#supply chain
152 stories taggedsupply chain · page 5 of 11.

Fake Paysafe and Skrill SDKs on npm and PyPI Went After Developers' Secrets
A single attacker uploaded 17 lookalike payment packages that quietly stole API keys, cloud credentials and GitHub tokens from anyone who installed them.

HalluSquatting: When AI Coding Helpers Invent Fake Software, Criminals Register It First
Researchers show how attackers can predict the fake package names AI assistants make up, then publish real malware under those names, waiting for developers to install the trap.

A Hidden Note in a Bug Report Tricked GitHub's AI Into Leaking Company Secrets
Researchers showed how a single crafted message in a public GitHub issue could fool an AI assistant into reading private code and posting it online for anyone to see.

Accenture confirms break-in as hacker offers 35GB of stolen code for sale
The consulting giant says the incident is contained, but a forum seller known as 888 claims to be holding source code, Azure access keys and SSH keys taken in July 2026.

The Weak Link This Week Wasn't Code. It Was Trust.
From home streaming boxes turned into criminal relays to AI assistants tricked by hidden instructions, this week's incidents share one root cause: systems trusting the wrong thing.

Researchers Show AI Coding Agent 'Skills' Can Hide Malware From Every Scanner Tested
A Hong Kong team's packing trick beat static scanners more than 90% of the time. Their own runtime checker caught most of it.

North Korean hackers flood open-source repositories with 108 booby-trapped packages
The Contagious Interview crew is back, seeding npm, Packagist, Go and Chrome with malware aimed at developers.

Seven flaws in a tiny bit of code could shake millions of gadgets
runZero found bugs in FatFs, the filesystem library hiding inside cameras, drones and hardware crypto wallets. Patches are already trickling out, but the fix will take years.

Fake Rollup Helper Packages on npm Traced to North Korean Hackers
Two look-alike JavaScript packages copied a popular developer tool line-for-line, then quietly opened a back door onto the machines of anyone who installed them.

American Tech Is Quietly Powering the Global Scam Machine
A joint investigation by AP and FRONTLINE found that tools built by US companies are helping criminals run fraud operations at industrial scale — and most victims never see it coming.

AI Assistants Are Inventing Fake Web Addresses — and Criminals Are Buying Them Up
Researchers at Palo Alto Networks found that AI tools routinely make up plausible-sounding website addresses that don't exist. Criminals are registering those addresses before anyone notices — and one already built a full fraud operation using the same AI trick.

Satellite reaction wheel flaw lets attackers with physical access swap in malicious firmware
CISA flags a signature-verification gap in CubeSpace's CW0057, tracked as CVE-2026-13743. The vendor rates practical risk as low.

Twenty Years of Getting It Wrong: The Breaches and Blunders That Defined Modern Cybersecurity
From MGM's identity disaster to MOVEit's patch pile-up, the same failure modes keep appearing in postmortems. That's the problem.

Unpatched Argo CD Flaw Turns Your GitOps Engine Into a Deployment Backdoor
A gRPC endpoint that skips authentication, network policies off by default, and Redis credentials sitting in the environment. Synacktiv's research shows how one compromised pod can become a supply-chain pivot.

ChocoPoC: The Fake Exploit Repos Turning Bug Hunters Into Victims
A Python-based infostealer is hiding inside GitHub proof-of-concept code marketed to vulnerability researchers, siphoning credentials, cookies, and files before dropping a remote shell.