Tag

#supply chain

149 stories taggedsupply chain · page 3 of 10.

A developer workstation surrounded by digital threats, symbolizing malware infiltration
Threat Intelligence

The Week Malware Wore a Friendly Face: Fake Extensions, Poisoned Packages and an Image That Talked to an AI

A roundup week where the payload wasn't the story. The disguise was.

4 min read
Dim editorial photograph of a developer workstation at night, screen showing a code editor with a redacted extension manifest, faint overlay of blockchain trans
Threat Intelligence

Hijacked GitHub Repos Turned Into Attack Machines Hunting cPanel Servers

Researchers found booby-trapped PHP packages using GitHub's own automation to scan the internet for web hosting control panels.

4 min read
Full frame photoreal editorial image of a dimly lit developer workstation at night, screen showing an abstract package manager interface with one line highlight
Threat Intelligence

Fake Newtonsoft.Json Package on NuGet Was Built to Rig Live Betting Games

A trojanised copy of a popular coding library targeted Digitain's gambling platform, quietly tampering with live game results.

3 min read
Full-frame 16:9 photoreal editorial image of a dimly lit enterprise data center aisle with cool blue server rack lighting, faint translucent network traffic lin
Ransomware

Ransomware Attacks Rose 25% in a Year. Artificial Intelligence Isn't the Main Driver.

A new report tracked 7,551 victims worldwide between April 2025 and March 2026. The growth came from more criminal groups, weaker targets, and supply-chain shortcuts, not fancy AI tools.

3 min read
Photoreal news-editorial 16:9 image of a large Japanese urban data centre at dusk, exterior shot, rows of cooling units and server ventilation grilles lit by am
Breaches

Ernst & Young Client Data Stolen in Third-Party Platform Breach

Names, Social Security numbers, and card details belonging to Ernst & Young clients were taken after criminals broke into a third-party software platform the firm used to manage data.

3 min read
Full-frame overhead photograph of a developer workstation at night, glowing terminal window on a matte black laptop screen showing generic package installation
Threat Intelligence

SleeperGem: Three Booby-Trapped Ruby Packages Slip Onto RubyGems

Researchers say the malicious gems sat quietly on the official Ruby package registry, waiting to pull down further attacker code onto developer laptops.

3 min read
Full-frame photoreal news-editorial image of a dimly lit developer workstation at night, glowing monitor showing rows of package manager install output in green
Threat Intelligence

Seven booby-trapped npm packages hit Vite developers with blockchain-controlled malware

Researchers at Checkmarx say the ViteVenom campaign hides its command server across four different cryptocurrency networks, making it unusually hard to shut down.

3 min read
Full-frame photoreal editorial shot of an empty stainless-steel dairy bottling line at a large modern factory, conveyor belts still, overhead fluorescent lights
Ransomware

Ransomware Attack Halts Fairlife Milk Production Across the US

Coca-Cola told the SEC that hackers broke into its Fairlife dairy subsidiary, forcing the company to stop making protein shakes and ultra-filtered milk at its American plants.

3 min read
Full-frame 16:9 photoreal news-editorial image of a dimly lit desk with two nearly identical software installer windows glowing on a monitor, one subtly misspel
Threat Intelligence

This Week's Cyber Mess: Fake Repos, Chrome Sync Stalking and a Ransomware Crew That Moves in a Day

A roundup of the week's smaller stories that share one uncomfortable theme: attacks that succeed because something looked close enough to trust.

4 min read
Photoreal news-editorial overhead shot of a developer workstation at dusk, glowing IDE on a dark monitor with abstract plugin tiles floating above the keyboard,
AI Security

AI Data Centres Are Being Built at Speed. Security Is Not Keeping Up.

A new report finds that the same assumptions baked into traditional data centres are being carried straight into AI facilities, where the stakes are much higher and the blast radius is far wider.

3 min read
Full-frame photoreal editorial shot of a laptop screen showing an anonymous online product page with rows of star ratings and review boxes, one review subtly hi
AI Security

A single fake review can trick an AI agent into buying the wrong product

Researchers describe a new class of attack where planted content on trusted pages steers AI assistants into harmful actions without ever hijacking the task itself.

4 min read
Full-frame photoreal news-editorial image of a dimly lit government office at night, a single desktop monitor glowing with an abstract green download progress b
Threat Intelligence

Brazilian Government Sites Turned Into Malware Traps in PhantomEnigma Campaign

Attackers quietly took over more than 20 official .gov.br domains and used them to push a stealthy backdoor, according to new analysis from ANY.RUN.

3 min read
A long polished conference table in a modern governmental chamber, empty high-backed chairs arranged formally on both sides, soft overhead lighting casting clea
Policy & Regulation

China's Military Is Quietly Banning Its Own Cybersecurity Companies

Chinese armed forces are shutting some of the country's biggest cybersecurity firms out of military contracts, and the reason has nothing to do with bad software.

3 min read
Full-frame photoreal editorial shot of a modern office desk at night, glow from a laptop screen showing abstract lines of pale code reflected on a glass surface
Cloud Security

The 'Approval Gap' in Ad Tech: When Marketing Tags Smuggle in Unknown Code

A single approved script on your website can quietly pull in code from vendors your security team has never heard of. Here is why that matters.

4 min read
Photoreal editorial shot of a developer's dark home office desk at night, a laptop open showing an abstract code editor interface with warning-red highlights on
Vulnerabilities

Cursor on Windows Runs Rogue git.exe From Any Opened Repo, No Warning

A flaw in the AI code editor lets a booby-trapped repository execute code on a developer's machine the moment the folder is opened.

4 min read
© 2026 Threat Vectr