supply chain attack

BigTech Companies

Hackers Breach EU Commission Via Security Tool Trivy

A major data breach at the European Commission was caused by a supply chain attack, where cybercriminals used a compromised…

Read More »
Artificial Intelligence

Meta Halts AI Training After Data Breach

A sophisticated supply chain attack, executed via a compromised open-source tool (LiteLLM), has led Meta to indefinitely suspend its partnership…

Read More »
AI & Tech

TeamPCP Ransomware Shift Raises Threat Despite Slower Attacks

TeamPCP has not retreated but has strategically paused its supply chain attacks to partner with a new ransomware-as-a-service (RaaS) operation…

Read More »
AI & Tech

Mercor Cyberattack Linked to Compromised LiteLLM Project

The AI recruiting platform Mercor was compromised in a supply chain attack linked to the open-source project LiteLLM, with the…

Read More »
Business

ManoMano Data Breach Exposes 38 Million European Customers

A major data breach at European online retailer ManoMano, originating from a compromised third-party service provider in January 2026, exposed…

Read More »
Artificial Intelligence

New npm Malware Spreads Itself in Supply Chain Attack

A sophisticated malware campaign is targeting developers via 19 typosquatting npm packages, stealing credentials and exhibiting worm-like behavior to self-propagate…

Read More »
BigTech Companies

Notepad++ Updates Channel After Security Breach

Notepad++ has released a critical security update (version 8.9.2) to fix vulnerabilities in its update mechanism that were exploited to…

Read More »
Artificial Intelligence

Notepad++ Supply Chain Attack Exposed: Patch Tuesday Outlook

A sophisticated supply chain attack on Notepad++ by a Chinese state-sponsored group and the exploitation of a Microsoft Office flaw…

Read More »
Cybersecurity

Malicious dYdX Packages Drain User Wallets

Security researchers discovered a sophisticated supply chain attack targeting dYdX developers, where malicious code in npm and PyPI packages was…

Read More »
BigTech Companies

State-Sponsored Hackers Hijacked Notepad++ Updates

A suspected Chinese state-sponsored hacking group compromised Notepad++'s update server, exploiting vulnerabilities in its updater to deliver malicious software to…

Read More »
Business

eScan AV Users Hit by Malicious Update Attack

Unknown attackers compromised eScan's update server, weaponizing it to deploy a malicious downloader that disabled the antivirus and blocked future…

Read More »
Business

eScan Server Breach Delivers Malicious Software Update

eScan antivirus software experienced a supply chain attack where a compromised regional update server distributed a malicious file to a…

Read More »
Cybersecurity

Trust Wallet Ties $8.5M Crypto Theft to NPM Attack

A major security breach at Trust Wallet, linked to the "Sha1-Hulud" supply chain attack, resulted in the theft of approximately…

Read More »
Business

Korean Air Data Breach: Thousands of Employee Records Exposed

The data breach originated at Korean Air's former subsidiary and current supplier, KC&D, compromising employee names and bank account numbers…

Read More »
BigTech Companies

Home Depot’s internal systems were exposed for a year, researcher finds

A Home Depot employee accidentally exposed a private access token online for nearly a year, granting extensive privileges to internal…

Read More »
BigTech Companies

19 Malicious Visual Studio Code Extensions Uncovered

A malicious campaign used 19 Visual Studio Code extensions to hide malware, often by embedding a tampered npm package or…

Read More »
Artificial Intelligence

OpenAI Data Breach: Why a Password Change Won’t Protect You

The breach was a supply chain attack targeting a third-party analytics provider (Mixpanel), not OpenAI's core systems, highlighting a common…

Read More »
BigTech Companies

Beware Malicious VS Code Extensions Stealing Data

Malicious extensions named Bitcoin Black and Codo AI were discovered on the VS Code marketplace, using social engineering and functional…

Read More »
Cybersecurity

Malicious Rust Packages Target Web3 Developers

Malicious packages uploaded to the Rust registry (crates.io) impersonated legitimate developer tools, stealing cryptocurrency by executing a stealthy, multi-stage attack…

Read More »
Business

Salesforce Users at Risk From Gainsight Supply Chain Attack

A cybersecurity incident involving Gainsight's Salesforce connector potentially exposed customer data, prompting Salesforce to revoke access and remove Gainsight apps…

Read More »