Tag

#supply chain

152 stories taggedsupply chain · page 4 of 11.

A long polished conference table in a modern governmental chamber, empty high-backed chairs arranged formally on both sides, soft overhead lighting casting clea
Policy & Regulation

China's Military Is Quietly Banning Its Own Cybersecurity Companies

Chinese armed forces are shutting some of the country's biggest cybersecurity firms out of military contracts, and the reason has nothing to do with bad software.

3 min read
Full-frame photoreal editorial shot of a modern office desk at night, glow from a laptop screen showing abstract lines of pale code reflected on a glass surface
Cloud Security

The 'Approval Gap' in Ad Tech: When Marketing Tags Smuggle in Unknown Code

A single approved script on your website can quietly pull in code from vendors your security team has never heard of. Here is why that matters.

4 min read
Photoreal editorial shot of a developer's dark home office desk at night, a laptop open showing an abstract code editor interface with warning-red highlights on
Vulnerabilities

Cursor on Windows Runs Rogue git.exe From Any Opened Repo, No Warning

A flaw in the AI code editor lets a booby-trapped repository execute code on a developer's machine the moment the folder is opened.

4 min read
Photoreal editorial shot of a developer's darkened desk, an open laptop showing rows of green package names in a terminal, one line highlighted in red, faint bl
Threat Intelligence

Hijacked AsyncAPI npm Packages Slipped a Botnet Loader Into Developer Machines

Four packages under the popular @asyncapi namespace were tampered with to deliver a multi-stage malware loader, in the latest reminder that the open-source supply chain is a soft target.

3 min read
Full-frame edge-to-edge 16:9 photoreal news-editorial image of a dimly lit server rack with green and amber LEDs reflecting off glossy black metal, faint binary
Vulnerabilities

Popular AI Coding Tool Cursor Runs Malicious Files Automatically, Researcher Warns

A security firm reported the flaw seven months ago. Cursor has yet to patch it.

3 min read
A weathered combination padlock resting on a cracked concrete surface, surrounded by a tangled web of thin copper wires spreading outward in all directions, pho
Identity & Access

Poisoned Developer Tool Downloaded Nearly 1,500 Times Before Anyone Noticed

Criminals hijacked the publishing credentials for a widely used JavaScript security package and slipped malware into four releases over a single weekend. Developers who installed any of those versions may have handed over passwords, crypto-wallet keys, and cloud access tokens without knowing it.

3 min read
Photoreal editorial image, 16:9 full-frame edge-to-edge composition
Threat Intelligence

Fake Student Proxies on npm Turned Browsers Into a DDoS Weapon

Researchers at JFrog say 148 malicious packages used the npm registry as free hosting for a booby-trapped proxy site, quietly enlisting students' browsers into a two-week attack campaign in May.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a laptop screen showing a generic browser extensions settings page with one entry greyed out and marke
Threat Intelligence

Chrome and Edge Yank ModHeader Extension After Hidden History Collector Found

The browser add-on had 1.6 million users. A dormant tracker sat inside its official store version, though no evidence suggests it ever ran.

3 min read
Photoreal editorial shot of a generic discount supermarket storefront at dusk in a European city, warm interior light glowing through glass doors, empty shoppin
Breaches

Lidl Customers in Three Countries Warned After Supplier Breach Exposes Personal Data

The German discount chain says a file at an outside IT provider was raided, spilling names, phone numbers and dates of birth for online shoppers in Germany, Belgium and the Netherlands.

4 min read
Full-frame overhead photoreal shot of a dimly lit developer workstation at night, glowing monitor showing abstract lines of code and a package manager terminal,
Threat Intelligence

Attackers Hijacked Injective Labs' GitHub to Slip Wallet-Stealing Code Into npm

A tampered @injectivelabs/sdk-ts release quietly siphoned crypto wallet keys and seed phrases from developers who installed it.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Ransomware

Hackers Are Targeting the Companies Behind Your Hospital, Not Just the Hospital Itself

Attacks on healthcare businesses, the billing firms and IT vendors that keep hospitals running, surged 110% in a year. Experts say criminals have figured out that one breach can unlock hundreds of patients at once.

3 min read
Full-frame edge-to-edge overhead photoreal shot of a developer's dark wooden desk at night, a laptop screen glowing with abstract green code, a small physical h
Threat Intelligence

Poisoned Injective SDK on npm quietly stole crypto wallet keys for hours

A hijacked contributor account on GitHub pushed a booby-trapped version of a popular blockchain toolkit, siphoning seed phrases from any developer who ran the wrong function.

3 min read
Full-frame edge-to-edge photoreal news-editorial shot of a dim server room aisle at night, rows of dark server racks with faint green and amber status lights re
Threat Intelligence

Old, Silent GitHub Accounts Are Being Used to Quietly Map Companies

Datadog Security Labs says several overlapping scraping campaigns are cataloguing corporate GitHub organisations using dormant 'ghost' accounts and stolen tokens.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Threat Intelligence

Your Business Is Already a Wartime Target. Here Is What to Do About It.

Nation-states attacking private companies is not a future risk. It happened at scale in 2017 and the conditions that made it possible have only grown more complicated since.

3 min read
Full-frame overhead shot of a developer's dark wooden desk, a laptop screen glowing with abstract lines of code, a small red warning icon reflected on the keybo
AI Security

AI Coding Assistants Can Be Tricked Into Running the Very Malware They Were Asked to Find

A proof-of-concept from the AI Now Institute shows Claude Code and OpenAI's Codex executing attacker-supplied code when asked to review it in autonomous mode.

3 min read
© 2026 Threat Vectr