A major data breach at the European Commission was caused by a supply chain attack, where cybercriminals used a compromised…
Read More »supply chain attack
A sophisticated supply chain attack, executed via a compromised open-source tool (LiteLLM), has led Meta to indefinitely suspend its partnership…
Read More »TeamPCP has not retreated but has strategically paused its supply chain attacks to partner with a new ransomware-as-a-service (RaaS) operation…
Read More »The AI recruiting platform Mercor was compromised in a supply chain attack linked to the open-source project LiteLLM, with the…
Read More »A major data breach at European online retailer ManoMano, originating from a compromised third-party service provider in January 2026, exposed…
Read More »A sophisticated malware campaign is targeting developers via 19 typosquatting npm packages, stealing credentials and exhibiting worm-like behavior to self-propagate…
Read More »Notepad++ has released a critical security update (version 8.9.2) to fix vulnerabilities in its update mechanism that were exploited to…
Read More »A sophisticated supply chain attack on Notepad++ by a Chinese state-sponsored group and the exploitation of a Microsoft Office flaw…
Read More »Security researchers discovered a sophisticated supply chain attack targeting dYdX developers, where malicious code in npm and PyPI packages was…
Read More »A suspected Chinese state-sponsored hacking group compromised Notepad++'s update server, exploiting vulnerabilities in its updater to deliver malicious software to…
Read More »Unknown attackers compromised eScan's update server, weaponizing it to deploy a malicious downloader that disabled the antivirus and blocked future…
Read More »eScan antivirus software experienced a supply chain attack where a compromised regional update server distributed a malicious file to a…
Read More »A major security breach at Trust Wallet, linked to the "Sha1-Hulud" supply chain attack, resulted in the theft of approximately…
Read More »The data breach originated at Korean Air's former subsidiary and current supplier, KC&D, compromising employee names and bank account numbers…
Read More »A Home Depot employee accidentally exposed a private access token online for nearly a year, granting extensive privileges to internal…
Read More »A malicious campaign used 19 Visual Studio Code extensions to hide malware, often by embedding a tampered npm package or…
Read More »The breach was a supply chain attack targeting a third-party analytics provider (Mixpanel), not OpenAI's core systems, highlighting a common…
Read More »Malicious extensions named Bitcoin Black and Codo AI were discovered on the VS Code marketplace, using social engineering and functional…
Read More »Malicious packages uploaded to the Rust registry (crates.io) impersonated legitimate developer tools, stealing cryptocurrency by executing a stealthy, multi-stage attack…
Read More »A cybersecurity incident involving Gainsight's Salesforce connector potentially exposed customer data, prompting Salesforce to revoke access and remove Gainsight apps…
Read More »


















