Browsing Category
Supply Chain Risk
16 posts
‘Malware-Slop’ npm Package Targets Claude AI User Files
OX Security said a malicious npm package tried to steal files from Claude user workspaces and upload them to GitHub.
Attackers Turned Trusted Developer Updates Into a Credential Trap
A supply-chain campaign hit trusted developer tools and package registries, exposing how quickly poisoned updates can steal cloud, code and CI/CD credentials.
Pwn2Own Berlin 2026 Closes With $1.3M Paid, 47 Zero-Days and a New Champion
DEVCORE's Orange Tsai-led team dominated all three days to claim the 2026 Master of Pwn title, while STARLabs SG delivered the weekend's most technically significant moment with a memory corruption exploit that broke out of a VMware ESXi hypervisor and crossed tenant boundaries.
Researchers Return to Pwn2Own Berlin Stage With $1M+ Prize Pool Still in Play
Orange Tsai's $200,000 Exchange exploit added fresh bruises to one of enterprise security's most battered attack surfaces as AI tools kept falling across the contest stage.
The App You Forgot About Is Still Reading Your Email
AI agents are multiplying your OAuth footprint. A forgotten "Allow" click is all it takes. Here's what's at risk — and how to check your own exposure right now.
EU Targets Huawei, ZTE in Escalating Telecom Infrastructure Security Push
The EU’s move signals a broader shift from 5G risk management to supply chain control.