< ciso
brief />
Tag Banner

All news with #supply chain compromise tag

616 articles

Cronos Restarts After Tectonic $74M Exploit

🔔 The Cronos blockchain resumed trading after a rapid price-manipulation attack on the Tectonic lending platform allowed an attacker to borrow $74 million. The attacker inflated the TONIC token price by 100x within 20 minutes and used it as collateral; only about $6 million in ETH was withdrawn while the rest remained on Cronos. Cronos halted the chain, restored state to before the exploit, and resumed block production while investigations continue.
read more →

Weekly cybersecurity recap: espionage, AI, and breaches

⚠️ This week’s recap highlights major disruptions and ongoing campaigns, from an FBI takedown of a Chinese proxy network to AI agents and supply-chain failures. Coverage includes router backdoors, chained PaperCut flaws, malware delivered via fake CAPTCHAs, and the evolving tactics of China-linked actors like Fire Ant. Patch and verify trusted infrastructure controls to reduce risk.
read more →

Trusted Chrome and Edge extensions weaponized

🔍 Researchers at Socket found a supply-chain campaign that turned 19 Chrome and Edge extensions into malware by acquiring or publishing updates to previously legitimate extensions. The attackers used automatic extension updates to push malicious JavaScript payloads that stole cryptocurrency, captured form input, hijacked active sessions, and exfiltrated social media access and browsing history. Several extensions had substantial user bases, underscoring the reach of the operation.
read more →

Arrests in Shai‑Hulud open source supply‑chain case

🛡️ Police in Australia have charged two men over alleged roles in TeamPCP, the gang behind the Shai‑Hulud worm that poisoned open source packages. The AFP, working with the FBI and WA Police, says the suspects — a 21‑year‑old and a 23‑year‑old — face multiple offences including data intrusion and unauthorised modification. Authorities attribute compromises at over 1,000 organisations and theft of more than 500,000 credentials and 300GB of data to the group.
read more →

Attackers Abuse npm Mirrors to Host Phishing Pages

📄 Threat actors are abusing npm packages and public mirrors to host malicious HTML that impersonates Cloudflare CAPTCHA pages and redirects visitors to attacker-controlled sites. Security researchers found multiple npm packages containing a single index.html that, when served through mirrors like unpkg, renders from legitimate domains and executes obfuscated JavaScript to redirect users. Some payloads fetch remote configuration (via api.keyval.org) allowing attackers to change redirect targets without republishing packages. OX Security warns mirrors can act as free frontend hosts for phishing content and recommends treating direct HTML requests to npm mirrors as suspicious.
read more →

Supply-chain malware infects Android car head units

🔍 Kaspersky researchers say a supply-chain attack abused a legitimate DoFun update app to deliver JarService malware to Android-based car head units, attributing the campaign to the MoYu group. The loader retrieves encrypted payloads and exposes nine remote commands used to collect device metadata, run code, open URLs, and perform network checks. Operators primarily install a reverse-proxy module named zhima to convert head units into proxy nodes for ad fraud and monetization, while DoFun says it has remediated the issue.
read more →

North Korean Supply Chain Attack Targets Rust Ecosystem

🔒 Wiz researchers linked a recent supply chain attack in the Rust ecosystem to state-sponsored North Korean actors. The campaign compromised maintainer accounts on crates.io to alter manifests and import a typosquatted dependency, allowing malicious build-time code to run during compilation. The backdoor aimed to harvest browser credentials, crypto wallets and developer secrets, affecting widely used crates including arrayref, internment and append-only-vec.
read more →

Pokémon Center breach exposes customer data, cancels orders

📣 Pokémon Center has notified UK and German customers that a third-party logistics provider, CEVA Logistics, suffered a cyberattack that exposed customer personal and order information. The breach affected CEVA systems between July 29 and August 1 and disrupted several European warehouses, causing shipping delays and cancellations. Pokémon Center says exposed data may include names, mailing addresses, phone numbers, email addresses, and order details, but not payment card information.
read more →

GE and Philips probe alleged Clop ransomware breach

🔍 General Electric and Philips are investigating claims that the Clop ransomware gang breached their systems and stole data. Philips confirmed an attempted compromise of an internal enterprise server that has been contained and said there was no impact on customer environments. GE acknowledged awareness of the claim and is assessing the potential issue. The incidents are linked to Clop’s exploitation of a PTC Windchill and FlexPLM vulnerability (CVE-2026-12569) that has prompted emergency advisories and active threat confirmations.
read more →

Five key security takeaways from Black Hat 2026

🔐 AI dominated Black Hat and DEFCON discussions, highlighting both its value as a defense tool and the risks posed by autonomous agents and malicious AI skills. Speakers urged moving beyond reactive patching toward durable designs, memory-safe languages like Rust, and automated remediation. Researchers revealed AI-based supply-chain attacks, methods to use GitHub telemetry for detections, and human-led AI research uncovering new vulnerabilities. A NAT-based attack class called NatJack was disclosed, prompting vendor patches.
read more →

Trezor reports customer data breach via ShipMonk hack

📢 Trezor disclosed a data breach after its shipping partner ShipMonk was hacked, exposing nearly 14,000 customers' order details. The exposed data includes full names, shipping addresses, email addresses, and phone numbers for customers who received orders between May 10 and August 8, 2026. Trezor confirmed its systems and devices were not compromised but warned affected customers to expect heightened phishing attempts. ShipMonk attributed the intrusion to a Metabase zero-day vulnerability that allowed attackers to access stored customer data.
read more →

Fake CCleaner installer enables Chrome credential theft

🛡️ Researchers discovered a multi-stage Windows malware campaign that uses a fake CCleaner download to install a malicious Chrome extension called GhostDesk. The payload abuses Chrome to capture credentials, cookies, keystrokes, screenshots, and to inject arbitrary JavaScript into active tabs. Variants impersonating 7-Zip and Adobe Acrobat share the same C2 infrastructure and delivery mechanism. Malwarebytes recommends verifying download sources and using up-to-date anti-malware protections.
read more →

Using GitHub telemetry as an EDR-style detector

🔍 Researchers at Black Hat USA 2026 demonstrated that GitHub’s native telemetry can be used like an EDR to detect supply-chain attacks by monitoring event streams, webhooks, API data, and Git history. Their open-source GitHub Threat Detector implements behavioral detections from recurring attacker techniques—such as forged commit metadata, mass tag poisoning, workflow abuse, and OIDC token misuse—into correlated rules. The tool uses a PostgreSQL-backed activity store for historical correlation and includes production and beta detection rules, though it faces practical limits from disabled webhooks and API rate limits.
read more →

Data Breach Impacts Ceva Logistics Supply Chain

🛡️ Ceva Logistics, part of CMA CGM Group, reported a breach affecting its European contract logistics operations, impacting eight warehouses. The company notified affected customers on August 1 after an incident that reportedly ran from July 29 to August 1. Client data potentially exposed included names, emails, addresses, phone numbers and order details, affecting customers such as Valve, Bol, De Bijenkorf, Ajax and ING. Vendors warn of follow-on phishing and impersonation risks and stress logistics firms are high-value attack targets.
read more →

UK Manufacturing Cyber Resilience Falls Short

🛠️ A new Make UK report finds that around 30% of UK manufacturers experienced a cyber incident in the past year, often through their supply chain. The study highlights significant operational and financial impacts, including production delays and material shortages, while many firms still lack formal response plans, CISO roles or clear cyber insurance coverage. The report urges board-level attention and improved supplier assurance.
read more →

Valve notifies Steam hardware customers of breach

🔔 Valve is informing Steam hardware customers in Europe that a breach at shipping partner CEVA Logistics exposed delivery-related data. The company says attackers accessed CEVA systems between July 29 and August 1, 2026, and likely obtained names, addresses, phone numbers, emails, and order details. Valve clarified that payment, passwords, and Steam Guard codes were not exposed and warned customers to watch for phishing attempts using the stolen information.
read more →

Malicious Solidity Pro VS Code Extensions Steal Wallets

🔒 Researchers have identified malicious Visual Studio Code extensions named Solidity Pro that evolved from fetching encrypted payloads to a full-featured information stealer. The extensions, distributed under names like helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, harvest browser profiles, crypto wallets, SSH keys, API tokens, and more, then exfiltrate data via a Telegram bot. The malware uses heavy obfuscation, staged clean releases, and randomized delayed activation to evade detection and marketplace review.
read more →

How Google Cloud detects and contains emerging threats

🔒 Google Cloud outlines its proactive, shared-fate approach to detect and contain emerging threats across AI workloads, cryptomining, credential exposure, supply chain attacks, and account takeover. The post describes detection signals, tailored containment actions like granular throttling and localized identity isolation, and escalation paths including targeted suspensions. It highlights integrations such as GitHub Secret Scanning and details observability tools like Cloud Abuse Event Logging, Cloud Audit Logging, and billing alerts.
read more →

Python package supply-chain risks for AI development

🛡️ On March 24, 2026, widely used Python package LiteLLM was compromised on PyPI, delivering a .pth-based payload that auto-executed on interpreter start. The threat actor group TeamPCP pushed malicious versions that harvested cloud tokens, SSH keys and other secrets, and poisoned packages were available for roughly three hours. The incident is part of a broader rise in malicious open-source packages and highlights unique risks in AI development environments where dependencies can expose models, data and multi-cloud credentials.
read more →

ThreatsDay bulletin: weekly cyber risk roundup

📌 This ThreatsDay bulletin summarizes a week of active cyber risks, including supply-chain npm packages, ClickOnce phishing chains, AI-driven attacks and new macOS and Samsung device exploits. It highlights research on coding-agent trust, AI-powered proxyjacking, and large-scale malicious npm campaigns, and notes policy and platform responses from Apple, Signal, and Microsoft. The report emphasizes common causes: exposed services, trusted defaults, recycled bugs, and poisoned agent instructions.
read more →