2026-10-01 11:45 UTC[med]How Financial Services Companies Can Modernize Their Software Supply ChainThe Hacker Newssupply-chain
2026-09-29 13:45 UTC[info]101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without ConsentThe Hacker Newssupply-chain
2026-09-24 11:08 UTC[info]Malicious npm Packages That Evade DefensesSchneier on Securitysupply-chainmalwareapt
2026-09-23 20:53 UTC[info]GitLab Email Addresses Can Be Weaponized for Supply Chain AttacksDark Readingsupply-chain
2026-09-22 10:22 UTC[info]Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub DataDark Readingsupply-chain
2026-09-21 10:55 UTC[info]CrowdSec Confirms Source Code Stolen in Supply Chain AttackSecurityWeeksupply-chaindata-breach
2026-09-20 14:11 UTC[info]Malicious npm packages evade install-script defenses at runtimeBleepingComputersupply-chainmalware
2026-09-20 11:07 UTC[info]An undercover Google analyst infiltrated a notorious supply-chain hacking gangArs Technicasupply-chain
2026-09-19 07:14 UTC[info]CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub RepositoriesThe Hacker Newssupply-chain
2026-09-18 16:00 UTC[info]An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking GangWired Securitysupply-chaindata-breach
2026-09-18 10:40 UTC[info]WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension StorageThe Hacker Newssupply-chainmalware
2026-09-18 09:46 UTC[info]Brevo Supply Chain Attack Injects Malware Into 100,000 WebsitesSecurityWeeksupply-chaincloudmalware
2026-09-18 09:18 UTC[info]Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm StealerThe Hacker Newssupply-chainaimalware
2026-09-18 08:49 UTC[high]Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatchedHelp Net Securityrcesupply-chainai
2026-09-18 06:00 UTC[med]Abandoned IoT apps keep sending sensitive data to broken serversHelp Net Securitysupply-chainiotmobile
2026-09-17 17:11 UTC[info]Brevo supply-chain attack injected ClickFix scripts on customer sitesBleepingComputersupply-chaincloudmalware
2026-09-17 12:29 UTC[high]Ransomware Attacks on Manufacturers Surge as Supply Chain Risk GrowsSecurityWeekransomwaresupply-chain
2026-09-17 06:13 UTC[info]Riverbed NPM 360 uses AI to predict and prevent network disruptionsHelp Net Securitysupply-chainai
2026-09-16 12:36 UTC[med]Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)Help Net SecurityCVE-2026-90894supply-chaincve
2026-09-14 20:19 UTC[med]Maximum Severity GitLab Flaw Puts Supply Chains at RiskDark ReadingCVE-2026-85706supply-chaincve