supply chain attack

AI & Tech

Craneware Data Breach: US Hospital Finance Software Hit by Theft

Craneware, a healthcare finance software provider used by approximately 2,000 US hospitals, disclosed a breach on July 20 where hackers…

Read More »
BigTech Companies

Hackers exploit ViPNet software to breach Russian government agencies

A hacking group is exploiting the update system of ViPNet private networking software to infiltrate Russian government agencies, state-owned enterprises,…

Read More »
BigTech Companies

Hundreds of Brands Impersonated on GitHub to Spread Infostealer Malware

A financially motivated Russian-speaking cybercriminal created 292 fraudulent GitHub repositories impersonating hundreds of brands, luring victims with fake "secure download"…

Read More »
AI & Tech

Hack claims Suno AI trained on scraped YouTube data

A security breach at Suno exposed internal data confirming the company scraped audio from YouTube Music, Deezer, and other services,…

Read More »
Business

Icarus Hackers Claim Klue OAuth Breach, Victim List Grows

Klue confirmed a security breach where attackers stole OAuth tokens from client Salesforce integrations after gaining access through a compromised…

Read More »
AI & Tech

Malicious JetBrains plugins steal developers’ AI API keys

At least 15 malicious plugins on the JetBrains Marketplace, masquerading as AI coding assistants and tools, have been discovered stealing…

Read More »
AI & Tech

400+ Arch Linux AUR Packages Hijacked for Infostealer and eBPF Rootkit Attacks

Attackers compromised over 400 packages in the Arch Linux User Repository (AUR) to deploy a Rust-based credential stealer, which can…

Read More »
AI & Tech

Red Hat npm packages hit by new Mini Shai-Hulud malware wave

On June 1, 2026, over 30 npm packages tied to Red Hat Cloud Services were compromised in a supply chain…

Read More »
AI & Tech

Popular OpenAI Codex tool with 29k weekly downloads stole dev tokens for a month

A malicious npm package named "codexui-android", with 29,000 weekly downloads and a legitimate appearance, secretly exfiltrated developer authentication tokens for…

Read More »
BigTech Companies

Hacked GitHub via tainted VS Code extension

GitHub confirmed a security breach after TeamPCP infiltrated its internal repositories via a compromised VS Code extension installed by an…

Read More »
BigTech Companies

GitHub Confirms 3,800 Repos Breached via Malicious VSCode Extension

A GitHub employee's device was compromised after installing a malicious VS Code extension, leading to approximately 3,800 internal repositories being…

Read More »
BigTech Companies

GitHub confirms hackers breached thousands of internal repos

GitHub confirmed a breach that compromised approximately 3,800 internal code repositories after an employee's device was infected through a malicious…

Read More »
BigTech Companies

Foxconn Ransomware Attack Underscores Ongoing Security Risks

The ransomware group Nitrogen claims to have stolen 8 TB of sensitive data, including schematics from major clients like Apple…

Read More »
Business

Daemon Tools Developer Confirms Trojanized Software

Disc Soft released a clean Version 12.6 of Daemon Tools Lite on May 5, just 12 hours after discovering a…

Read More »
Business

DAEMON Tools Devs Confirm Breach, Release Clean Version

DAEMON Tools Lite was compromised in a supply chain attack affecting free version 12.5.1 installers served from the official website…

Read More »
BigTech Companies

Trellix confirms data breach after source code theft

Trellix confirmed a data breach where unauthorized actors accessed a portion of its source code repository, with no evidence yet…

Read More »
AI & Tech

GlassWorm malware resurfaces through 73 sleeper OpenVSX extensions

The GlassWorm campaign has deployed 73 sleeper extensions on the OpenVSX ecosystem, with only 6 activated so far delivering malware,…

Read More »
AI & Tech

Open-Source Tool Reveals CI/CD Pipeline Attack Methods

Boost Security has launched SmokedMeat, an open-source framework that actively simulates end-to-end attack chains against an organization's own CI/CD infrastructure…

Read More »
BigTech Companies

Vercel Hack Exposes Customer Data

Hackers breached cloud platform Vercel by exploiting an employee's compromised Google account, which was linked to a third-party app from…

Read More »
AI & Tech

CPUID site hacked to distribute malware via HWMonitor

The official CPUID website, known for tools like HWMonitor, was compromised earlier this year, redirecting users to credential-stealing malware for…

Read More »