Authorities in Australia said Wednesday that they arrested two men accused of participating in cybercrimes for TeamPCP, a prolific group […]
Tag: supply chain attacks
Terabytes of credentials leaked in massive supply-chain attack
Skip to content TEAMPCP’S RAMPAGE CONTINUES The data was scraped and exfiltrated from 2,500 users of a compromised AI package. […]
Dozens of Red Hat packages backdoored through its official NPM channel
The worm, dubbed Shai-Hulud, has all the hallmarks of malware released last month as freely available open source. TeamPCP was […]
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
“Current evidence indicates that this data originated from Checkmarx’s GitHub repositories, and that access to those repositories was facilitated through […]
Widely used Trivy scanner compromised in ongoing supply-chain attack
Hackers have compromised virtually all versions of Aqua Security’s widely used Trivy vulnerability scanner in an ongoing supply chain attack […]
Supply-chain attack using invisible code hits GitHub and other repositories
The invisible code is rendered with Public Use Areas (sometimes called Public Use Access), which are ranges in the Unicode […]
Third-party breach disclosures don’t reflect the true scale of the problem
A new report from cyber risk management company Black Kite finds 136 unique major incidents, affecting 719 companies, however, an […]
Notepad++ users take note: It’s time to check if you’re hacked
Skip to content Suspected China-state hackers used update infrastructure to deliver backdoored version. Infrastructure delivering updates for Notepad++—a widely used […]
Supply chains, AI, and the cloud: The biggest failures (and one success) of 2025
The past year has seen plenty of hacks and outages. Here are the ones topping the list. Credit: Aurich Lawson […]
Open source malware up 140 percent
The latest OS Malware Index from Sonatype shows a 140 percent surge in open source malware as attackers target data […]
