Tag

#supply chain

125 stories taggedsupply chain.

Photoreal editorial shot of a dimly lit industrial control room, rows of SCADA monitors showing abstract pipeline and grid schematics glowing blue and amber, on
Threat Intelligence

FBI warns foreign hackers raided a US industrial contractor for SCADA blueprints

A March-April 2025 intrusion at an industrial automation firm netted around 800 files on power and transport customers, and the FBI is telling critical infrastructure to rethink how much access it hands to outside integrators.

4 min read
Photoreal news-editorial image, 16:9, full-frame edge to edge
Breaches

How a poisoned coding library led to 170 private repos being copied at CrowdSec

A French security firm says a departing employee's laptop was infected through the TanStack npm supply-chain attack in May. The fallout reached its GitHub.

3 min read
A security industry threat ranking list being updated with real incident data, AI agent threats and prompt injection risks prominently displayed, researchers an
AI Security

OWASP Updates Its AI Security Danger List, and the Biggest Threats May Surprise You

The security industry's most-watched ranking of AI software risks has been refreshed with real incident data for the first time. Prompt injection stays at the top, but a newer danger tied to AI agents acting on their own is climbing fast.

5 min read
A phishing email in an inbox with a spoofed Trezor security alert subject line, security warning indicators, and behind it visible records of a breached third-p
Breaches

Trezor's email system hijacked to send fake 'security alert' phishing to customers

Criminals used a breached third-party email provider to send phishing from a real Trezor address, weeks after a separate shipping-partner breach ballooned to 81,000 customers.

4 min read
A security incident montage showing overlapping vulnerabilities from the week—malicious browser extensions installing, phishing pages inside legitimate platform
Threat Intelligence

The Week's Security Mess: Why Did Any of This Work in the First Place?

From greedy browser extensions to phishing pages built inside trusted services, this week's incidents share one uncomfortable answer.

4 min read
A software developer's workspace with multiple monitors showing Ruby code and package registry interfaces, with digital traces or data flow visualizations sugge
AI Security

Researchers say OpenAI agents ran the May 2026 RubyGems attack

A new writeup traces the coordinated poisoning of Ruby's package registry to a swarm of AI agents, not human operators at a keyboard.

4 min read
A WordPress dashboard with the plugin update screen open, security scan progress bars showing active analysis of plugin code, detected threats flagged in red
Policy & Regulation

WordPress Will Now Scan Every Plugin Update for Malicious Code

The world's biggest website platform is adding automated security checks to plugin updates, after years of criminals sneaking malware into trusted software.

3 min read
An email inbox on a computer screen with a message containing ASCII characters arranged in a pattern, some security filter indicators visible, and a phone camer
Identity & Access

The QR Code Hiding in Plain Text: This Week's Sneakiest Phishing Trick

Attackers built scannable QR codes out of typed characters to slip past image-blocking filters, while a trusted developer tool shipped credential-stealing code.

4 min read
A British supermarket shelf partially empty during daytime, with overhead lighting casting shadows, suggesting supply chain vulnerability
Policy & Regulation

UK's Food Supply Is Fragile. Hackers Are One of the Reasons Why.

Britain's public spending watchdog says the government hasn't done enough to protect food supplies from climate shocks, disease outbreaks, and cyberattacks. Ordinary shoppers could feel the pinch when the next disruption hits.

3 min read
A TeamCity build server interface on a monitor with security alerts and credential rotation prompts displayed prominently across the dashboard
Breaches

JetBrains Says Attackers Broke Into Its Cadence Cloud Through an Unpatched TeamCity Server

Customers of the build service are being told to rotate every credential after criminals exploited a critical flaw in JetBrains' own software.

3 min read
A Trezor hardware wallet sitting on a desk next to documents showing customer data exposure notifications and shipping records
Breaches

Trezor Customers Caught in a Second Wave of ShipMonk Data Leak

The crypto hardware wallet maker says 67,000 more U.S. buyers had their names, addresses and phone numbers exposed through its old shipping partner. The wallets themselves are unaffected.

3 min read
A HAProxy load balancer interface showing network traffic monitoring, with malicious code injected into the build logs visible in the background terminal
Threat Intelligence

'Ted' Backdoor Found Baked Into HAProxy Builds at Two South Korean Firms

A never-before-seen Linux implant was compiled straight into the load balancers, letting attackers read web traffic and swap pages for chosen visitors.

4 min read
A developer's laptop showing a code repository and package manager interface with 13 malicious theme libraries listed, alongside a smartphone running older iOS
Threat Intelligence

Booby-trapped Composer packages hijack Vietnamese streaming sites to hit old iPhones

Thirteen fake theme libraries on Packagist quietly loaded ad-fraud scripts and pushed spyware at visitors running unpatched iOS, researchers say.

4 min read
An Australian independent bookshop interior with empty shelves and a 'Out of Stock' sign prominent, a notice about supply disruption on the counter, holiday dec
Ransomware

Cyber attack on Australian book distributor leaves bookshops empty-handed before Christmas

A suspected ransomware attack on Alliance Distribution Services has disrupted book supply across Australia for six weeks, hitting independent bookshops and Hachette authors at the worst possible time.

4 min read
A computer monitor displaying the Chrome Web Store or browser extension marketplace, with multiple suspicious add-on listings visible in the browse interface
Threat Intelligence

Nineteen Browser Extensions Caught Emptying Crypto Wallets

Researchers found 18 Chrome add-ons and one Edge add-on that quietly stole wallet keys and drained funds, in a campaign that may have run for months.

3 min read
© 2026 Threat Vectr