Tag

#supply chain

149 stories taggedsupply chain · page 9 of 10.

AI Security

One GitHub Issue Was Enough to Pwn Repos Running Claude Code Action

A bug in Anthropic's Claude Code GitHub Action turned issue triage into arbitrary code execution — including, briefly, against the action's own repo.

2 min read
Threat Intelligence

The Week the Tape Came Off: Old Bugs, Cheap C2, and AI That Breaks Things

A roundup of the criminal-economy churn driving this week's intrusions, from plugin holes to agentic AI gone feral.

2 min read
Vulnerabilities

GitHub's Browser VSCode Handed Attackers a Skeleton Key to Your Private Repos

An unscoped OAuth token, a Jupyter notebook, and a skipped publisher trust check. That's all it took.

3 min read
Identity & Access

Poisoned npm Package Stole OpenAI Codex Tokens — and the GitHub Repo Looked Fine

codexui-android published clean source code while shipping malicious artifact builds that harvested refresh tokens. The gap between repo and registry is where the attack lived.

2 min read
Vulnerabilities

Miasma Attack Targets Red Hat Packages

Supply chain breach deploys credential-stealing worm through compromised npm packages.

2 min read
Vulnerabilities

Oracle Launches Monthly Patch Cycle With 35-Flaw Drop, Four CVEs Under Active PoC Threat

A CVSS 10 hole in REST Data Services leads the list. Four older bugs with public exploit code deserve faster attention than their scores suggest.

2 min read
Threat Intelligence

Malicious npm Package codexui-android Pulls 29K Weekly Downloads, Targets OpenAI Codex Tokens

A package posing as a remote web UI for OpenAI Codex is harvesting developer credentials. It's still live on npm and GitHub.

2 min read
Threat Intelligence

Russia's Tech Embargo Run-Around: Shell Companies, Middlemen, and Embedded Spies

Western sanctions were supposed to starve Moscow's military-industrial base of critical components. Instead, Russian intelligence built a procurement machine to go get them anyway.

2 min read
Threat Intelligence

GlassWorm Is Down. The Repository Problem Isn't.

CrowdStrike, Google, and Shadowserver severed four C2 channels simultaneously. Meanwhile, 157 OSV false positives quietly eroded trust in the tools defenders depend on.

3 min read
Vulnerabilities

Critical Argument Injection Zero-Day in Gogs Puts Self-Hosted Git Servers at Risk

A CVSS 9.4 flaw lets authenticated attackers execute arbitrary code through maliciously named pull-request branches — no patch is available.

2 min read
Threat Intelligence

Typosquatted NuGet 'Sicoob.Sdk' Hoovers PFX Certs From Brazilian Banks

A poisoned package impersonating Brazil's Sicoob co-op banking network exfiltrates client IDs and PFX certificates — the same certs that sign API calls into the financial system.

2 min read
AI Security

French Startup Edamame Builds Runtime Watch for AI Coding Agents

The platform uses host telemetry and AI analysis to flag intent drift, secret theft, and supply-chain interference — in real time, before the damage lands.

2 min read
Threat Intelligence

JINX-0164 Runs Fake-Recruiter Playbook Against Crypto Firms, Drops Custom macOS Malware

A newly catalogued threat actor is courting engineers at cryptocurrency companies with bogus job offers, then pivoting into CI/CD systems to siphon digital assets.

2 min read
Threat Intelligence

CrowdStrike, Google and Shadowserver Pull the Plug on GlassWorm's C2

A coordinated takedown severed every known command channel of the developer-targeting worm — for now.

2 min read
AI Security

The npm Package That Reached Into Claude's Sandbox

A bait package called mouse5212-super-formatter quietly siphoned files from the directory Anthropic's Claude uses to handle user uploads, exfiltrating them to a GitHub repo controlled by the author.

2 min read
© 2026 Threat Vectr