Tag

#supply chain

148 stories taggedsupply chain · page 10 of 10.

Threat Intelligence

Megalodon Campaign Pushed 5,718 Malicious Commits Into GitHub Repos in Six Hours

An automated backdooring operation abused compromised GitHub credentials to silently inject base64-encoded bash payloads into CI/CD workflows across more than 5,500 public repositories on May 18.

2 min read
Vulnerabilities

Unpatched Flaws Now Outpace Stolen Credentials as the Leading Breach Entry Point

Verizon's 2025 DBIR puts vulnerability exploitation at 31% of breach root causes. Median patch time has climbed to 43 days, and only 26% of CISA KEVs were fully remediated — a gap attackers are sprinting through.

4 min read
Threat Intelligence

TrapDoor: The Supply Chain Campaign That Wants Your Whole Dev Environment, Not Just Your Secrets

A cross-registry malware campaign hitting npm, PyPI, and Crates.io is going after CI/CD pipelines, SSH trust chains, and AI coding assistant files — not just credentials on install.

3 min read
Threat Intelligence

The Boring Attacks Are Winning: Why Defenders Keep Losing to Trusted Tools

Leaked tokens, poisoned npm packages, and login replays are doing more damage than zero-days this quarter. Here is how to spot the pattern before it spots you.

3 min read
Threat Intelligence

Megalodon Campaign Plants Malicious Workflows in 5,561 GitHub Repos in Six Hours

Throwaway accounts pushed 5,718 commits forging build-bot identities to exfiltrate CI/CD secrets, researchers said.

2 min read
Threat Intelligence

Laravel-Lang Packages Hijacked to Push a Cross-Platform Credential Stealer

Four popular Laravel-Lang packages were tagged with malicious releases that drop a credential-harvesting framework on Windows, macOS, and Linux.

3 min read
Threat Intelligence

Eight Packagist Projects Hijacked to Pull Linux Payload From GitHub Releases

The injected code lived in package.json, not composer.json, and targeted JavaScript-shipping Composer projects.

2 min read
Threat Intelligence

TrapDoor Campaign Plants Credential Stealers Across npm, PyPI, and Crates.io

A coordinated operation seeded 34+ malicious packages across three registries since May 2026. If you ship code, this one is sitting in your dependency tree right now.

3 min read
Cloud Security

CISA Contractor Spent Six Months Treating GitHub as a Personal Dropbox

A Nightwing employee's public 'Private-CISA' repo leaked AWS GovCloud admin keys, plaintext passwords and the agency's internal build pipeline — with secret-scanning deliberately switched off.

2 min read
Cloud Security

CISA Contractor's Public GitHub Repo Spilled GovCloud Keys for Months; Lawmakers Want Answers

An RSA private key tied to the CISA-IT GitHub organization sat in a public 'Private-CISA' repo since November 2025. The agency is still rotating credentials.

3 min read
Threat Intelligence

The Week the Backlog Came Due: Linux Holes, Defender Zero-Days, and a Poisoned Dev Tool

A messy seven days for defenders, where forgotten servers and trusted tooling did most of the damage.

3 min read
AI Security

Anthropic's Mythos AI Found 23,000 Potential Vulnerabilities Across 1,000 Open-Source Projects — and Counting

The numbers are large. The confirmed critical findings are real. What Anthropic has not yet said publicly is whether any of them were exploited before disclosure.

2 min read
Threat Intelligence

Laravel Lang Composer packages backdoored via GitHub tag rewrite, dropping infostealer on developer machines

Attackers reused legitimate version tags on the laravel-lang GitHub repository to push malicious Composer payloads to downstream installs, harvesting credentials from build environments.

2 min read
© 2026 Threat Vectr