Tag

#supply chain

152 stories taggedsupply chain · page 6 of 11.

Threat Intelligence

ChocoPoC RAT Hides in Fake GitHub Exploits, Targets Security Researchers

A cluster of trojanized proof-of-concept repositories is pushing a Python-based RAT to the very people who go looking for them.

2 min read
Vulnerabilities

No Patch, No CVE: Argo CD Repo-Server Flaw Opens Door to Kubernetes Cluster Takeover

Synacktiv reported the unauthenticated RCE bug to maintainers. There's still no fix.

3 min read
Threat Intelligence

Fake Perplexity Extension Siphoned Every Chrome Address Bar Keystroke

Microsoft researchers flagged a counterfeit Perplexity Chrome extension that piped queries and omnibox input to an attacker server before completing the search.

3 min read
AI Security

Poisoned Repos Can Trick Claude Code Into Opening a Reverse Shell

Researchers show that prompt injection hidden inside a repository's files is enough to turn Anthropic's agentic coding tool against the developer running it.

2 min read
AI Security

Prompt Injection in Git Repos Can Turn Claude Code Into a Reverse Shell Launcher

Malicious instructions buried in a repository's files can hijack Anthropic's Claude Code agent and open a backdoor on the developer's own machine — no obvious malware required.

2 min read
Vulnerabilities

libssh2 Clients Get a Nasty Surprise: PoC Lands for CVE-2026-55200

A malicious SSH server can corrupt memory on any client built against libssh2 1.11.1 or earlier. No creds required.

2 min read
Threat Intelligence

Supply-Chain Attackers Hide Python Stealer in npm and Go Packages, Sidestep Lifecycle Scripts

JFrog flags two hijacked npm packages and a Go cluster that abuse VS Code tasks to drop a cross-platform infostealer — bypassing the script hooks defenders typically watch.

3 min read
Vulnerabilities

Amazon Patches CVE-2026-12957 in Q Developer: Malicious Repo Could Drain AWS Credentials via MCP

A workspace-trust prompt was all that stood between a developer and credential theft. Amazon has shipped a fix for the high-severity flaw in its AI coding assistant.

2 min read
Threat Intelligence

Mini Shai-Hulud Worm Jumps to Go, Hits LeoPlatform and RStreams npm Packages

The self-propagating supply chain campaign tied to Miasma and Hades has spread again — abusing GitHub Actions workflows and now reaching Go modules.

2 min read
Threat Intelligence

Featured Chrome Ad Blocker with 10M+ Installs Carries Dormant JS Injection Capability

Researchers flagged a Featured-badge extension that can pull and execute remote JavaScript — a capability common to supply-chain abuse clusters tracked across the Chrome Web Store.

2 min read
AI Security

AIVEX Triage Model Targets Software Supply Chain Risk in AI Environments

A new framework aims to help security teams prioritize which supply chain vulnerabilities carry the highest operational, safety, and business risk where AI systems are in play.

2 min read
Vulnerabilities

Cordyceps Flaw Class Hands Attackers the Keys to 300+ GitHub Repos

A newly catalogued CI/CD weakness lets attackers hijack workflows at Microsoft, Google and Apache projects, researchers say.

2 min read
Vulnerabilities

FFmpeg Vulnerability 'PixelSmash' Threatens Media Applications

A critical flaw in FFmpeg's MagicYUV decoder reveals the fragility of software supply chains.

2 min read
Policy & Regulation

White House Orders Federal Agencies to Migrate Cryptography by 2030, Signals Contractor Reckoning

Two executive orders set hard federal deadlines for post-quantum cryptography adoption and launch a government-wide quantum R&D program — with ripple effects for every contractor touching federal networks.

3 min read
AI Security

Fake Agent Skill Slips Past Every Scanner, Lands on 26,000 AI Agents

A red-team experiment by AIR pushed a booby-trapped skill through a popular marketplace and an Instagram ad. The skill marketplaces' security scanners shrugged.

2 min read
© 2026 Threat Vectr