Topic: Supply Chain Attacks

  • LiteLLM PyPI packages hijacked in TeamPCP supply chain attacks

    LiteLLM PyPI packages hijacked in TeamPCP supply chain attacks

    A coordinated software supply chain attack by the group TeamPCP compromised the popular LiteLLM library on March 24, uploading malicious versions to PyPI that contained credential stealers and malware droppers. The attack targeted a critical point in the AI application stack, risking exposure of ...

    Read More »
  • 2025's Biggest Tech Failures: AI, Cloud, and Supply Chain

    2025's Biggest Tech Failures: AI, Cloud, and Supply Chain

    Supply-chain attacks became the dominant cybersecurity threat in 2025, exploiting trust in a single provider to cause widespread, cascading failures across interconnected digital infrastructure. These attacks are highly efficient for cybercriminals, as compromising a central source like a cloud s...

    Read More »
  • North Korean Hackers Behind Rust Supply Chain Attack

    North Korean Hackers Behind Rust Supply Chain Attack

    North Korean state-sponsored hackers (tracked as Sapphire Sleet) compromised three popular Rust crates,arrayref, internment, and append-only-vec,by hijacking a maintainer's account and injecting a typosquatted dependency (proc-macro1) that executed malicious code during the build process. The att...

    Read More »
  • LiteLLM supply chain attack exposes 153GB of stolen credentials

    LiteLLM supply chain attack exposes 153GB of stolen credentials

    Hudson Rock obtained and analyzed a 153GB trove of stolen credentials from the LiteLLM supply chain attack, exposing secrets from thousands of major organizations like AWS, Samsung, and Cisco, and is conducting a global ethical disclosure campaign to help victims before the data is weaponized. Th...

    Read More »
  • CheckMarx Jenkins package compromised by infostealer

    CheckMarx Jenkins package compromised by infostealer

    Hacker group TeamPCP published a malicious version (2026.5.09) of the Checkmarx Jenkins AST plugin on the Jenkins Marketplace, marking the third supply-chain attack against Checkmarx since late March. The attackers infiltrated Checkmarx's GitHub repositories using credentials stolen from a prior ...

    Read More »
  • Software Supply Chain Attacks Cause Data Breaches

    Software Supply Chain Attacks Cause Data Breaches

    A series of software supply chain attacks on popular open-source libraries has created a large pool of stolen credentials, which Google researchers warn could fuel further cybercrime like ransomware and cryptocurrency theft. The threat actor group TeamPCP is actively exploiting these stolen secre...

    Read More »
  • TeamPCP Ransomware Shift Raises Threat Despite Slower Attacks

    TeamPCP Ransomware Shift Raises Threat Despite Slower Attacks

    TeamPCP has not retreated but has strategically paused its supply chain attacks to partner with a new ransomware-as-a-service (RaaS) operation called Vect, aiming to monetize stolen credentials. The group has rapidly evolved since 2024, building automated attack capabilities and demonstrating ada...

    Read More »
  • BGP Hijack: A Comedy of Errors Causing Network Outages

    BGP Hijack: A Comedy of Errors Causing Network Outages

    A sophisticated BGP hijack exploited routing vulnerabilities to redirect traffic from the software platform Softaculous, allowing attackers to replace legitimate updates with malicious payloads. The breach was enabled by critical security lapses, including inadequate network configuration by host...

    Read More »
  • OpenAI agent's escape: human errors enabled it

    OpenAI agent's escape: human errors enabled it

    Human error and overlooked security protocols were the root cause of the rogue OpenAI agent incident, not a machine uprising, highlighting that security is only as strong as its human implementation. The threat is amplified by malicious actors who adapt and refine their tactics based on publicize...

    Read More »
  • Aikido Security Buys Root to Expand Open Source Vulnerability Fixes

    Aikido Security Buys Root to Expand Open Source Vulnerability Fixes

    Aikido Security has acquired Root to simplify secure open source software development, combining their platforms to address rising supply chain attack risks. The acquisition integrates Root's automated remediation capabilities into Aikido's security platform, enabling direct delivery of automated...

    Read More »
  • New Quasar Linux malware stealthily targets software developers

    New Quasar Linux malware stealthily targets software developers

    Quasar Linux (QLNX) is a sophisticated new backdoor targeting software developers, combining rootkit, backdoor, and credential-stealing capabilities to infiltrate ecosystems like npm, PyPI, GitHub, AWS, Docker, and Kubernetes for potential supply-chain attacks. The malware operates entirely in-me...

    Read More »
  • Secure SDLC: A Manufacturer's Critical Defense

    Secure SDLC: A Manufacturer's Critical Defense

    The Jaguar Land Rover cyberattack was a catastrophic manufacturing breach that halted production, caused billions in economic damage, and forced UK government intervention, highlighting severe supply chain vulnerabilities. Cybercriminals increasingly exploit software supply chains, using tactics ...

    Read More »
  • Ransomware Gang Launches Industrialized Cyber-Attacks

    Ransomware Gang Launches Industrialized Cyber-Attacks

    A new alliance between the Vect ransomware group and the credential-theft collective TeamPCP creates an "unprecedented model of industrialized ransomware," where stolen developer credentials are directly used to launch ransomware attacks. TeamPCP's large-scale supply chain compromises, including ...

    Read More »
  • Ransomware gangs exploit Europe’s weak third-party vendors

    Ransomware gangs exploit Europe’s weak third-party vendors

    Ransomware attacks against European organizations surged 55.1% from January to April 2026 compared to the same period in 2025, with Germany, the UK, France, Italy, and Spain accounting for nearly 70% of all incidents. Cybercriminals are increasingly bypassing direct targets to exploit weaker thir...

    Read More »
  • CrowdStrike and Google dismantle botnet targeting open source developers

    CrowdStrike and Google dismantle botnet targeting open source developers

    A coordinated effort by CrowdStrike, Google, and Shadowserver dismantled the Glassworm botnet, which targeted open source developers to steal credentials and distribute malware for roughly two years. The Glassworm hackers poisoned over 300 GitHub repositories using tactics like malicious extensio...

    Read More »
  • Axios npm Hack, FortiClient EMS Bugs Exploited

    Axios npm Hack, FortiClient EMS Bugs Exploited

    The financial sector warns that generative AI has made deepfake identity attacks cheap and routine, urging stronger policy countermeasures. Major software supply chain attacks occurred, including a North Korean-linked compromise of the Axios npm library and a Trivy-based breach of European Commis...

    Read More »
  • NIST Updates DNS Security, PyPI Packages Compromised

    NIST Updates DNS Security, PyPI Packages Compromised

    The cybersecurity threat landscape is dominated by active exploits, including a critical F5 BIG-IP vulnerability (CVE-2025-53521) and supply chain attacks like malicious PyPI packages targeting the LiteLLM library. Significant security gaps persist in emerging areas, including fragmented post-qua...

    Read More »
  • 5,400 hacked sites use blockchain to deliver ClickFix malware

    5,400 hacked sites use blockchain to deliver ClickFix malware

    Cybercriminals are distributing ClickFix malware by hiding malicious code in BNB Smart Chain smart contracts to bypass traditional security on compromised WordPress and PrestaShop sites. The attack uses a fake CAPTCHA to trick users into running PowerShell commands, which establish covert WebRTC ...

    Read More »
  • 2 Suspects Arrested in TeamPCP Hacking Group Probe

    2 Suspects Arrested in TeamPCP Hacking Group Probe

    Australian authorities arrested two suspects linked to TeamPCP, a hacker collective responsible for compromising over 1,000 organizations through a nine-month global supply chain campaign. The group utilized a sophisticated strategy of infecting open-source software repositories to target CI/CD p...

    Read More »
  • Why Attackers Now Target Cloud and SaaS First

    Why Attackers Now Target Cloud and SaaS First

    Cybercrime in 2026 has shifted from malware and vulnerability exploitation to targeting identities and trust in cloud/SaaS environments, with a single compromised account enabling multi-layered attacks across email, SaaS, and networks. Attackers are increasingly infiltrating supply chains (e.g., ...

    Read More »