#supply chain
125 stories taggedsupply chain · page 2 of 9.

ZBT Routers Found With Two Hidden Factory Backdoors Handing Attackers Full Control
Researchers at VulnCheck say firmware shipped by Shenzhen Zhibotong Electronics contains two undocumented implants that let anyone on the internet run commands as root.

Banning One AI Brand Isn't Enough: Your Model's Family Tree Still Matters
Cisco researchers say that where an AI model is built tells you far less than where it came from. Tracing a model's lineage reveals hidden dependencies and inherited behaviours that a country-of-origin label simply cannot.

Trump Signs Emergency Order to Block Foreign-Made Backdoors From US Power Grid
Executive Order 14420 bars untrusted foreign equipment from America's high-voltage electricity network, citing hidden remote-access capabilities that could let hostile governments cut the lights.

Criminals Turn npm Into Free Hosting for Fake Cloudflare Login Traps
Researchers found 24 packages on the npm registry being used not to poison developers, but as free web hosting for phishing pages that pretend to be Cloudflare's human-check screen.

This Week in AI Security: Rogue Packages, PLC Hacks by Chatbot, and Leaky Stripe Keys
A weekly roundup of the AI and infrastructure security stories that actually matter, translated into plain English.

Cyberattack on Hachette Australia Leaves Bookshops Without Stock During Peak Season
A breach of the publisher's computer systems on 18 July has frozen book distribution across Australia and New Zealand, hitting authors, retailers, and readers at the worst possible moment in the retail calendar.

OWASP Publishes First Security Watchlist for AI Agent 'Skills'
A real attack in July exposed more than 300,000 users to stolen credentials through fake AI skills. Now the group behind the web's most-used security checklists has named the top ten risks, and 'malicious skills' sits at number one.

New Android malware slips into cars through the dashboard's own update system
Kaspersky says the DoFun head unit malware turns infected vehicles into ad-fraud engines and proxy relays for cybercrime.

A popular JavaScript sandbox has a hole in it, and the fix is to stop using it
Researchers found a way out of isolated-vm, an open-source tool used to safely run untrusted code. The maintainer says the project is unmaintained and users should migrate.

Malicious RubyGems Packages Impersonate Popular Libraries to Steal Windows Credentials
Researchers flagged seven typosquatted gems on August 15, 2026, part of a wider campaign delivering a Windows information stealer.

A booby-trapped GitHub ticket could have stolen Snowflake's internal Jira keys
Researchers at Wiz found a flaw in a Snowflake code repository that let anyone on the internet run commands inside its automated build system, exposing credentials to the company's private issue tracker.

The Boring Break-Ins: Why This Week's Worst Hacks Were the Simplest
Fresh incidents show attackers rarely need clever tricks. Exposed servers, old bugs and unattended browser sessions did most of the damage this week.

Seven arrested over €30M Commerzbank fraud that abused a service provider flaw
Investigators say the crew drained customer accounts by exploiting a weakness at a third-party firm that connects to the German bank.

A Survey Company May Have Leaked Scottish Government Workers' Personal Details
A contractor hired to run a government training exercise lost staff data from Scotland's public prosecution service. The real worry: dozens of other agencies probably handed over the same information.

A New Free Tool Lets You See Who's Actually Tracking You Online
DecryptAds pulls back the curtain on the ad partners and data brokers hiding inside popular websites and apps, including some based in Russia and China.