#supply chain
125 stories taggedsupply chain.

FBI warns foreign hackers raided a US industrial contractor for SCADA blueprints
A March-April 2025 intrusion at an industrial automation firm netted around 800 files on power and transport customers, and the FBI is telling critical infrastructure to rethink how much access it hands to outside integrators.

How a poisoned coding library led to 170 private repos being copied at CrowdSec
A French security firm says a departing employee's laptop was infected through the TanStack npm supply-chain attack in May. The fallout reached its GitHub.

OWASP Updates Its AI Security Danger List, and the Biggest Threats May Surprise You
The security industry's most-watched ranking of AI software risks has been refreshed with real incident data for the first time. Prompt injection stays at the top, but a newer danger tied to AI agents acting on their own is climbing fast.

Trezor's email system hijacked to send fake 'security alert' phishing to customers
Criminals used a breached third-party email provider to send phishing from a real Trezor address, weeks after a separate shipping-partner breach ballooned to 81,000 customers.

The Week's Security Mess: Why Did Any of This Work in the First Place?
From greedy browser extensions to phishing pages built inside trusted services, this week's incidents share one uncomfortable answer.

Researchers say OpenAI agents ran the May 2026 RubyGems attack
A new writeup traces the coordinated poisoning of Ruby's package registry to a swarm of AI agents, not human operators at a keyboard.

WordPress Will Now Scan Every Plugin Update for Malicious Code
The world's biggest website platform is adding automated security checks to plugin updates, after years of criminals sneaking malware into trusted software.

The QR Code Hiding in Plain Text: This Week's Sneakiest Phishing Trick
Attackers built scannable QR codes out of typed characters to slip past image-blocking filters, while a trusted developer tool shipped credential-stealing code.

UK's Food Supply Is Fragile. Hackers Are One of the Reasons Why.
Britain's public spending watchdog says the government hasn't done enough to protect food supplies from climate shocks, disease outbreaks, and cyberattacks. Ordinary shoppers could feel the pinch when the next disruption hits.

JetBrains Says Attackers Broke Into Its Cadence Cloud Through an Unpatched TeamCity Server
Customers of the build service are being told to rotate every credential after criminals exploited a critical flaw in JetBrains' own software.

Trezor Customers Caught in a Second Wave of ShipMonk Data Leak
The crypto hardware wallet maker says 67,000 more U.S. buyers had their names, addresses and phone numbers exposed through its old shipping partner. The wallets themselves are unaffected.

'Ted' Backdoor Found Baked Into HAProxy Builds at Two South Korean Firms
A never-before-seen Linux implant was compiled straight into the load balancers, letting attackers read web traffic and swap pages for chosen visitors.

Booby-trapped Composer packages hijack Vietnamese streaming sites to hit old iPhones
Thirteen fake theme libraries on Packagist quietly loaded ad-fraud scripts and pushed spyware at visitors running unpatched iOS, researchers say.

Cyber attack on Australian book distributor leaves bookshops empty-handed before Christmas
A suspected ransomware attack on Alliance Distribution Services has disrupted book supply across Australia for six weeks, hitting independent bookshops and Hachette authors at the worst possible time.

Nineteen Browser Extensions Caught Emptying Crypto Wallets
Researchers found 18 Chrome add-ons and one Edge add-on that quietly stole wallet keys and drained funds, in a campaign that may have run for months.