Anavem
Languagefr

#supply-chain-attack

20 articles

News20

Cargo truck on dark highway with warning lights and stormy atmosphere
High
Cyber Attacks

FBI Warns of $725M Cargo Theft Surge Targeting Logistics

FBI alerts transportation industry to massive cyber-enabled cargo theft surge reaching $725 million in losses across US and Canada during 2025.

April 30, 06:32 PM6 min
Computer screen showing WordPress security warnings with dramatic lighting
High
Malware

WordPress Plugin Backdoor Exposed After Five Years

Quick Page/Post Redirect plugin containing hidden backdoor code affects over 70,000 WordPress installations worldwide.

April 30, 12:13 AM5 min
Computer screen showing Visual Studio Code with highlighted malicious code in dark lighting
High
Cyber Attacks

Glassworm Campaign Plants 73 Malicious VS Code Extensions

Researchers discovered 73 malicious Visual Studio Code extensions in OpenVSX that activate after updates to steal sensitive data.

April 27, 11:41 PM5 min
Computer screen showing Python code with security warning overlays and dramatic lighting
High
Cyber Attacks

Malicious elementary-data Package Steals Developer Crypto

Attackers compromised the popular elementary-data Python package on PyPI to harvest developer credentials and cryptocurrency wallets from infected systems.

April 27, 05:17 PM5 min
Dark server room with red warning lights illuminating compromised computer systems
High
Cyber Attacks

Checkmarx KICS Supply Chain Attack Targets Developer Tools

Attackers compromised Docker images and VSCode extensions for Checkmarx KICS security scanner to steal sensitive data from developer environments.

April 23, 06:05 PM5 min
Laptop displaying Python code with security warning indicators on screen
Critical
Malware

NKAbuse Malware Exploits Marimo Python Notebook Flaw

Attackers exploit critical Marimo reactive Python notebook vulnerability to deploy NKAbuse malware variant through Hugging Face Spaces infrastructure.

April 16, 06:58 PM5 min
Multiple computer screens showing WordPress security alerts in dark server room
High
Cyber Attacks

30+ WordPress Plugins Compromised in EssentialPlugin Supply Chain Attack

Over 30 WordPress plugins from EssentialPlugin were compromised with malicious code enabling unauthorized website access, affecting thousands of installations.

April 15, 10:33 PM5 min
Dark server room with red emergency lighting and glowing computer terminal showing security warnings
High
Data Breaches

Rockstar Games Hit by ShinyHunters Data Breach via Anodot

Rockstar Games suffered a data breach through compromised analytics provider Anodot, with ShinyHunters gang now leaking stolen data publicly.

April 13, 10:08 PM5 min
macOS security warning dialog on laptop screen with dramatic lighting
High
Cyber Attacks

OpenAI Rotates macOS Certificates After Supply Chain Attack

OpenAI revoked macOS code-signing certificates following a malicious Axios package compromise that targeted GitHub Actions workflows.

April 13, 07:39 PM5 min
Computer motherboard and CPU socket under red warning lighting suggesting security compromise
High
Cyber Attacks

CPUID Website Compromised: CPU-Z Downloads Serve Malware

Attackers compromised CPUID's API to replace legitimate CPU-Z and HWMonitor downloads with malicious executables on the official website.

April 10, 03:12 PM5 min
Dark server room with red warning lights illuminating compromised servers
High
Cyber Attacks

Smart Slider 3 Pro Plugin Hijacked via Supply Chain Attack

Attackers compromised the Smart Slider 3 Pro plugin update system, pushing malicious backdoors to WordPress and Joomla sites worldwide.

April 9, 06:15 PM5 min
Modern corporate office building at dusk with storm clouds overhead
High
Cyber Attacks

UNC6783 Hackers Target BPO Firms to Access Corporate Data

Google's Mandiant identifies UNC6783 threat group exploiting business process outsourcing providers to infiltrate high-value corporate targets across multiple industries.

April 8, 11:46 PM4 min
Multiple development screens showing code repositories with security warnings in dark workspace
High
Cyber Attacks

North Korean Hackers Target Go, Rust, PHP Developers

North Korea's Contagious Interview campaign deploys malicious packages across Go, Rust, and PHP ecosystems to target developers worldwide.

April 8, 09:47 AM5 min
Computer screen showing npm package manager with security warnings and error messages
Critical
Cyber Attacks

Axios npm Package Hijacked, 100M+ Downloads Compromised

Attackers compromised the popular Axios JavaScript HTTP client npm package, delivering cross-platform remote access trojans to millions of developers worldwide.

March 31, 03:53 PM5 min
Python code editor showing package installation with security warning overlays
High
Cyber Attacks

TeamPCP Hackers Compromise Telnyx PyPI Package

TeamPCP threat group compromised the official Telnyx Python package on PyPI, injecting credential-stealing malware hidden in WAV audio files.

March 27, 10:13 PM5 min
Computer screen showing VS Code with security warning dialog in dark development environment
High
Vulnerabilities

Open VSX Registry Bug Let Malicious VS Code Extensions Bypass Security

Open VSX's pre-publish scanning pipeline contained a critical flaw that allowed malicious Visual Studio Code extensions to bypass security vetting and reach the registry.

March 27, 02:57 PM5 min
HackerOne Employee Data Exposed in Navia Breach
Medium
Data Breaches

HackerOne Employee Data Exposed in Navia Breach

HackerOne confirms hundreds of employee records were compromised in a cyberattack targeting third-party vendor Navia Benefits Solutions.

March 25, 08:57 AM5 min
TeamPCP Hackers Compromise LiteLLM Python Package in Supply Chain Attack
High
Cyber Attacks

TeamPCP Hackers Compromise LiteLLM Python Package in Supply Chain Attack

TeamPCP hacking group compromised the popular LiteLLM Python package on PyPI, claiming to have stolen data from hundreds of thousands of devices.

March 24, 11:29 PM5 min
Dark server room with red warning lights and compromised terminal screen
High
Cyber Attacks

Trivy Scanner Hit by Supply Chain Attack via GitHub Actions

TeamPCP threat actors compromised the popular Trivy vulnerability scanner, distributing credential-stealing malware through official releases and GitHub Actions workflows.

March 21, 06:30 PM5 min
Dark server room with blue glowing servers and one rack highlighted in red emergency lighting
High
Cyber Attacks

Trivy Scanner Hit by Second Supply Chain Attack in Month

Aqua Security's Trivy vulnerability scanner suffered another supply chain compromise targeting GitHub Actions workflows and CI/CD secrets.

March 20, 06:47 PM4 min