Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Supply Chain

20 articles

SecurityWeek Supply Chain 11h ago

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks

The most recent variants of the self-propagating attacks are named Miasma and Hades. The post Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain ...

T1195

SecurityWeek →

AWS Security Blog Supply Chain Amazon 1d ago

ICYMI: May 2026 @AWS Security

Read all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, ...

AWS Security Blog →

SC Media Supply Chain 1d ago

VS Code adds 2-hour delay for extension updates to combat supply chain threats

Starting with VS Code version 1.123, extensions will undergo a two-hour waiting period after publication before being automatically updated, provided automat...

SC Media →

The Hacker News Supply Chain Microsoft 1d ago

VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development environment (IDE) are ...

T1195

The Hacker News →

CSO Online Supply Chain 4d ago

Patching fast and slow: Ruby devs delay to defend against supply chain attack

The team behind RubyGems, a package hosting site for Ruby developers, has added a new feature to bundler, a tool for managing Ruby packages (or ‘gems’) to pr...

T1195

CSO Online →

SC Media Supply Chain Sophos 4d ago

Hola browser supply chain attack delivers cryptocurrency miner

Cybersecurity researchers at Sophos and other companies discovered an undeclared executable, identified as a Monero cryptocurrency miner, being installed wit...

T1195

SC Media →

GBHackers Supply Chain 4d ago

Malicious Python Package Mimics Parsimonious Parser

A sophisticated typosquatting attack targeting Python developers through a malicious package named “parsimonius” on the Python Package Index (PyPI). The rogu...

T1195

GBHackers →

BleepingComputer Supply Chain Microsoft 5d ago

Hola Browser for Windows compromised to deliver cryptominer

The Windows version of the Hola Browser has been compromised in a supply chain attack that delivered an undeclared executable identified by researchers as a ...

T1195

BleepingComputer →

Microsoft Security Blog Supply Chain Microsoft 5d ago

Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us 

A surge in real-world attacks against agentic AI systems is reshaping how we think about risk. Based on 12 months of red teaming, this update introduces seve...

T1195

Microsoft Security Blog →

GBHackers Supply Chain GitHub 6d ago

38% of GitHub Actions Workflows Exposed to Script Injection Risks

Analysis has revealed that 38% of organizations are running GitHub Actions workflows vulnerable to script injection or unsafe trigger configurations, highlig...

T1195

GBHackers →

SC Media Supply Chain Jun 2

Why supply chain attacks work and what detection can actually do about it

Here’s what to do in a world where credential theft has been automated and turned into a commodity.

T1078 T1195

SC Media →

CSO Online Supply Chain Google GitHub Jun 2

Attack targeting OpenAI Codex users exposes AI software supply chain risks

A malicious npm package posing as a remote user interface for OpenAI Codex exfiltrated developer authentication tokens, after attackers allegedly published c...

T1041 T1195 T1598

CSO Online →

Kaspersky Securelist Supply Chain Docker Jun 1

Containers on fire: from container escapes to supply chain attacks

We break down the primary attack vectors in containerized environments: exposed secrets, privilege misconfigurations, API compromise, and supply chain attacks.

T1195

Kaspersky Securelist →

SentinelOne Blog Supply Chain May 29

The Good, the Bad and the Ugly in Cybersecurity – Week 22

Authorities dismantle Russian-aligned hosting firm, FBI warns of in-person data thefts, and TrapDoor steals credentials via software supply chain attack.

T1041 T1195

SentinelOne Blog →

GBHackers Supply Chain May 29

Malicious NuGet Package Disguised as Sicoob SDK Exfiltrates Banking Passwords

A newly discovered malicious NuGet package disguised as a legitimate Sicoob software development kit (SDK) has been caught exfiltrating sensitive banking cre...

T1041 T1195

GBHackers →

GBHackers Supply Chain GitHub May 29

Typosquatted npm Packages Steal Cloud and CI/CD Secrets

A coordinated npm supply chain attack has been uncovered targeting developers working with OpenSearch, ElasticSearch, and DevOps tooling, with attackers acti...

T1195

GBHackers →

Kaspersky Securelist Supply Chain Docker May 29

What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant

What are the main risks for container environments: vulnerabilities, supply chain attacks, configuration errors; how to improve container security and how Ka...

T1195

Kaspersky Securelist →

CSO Online Supply Chain IBM Red Hat May 29

IBM and Red Hat want to become the ‘security clearinghouse’ for open source applications in the enterprise

Open source code is everywhere in the enterprise; it’s estimated that upwards of 90% of Fortune 500 companies have it in their software supply chains. But op...

T1195 T1598

CSO Online →

SC Media Supply Chain Linux May 28

Linux Supply Chain How-To - PSW #928

SC Media →

SC Media Supply Chain IBM Red Hat May 28

IBM, Red Hat launch Project Lightwell to secure open-source software

IBM and Red Hat launch $5 billion effort to secure open-source software supply chains.

T1195

SC Media →

1 2 3 4 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA