Tag

#supply chain

125 stories taggedsupply chain · page 2 of 9.

Close-up of a circuit board with glowing red indicator lights and exposed firmware pathways, highlighting vulnerability points where unauthorized code could ent
Vulnerabilities

ZBT Routers Found With Two Hidden Factory Backdoors Handing Attackers Full Control

Researchers at VulnCheck say firmware shipped by Shenzhen Zhibotong Electronics contains two undocumented implants that let anyone on the internet run commands as root.

3 min read
A genealogical tree diagram made of interconnected glowing nodes and branching pathways, representing the lineage and dependencies of AI model origins traced ac
AI Security

Banning One AI Brand Isn't Enough: Your Model's Family Tree Still Matters

Cisco researchers say that where an AI model is built tells you far less than where it came from. Tracing a model's lineage reveals hidden dependencies and inherited behaviours that a country-of-origin label simply cannot.

3 min read
A high-voltage electrical transmission tower and power grid infrastructure photographed against a dramatic sky, with digital security barriers and blocked forei
Policy & Regulation

Trump Signs Emergency Order to Block Foreign-Made Backdoors From US Power Grid

Executive Order 14420 bars untrusted foreign equipment from America's high-voltage electricity network, citing hidden remote-access capabilities that could let hostile governments cut the lights.

4 min read
A developer's workspace with an npm package manager interface open on the monitor, showing package listings and download counts, with a phishing login page prev
Threat Intelligence

Criminals Turn npm Into Free Hosting for Fake Cloudflare Login Traps

Researchers found 24 packages on the npm registry being used not to poison developers, but as free web hosting for phishing pages that pretend to be Cloudflare's human-check screen.

3 min read
Overhead view of scattered security briefing documents, threat intelligence printouts, and a laptop displaying code or threat data, with coffee cups and notatio
AI Security

This Week in AI Security: Rogue Packages, PLC Hacks by Chatbot, and Leaky Stripe Keys

A weekly roundup of the AI and infrastructure security stories that actually matter, translated into plain English.

4 min read
An empty bookshop warehouse with vacant shelves and logistics equipment at a standstill, boxes piled haphazardly on the floor, conveying disruption during peak
Breaches

Cyberattack on Hachette Australia Leaves Bookshops Without Stock During Peak Season

A breach of the publisher's computer systems on 18 July has frozen book distribution across Australia and New Zealand, hitting authors, retailers, and readers at the worst possible moment in the retail calendar.

4 min read
A security professional reviewing documentation and checklists on a desk, with a laptop displaying OWASP guidelines and AI security frameworks on the screen
AI Security

OWASP Publishes First Security Watchlist for AI Agent 'Skills'

A real attack in July exposed more than 300,000 users to stolen credentials through fake AI skills. Now the group behind the web's most-used security checklists has named the top ten risks, and 'malicious skills' sits at number one.

4 min read
A car dashboard infotainment system screen showing an update notification and suspicious network activity, with the vehicle's interior visible around it
Threat Intelligence

New Android malware slips into cars through the dashboard's own update system

Kaspersky says the DoFun head unit malware turns infected vehicles into ad-fraud engines and proxy relays for cybercrime.

4 min read
A code editor showing JavaScript sandbox security functions with breach points highlighted, surrounded by documentation windows displaying vulnerability details
Vulnerabilities

A popular JavaScript sandbox has a hole in it, and the fix is to stop using it

Researchers found a way out of isolated-vm, an open-source tool used to safely run untrusted code. The maintainer says the project is unmaintained and users should migrate.

3 min read
A software repository package listing showing nearly identical library names with subtle misspellings, with one package highlighted as malicious and credential-
Threat Intelligence

Malicious RubyGems Packages Impersonate Popular Libraries to Steal Windows Credentials

Researchers flagged seven typosquatted gems on August 15, 2026, part of a wider campaign delivering a Windows information stealer.

3 min read
A GitHub repository page open on a laptop screen with a seemingly innocent ticket thread, while a developer terminal window shows automated build system command
Vulnerabilities

A booby-trapped GitHub ticket could have stolen Snowflake's internal Jira keys

Researchers at Wiz found a flaw in a Snowflake code repository that let anyone on the internet run commands inside its automated build system, exposing credentials to the company's private issue tracker.

4 min read
A security incident response room with investigators reviewing screens showing exposed database servers, unpatched systems, and abandoned user sessions on publi
Threat Intelligence

The Boring Break-Ins: Why This Week's Worst Hacks Were the Simplest

Fresh incidents show attackers rarely need clever tricks. Exposed servers, old bugs and unattended browser sessions did most of the damage this week.

4 min read
Bank transaction records displayed on multiple screens in an investigation room, with highlighted suspicious transfer patterns and wire traces connecting to dif
Threat Intelligence

Seven arrested over €30M Commerzbank fraud that abused a service provider flaw

Investigators say the crew drained customer accounts by exploiting a weakness at a third-party firm that connects to the German bank.

3 min read
Government office building in Edinburgh with survey equipment cases and hard drives stacked near an unsecured loading area, clipboard with employee rosters visi
Breaches

A Survey Company May Have Leaked Scottish Government Workers' Personal Details

A contractor hired to run a government training exercise lost staff data from Scotland's public prosecution service. The real worry: dozens of other agencies probably handed over the same information.

4 min read
Computer screen displaying a web browser with DecryptAds analysis tool overlay revealing hidden ad networks and data brokers operating in the background of popu
Threat Intelligence

A New Free Tool Lets You See Who's Actually Tracking You Online

DecryptAds pulls back the curtain on the ad partners and data brokers hiding inside popular websites and apps, including some based in Russia and China.

4 min read
© 2026 Threat Vectr