Tagged: supply chain attack
The North Korean threat collective PurpleBravo has, for over a year, orchestrated a sophisticated and targeted offensive designated as Contagious Interview. This campaign utilizes fraudulent recruitment processes to assault enterprises across Europe, Asia, the...
Software developers remain a paramount objective for cyber-adversaries, as burgeoning malicious campaigns increasingly exploit the very instruments and environments foundational to the software development lifecycle. A poignant illustration of this trend is the emergence...
Security researchers from the cybersecurity firm Wiz have unearthed a critical vulnerability within the AWS CodeBuild service, which facilitated a total takeover of Amazon’s own GitHub repositories and posed a catastrophic risk to cloud...
A sophisticated supply chain offensive recently compromised the n8n workflow automation ecosystem, as adversaries infiltrated the npm repository with malicious packages camouflaged as legitimate integration modules. According to research by Endor Labs, the primary...
Security researchers at Zscaler have unearthed a sophisticated campaign exploiting prevalent cryptocurrency themes. Three deleterious libraries were discovered within the official npm repository, serving as conduits for a previously undocumented Remote Access Trojan (RAT)...
Popular IDEs with AI assistants—such as Cursor, Windsurf, Google Antigravity, and Trae—have been found vulnerable to a supply-chain attack. These environments prompt users to install extensions that are absent from the OpenVSX catalog. The...
A large-scale supply chain compromise known as Shai-Hulud has been linked to the recent theft of approximately USD 8.5 million in cryptocurrency from more than 2,500 Trust Wallet accounts. The company’s team has concluded...
A new wave of malicious extensions has been uncovered in the Open VSX extension marketplace, which is used by millions of developers worldwide. Researchers at Koi Security warn that attackers are seeding the catalog...
A dangerous vulnerability has been discovered in the Trust Wallet browser extension, potentially allowing attackers to steal users’ cryptocurrency. The issue affected version 2.68, and the wallet’s team officially urged everyone who had installed...
The Chinese hacking group known as Evasive Panda (also tracked as Bronze Highland, Daggerfly, and StormBamboo) carried out one of the most sophisticated and long-running cyber campaigns of recent years, silently infecting victim systems...
In late December, an unwelcome supply-chain surprise erupted around the popular text editor EmEditor. According to the developer, between December 19 and 22, 2025, the download button on the official website may have served...
Blockchain investigator ZachXBT reported on December 25 that, over the preceding hours, numerous Trust Wallet users had experienced unauthorized withdrawals. Affected individuals claimed their assets were drained from their wallets without any form of...