feed.gg
Topic7 articles

Supply-Chain Attack

Ongoing coverage on Supply-Chain Attack.

Latest coverage

7 articles · newest first
EGamers.io

Two Alleged TeamPCP Hackers Arrested in Australia Over Supply Chain Worm That Hit 1,000+ Organizations

The Australian Federal Police have arrested two men in Western Australia in connection with the TeamPCP hacking group, which allegedly distributed malware through open source software packages, impacting over 1,000 organizations. The group's supply chain attack, utilizing a worm named Shai-Hulud, compromised tools like the Trivy vulnerability scanner, leading to the theft of terabytes of credentials and private data.

thumb
Blues News

Evening Safety Dance

The Miasma supply-chain attack toolkit has been publicly released on GitHub. This toolkit is designed to facilitate supply chain attacks, posing a significant cybersecurity threat.

Blues News

Morning Safety Dance

Pitney Bowes has become the latest victim of a supply-chain attack attributed to the group ShinyHunters. The ongoing attack targets security and development tools, indicating a broader trend of breaches affecting software infrastructure.

Blues News

Evening Safety Dance

A new npm supply chain worm has been detected, compromising developer environments. This incident highlights ongoing security vulnerabilities within the software development ecosystem.

PC Gamer

Web-code library with millions of weekly downloads poisoned by malicious release: 'This is unironically a malware…

The popular JavaScript library Axios was targeted in a sophisticated supply chain attack, with malicious versions distributing a remote access trojan. Attackers, identified as a North Korea-nexus threat actor, pre-built payloads and poisoned release branches, with malware calling home within seconds of installation. While malicious versions were quickly removed, cybersecurity firms warn of potential compromise and recommend thorough security assessments.

thumb
PC Gamer

The FCC says foreign routers 'pose an unacceptable risk' and now require special approval to be sold in the US

The US Federal Communications Commission (FCC) has added foreign-produced consumer routers to a 'Covered List,' deeming them an unacceptable national security risk. New foreign routers will require special approval to be sold in the US, though existing devices are unaffected. This measure aims to mitigate risks such as network surveillance and cyberattacks, particularly those linked to state-sponsored actors.

thumb
Blues News

Morning Safety Dance

The GlassWorm supply-chain attack has been identified as exploiting 72 open VSX extensions to target developers. This sophisticated attack highlights significant vulnerabilities within the software development ecosystem.