugs are back, supply chains are getting stranger, and the shortest exploit paths are once again the ones nobody guarded.

4 min read
Photoreal editorial shot of a modern glass office tower at dusk with cold blue interior lighting on empty open-plan floors, a faint reflection of code-like patt
Breaches

LexisNexis Pulls Three Services Offline After Vendor Server Break-In

The data analytics giant disconnected Nexis Diligence, Metabase API and Newsdesk after spotting suspicious activity on a third party's servers, and is rebuilding the systems from scratch.

4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Breaches

Valve tells European Steam customers their delivery details were stolen in CEVA Logistics hack

The gaming giant says names, addresses and phone numbers were taken after attackers spent four days inside its European shipping partner's systems.

4 min read
Full-frame 16:9 photoreal editorial shot of a developer workstation at night, multiple monitors showing dense terminal output and an open code editor with a sus
Threat Intelligence

Fake 'Solidity Pro' VS Code Extensions Caught Emptying Crypto Wallets

Two look-alike extensions posed as tools for Ethereum developers, then quietly installed wallet and password stealers on the machines that trusted them.

3 min read
A dense grid of glowing green and amber data packets flowing through dark fiber-optic tubes, photographed in macro with sharp focus on the structured geometric
Vulnerabilities

Russian hacktivists hijack TrueConf video servers to push booby-trapped installers

Kaspersky says the Head Mare group exploited two unpatched flaws in TrueConf conferencing servers to swap the real client installer for one carrying the PhantomCore backdoor.

4 min read
Photoreal news-editorial image, 16:9 full-frame composition edge to edge
Opinion

Open source grew up in a hurry, and the security bill is coming due

The world runs on free code written by strangers. That model is finally hitting its limits, and everyone using cloud services is exposed.

4 min read
Full-frame edge-to-edge overhead photoreal shot of a developer's dark wooden desk at night, a laptop screen glowing with abstract green code, a small physical h
Threat Intelligence

The Week's Attacks Were Cheap, Ordinary, and Very Effective

Opening a repo, installing a package, or previewing a PDF was enough to hand attackers a foothold this week. None of it was sophisticated. All of it worked.

4 min read
A chaotic scene of digital data swirling around a government building, symbolizing a cyber breach
Cloud Security

One Developer Password Unlocked Everything: Inside a Healthcare Software Provider's Wake-Up Call

A company that thought its segmented cloud setup was secure ran a simulated attack and watched a single stolen developer credential unravel four years of layered defences in minutes.

4 min read
Photoreal news-editorial aerial view of a vast network of illuminated fiber-optic cables converging on a central node that has gone dark, surrounding nodes stil
Threat Intelligence

Twenty Chinese Router Models Ship From The Factory With A Hidden Backdoor

Researchers at VulnCheck say every current Zbtlink firmware image contains an implant that phones home to Chinese servers and hands attackers root access.

4 min read
Photoreal editorial shot of a developer's darkened desk, an open laptop showing rows of green package names in a terminal, one line highlighted in red, faint bl
Threat Intelligence

Malicious npm Packages Hide Attacker Servers Inside Empty Ethereum Transactions

Researchers found two booby-trapped code libraries pulling instructions from fake wallet addresses on the Ethereum blockchain, a twist on the EtherHiding trick now dubbed NullReceiver.

4 min read
Aerial view of a Southeast Asian power plant at night, with a cybersecurity threat theme
Threat Intelligence

Trojanised QuickFox VPN installer plants stealth backdoor on users' PCs

Fortinet researchers say a tampered version of the China-focused VPN app has been serving the FDMTP backdoor since at least August 2025, with tradecraft that overlaps activity tracked as Silver Fox.

3 min read
© 2026 Threat Vectr