#supply chain
149 stories taggedsupply chain · page 3 of 10.

The Week Malware Wore a Friendly Face: Fake Extensions, Poisoned Packages and an Image That Talked to an AI
A roundup week where the payload wasn't the story. The disguise was.

Hijacked GitHub Repos Turned Into Attack Machines Hunting cPanel Servers
Researchers found booby-trapped PHP packages using GitHub's own automation to scan the internet for web hosting control panels.

Fake Newtonsoft.Json Package on NuGet Was Built to Rig Live Betting Games
A trojanised copy of a popular coding library targeted Digitain's gambling platform, quietly tampering with live game results.

Ransomware Attacks Rose 25% in a Year. Artificial Intelligence Isn't the Main Driver.
A new report tracked 7,551 victims worldwide between April 2025 and March 2026. The growth came from more criminal groups, weaker targets, and supply-chain shortcuts, not fancy AI tools.

Ernst & Young Client Data Stolen in Third-Party Platform Breach
Names, Social Security numbers, and card details belonging to Ernst & Young clients were taken after criminals broke into a third-party software platform the firm used to manage data.

SleeperGem: Three Booby-Trapped Ruby Packages Slip Onto RubyGems
Researchers say the malicious gems sat quietly on the official Ruby package registry, waiting to pull down further attacker code onto developer laptops.

Seven booby-trapped npm packages hit Vite developers with blockchain-controlled malware
Researchers at Checkmarx say the ViteVenom campaign hides its command server across four different cryptocurrency networks, making it unusually hard to shut down.

Ransomware Attack Halts Fairlife Milk Production Across the US
Coca-Cola told the SEC that hackers broke into its Fairlife dairy subsidiary, forcing the company to stop making protein shakes and ultra-filtered milk at its American plants.

This Week's Cyber Mess: Fake Repos, Chrome Sync Stalking and a Ransomware Crew That Moves in a Day
A roundup of the week's smaller stories that share one uncomfortable theme: attacks that succeed because something looked close enough to trust.

AI Data Centres Are Being Built at Speed. Security Is Not Keeping Up.
A new report finds that the same assumptions baked into traditional data centres are being carried straight into AI facilities, where the stakes are much higher and the blast radius is far wider.

A single fake review can trick an AI agent into buying the wrong product
Researchers describe a new class of attack where planted content on trusted pages steers AI assistants into harmful actions without ever hijacking the task itself.

Brazilian Government Sites Turned Into Malware Traps in PhantomEnigma Campaign
Attackers quietly took over more than 20 official .gov.br domains and used them to push a stealthy backdoor, according to new analysis from ANY.RUN.

China's Military Is Quietly Banning Its Own Cybersecurity Companies
Chinese armed forces are shutting some of the country's biggest cybersecurity firms out of military contracts, and the reason has nothing to do with bad software.

The 'Approval Gap' in Ad Tech: When Marketing Tags Smuggle in Unknown Code
A single approved script on your website can quietly pull in code from vendors your security team has never heard of. Here is why that matters.

Cursor on Windows Runs Rogue git.exe From Any Opened Repo, No Warning
A flaw in the AI code editor lets a booby-trapped repository execute code on a developer's machine the moment the folder is opened.