Browsing Category
Supply Chain Risk
14 posts
Cyberattack Hits 30+ Minnesota Water Systems
Attackers disrupted automated controls at utilities across the state. Investigators have not named the culprit as recent federal warnings focus on internet-exposed industrial equipment.
WriteOut PoC Attack Exposed AI Tool to One-Click Takeover
A discovered vulnerability in Writer AI could have allowed account theft, but it has since been fixed.
CISOs Blamed for 73% of Breaches: But Lack Authority to Stop Them
Accountability without blame: Why cyber incident response requires shared responsibility.
Klue Supply Chain Attack: How a 2022 Credential Exposed LastPass and Ten Other Firms
The Klue supply chain attack exposed a structural blind spot that most security teams still haven't fixed: the forgotten OAuth connection sitting quietly in the corner of their Salesforce instance.
GlassWorm is Back as GlassWASM, Hiding in Open VSX Extensions
A new WebAssembly variant hides its payload in compiled binary and pulls its commands from the Solana blockchain and neither of which standard extension scanners are built to catch.
Red Hat npm Attack Sparks Supply-Chain Alarm
Hackers infiltrated Red Hat software with malware on npm, targeting cloud developer credentials, raising concerns over supply-chain attacks.
CrowdStrike’s ‘Mythos Moment’ Turns AI Security Into Wall Street’s New Test
Nearly two years after its faulty update triggered a global IT outage, CrowdStrike posted record growth and pitched itself as critical AI infrastructure.
DJI Audit Finds No Backdoors as FCC Fight Moves From Policy to Proof
DJI's independent security assessment found no significant risks in its drones, strengthening its position against U.S. regulations, despite ongoing security concerns and market uncertainties.
‘Malware-Slop’ npm Package Targets Claude AI User Files
OX Security said a malicious npm package tried to steal files from Claude user workspaces and upload them to GitHub.
Attackers Turned Trusted Developer Updates Into a Credential Trap
A supply-chain campaign hit trusted developer tools and package registries, exposing how quickly poisoned updates can steal cloud, code and CI/CD credentials.