#supply chain
148 stories taggedsupply chain.

Poisoned LiteLLM Packages on PyPI May Have Leaked Secrets From 2,100 Organisations
CloudSEK says a 434,000-file dataset stolen during a 40-minute window in March traces back to two malicious releases of the popular AI gateway library.

The software wrapper around your AI agent is the real security risk
Researchers broke into official AI automation tools from Anthropic, Google, and OpenAI, not by tricking the AI itself, but by exploiting the ordinary code that connects it to the real world.

Your GitHub activity logs are a smoke detector you forgot to switch on
Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

Banned Chrome Extension Returns With Hidden Affiliate Scam, and Security Researchers Warn the Next Version Could Be Worse
A browser add-on pulled from the Chrome Web Store for stealing AI chat conversations is back, and it is now quietly opening affiliate links on users' computers every time it updates.

Weekly Recap: A Metabase Zero-Day, Poisoned AI Plugins, and Routers Left Wide Open
Old bugs are back, supply chains are getting stranger, and the shortest exploit paths are once again the ones nobody guarded.

LexisNexis Pulls Three Services Offline After Vendor Server Break-In
The data analytics giant disconnected Nexis Diligence, Metabase API and Newsdesk after spotting suspicious activity on a third party's servers, and is rebuilding the systems from scratch.

Valve tells European Steam customers their delivery details were stolen in CEVA Logistics hack
The gaming giant says names, addresses and phone numbers were taken after attackers spent four days inside its European shipping partner's systems.

Fake 'Solidity Pro' VS Code Extensions Caught Emptying Crypto Wallets
Two look-alike extensions posed as tools for Ethereum developers, then quietly installed wallet and password stealers on the machines that trusted them.

Russian hacktivists hijack TrueConf video servers to push booby-trapped installers
Kaspersky says the Head Mare group exploited two unpatched flaws in TrueConf conferencing servers to swap the real client installer for one carrying the PhantomCore backdoor.

Open source grew up in a hurry, and the security bill is coming due
The world runs on free code written by strangers. That model is finally hitting its limits, and everyone using cloud services is exposed.

The Week's Attacks Were Cheap, Ordinary, and Very Effective
Opening a repo, installing a package, or previewing a PDF was enough to hand attackers a foothold this week. None of it was sophisticated. All of it worked.

One Developer Password Unlocked Everything: Inside a Healthcare Software Provider's Wake-Up Call
A company that thought its segmented cloud setup was secure ran a simulated attack and watched a single stolen developer credential unravel four years of layered defences in minutes.

Twenty Chinese Router Models Ship From The Factory With A Hidden Backdoor
Researchers at VulnCheck say every current Zbtlink firmware image contains an implant that phones home to Chinese servers and hands attackers root access.

Malicious npm Packages Hide Attacker Servers Inside Empty Ethereum Transactions
Researchers found two booby-trapped code libraries pulling instructions from fake wallet addresses on the Ethereum blockchain, a twist on the EtherHiding trick now dubbed NullReceiver.

Trojanised QuickFox VPN installer plants stealth backdoor on users' PCs
Fortinet researchers say a tampered version of the China-focused VPN app has been serving the FDMTP backdoor since at least August 2025, with tradecraft that overlaps activity tracked as Silver Fox.