Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Supply Chain

20 articles

Infosecurity Magazine Supply Chain May 28

Attackers Move Past Typosquatting to Realistic Package Impersonation

Most malicious open source packages now mimic real code rather than rely on typosquatting

T1195

Infosecurity Magazine →

Help Net Security Supply Chain May 28

A single typo could derail your World Cup plans

Cybercriminals are spoofing Fédération Internationale de Football Association (FIFA) websites ahead of the 2026 FIFA World Cup, the FBI warns. The attackers ...

T1195

Help Net Security →

SecurityWeek Supply Chain May 27

‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems

Malicious repositories and disguised symlinks can trick AI coding agents into silently installing attacker-controlled MCP servers capable of stealing secrets...

T1195

SecurityWeek →

AWS Security Blog Supply Chain Apple Amazon May 26

Well-architected best practices for software supply chain security

There have been multiple notable supply chain attacks using the npm Registry since September: Shai-Hulud, Chalk/Debug, one abusing tea.xyz tokens, and recent...

T1195 1 IOC

AWS Security Blog →

SecurityWeek Supply Chain GitHub May 25

Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack

Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens. The post Over 5,500 GitHub R...

T1195

SecurityWeek →

GBHackers Supply Chain GitHub May 25

GitHub Strengthens npm Security With Staged Publishing Protection

GitHub has introduced a major security enhancement to the npm ecosystem with the general availability of staged publishing and new install-time controls in n...

T1195

GBHackers →

The Hacker News Supply Chain GitHub May 23

npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a relea...

T1195 T1598

The Hacker News →

HackRead Supply Chain GitHub May 22

5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours

SafeDep uncovered the Megalodon attack targeting 5,561 GitHub repositories with malicious CI workflows and cloud credential theft.

T1078 T1195

HackRead →

Help Net Security Supply Chain GitLab May 22

GitLab 19.0 adds AI workflows, secrets management, and self-hosted model support

GitLab released GitLab 19.0 with expanded secrets management, agentic merge request workflows, improved CI pipeline visibility, support for self-hosted open-...

Help Net Security →

SecurityWeek Supply Chain GitHub May 22

Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack

Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated. The post Grafana Says Codebase and Other Dat...

T1041 T1195

SecurityWeek →

SC Media Supply Chain GitHub May 21

FCC, Github, MiniShai-hulud, Stated of Supply Chain, Itron, CRA, NIS2, and more!! - PSW #927

SC Media →

SecurityWeek Supply Chain May 21

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility

New vulnerabilities are being discovered too fast, the time-to-exploitation is too short, and our visibility into them is largely lacking. The post Supply Ch...

SecurityWeek →

SecurityWeek Supply Chain May 20

Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack

A compromised maintainer account was used to publish malicious package versions across the @antv namespace. The post Over 320 NPM Packages Hit by Fresh Mini ...

T1195

SecurityWeek →

The Hacker News Supply Chain May 20

Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem

AI-generated lookalike domains are now embedded inside the third-party scripts running on your web properties. Here's why your current stack can't see them, ...

T1195

The Hacker News →

GBHackers Supply Chain GitHub May 19

Compromised GitHub Action Steals Workflow Credentials

A widely used GitHub Action, actions-cool/issues-helper, has been compromised in a supply chain attack that exposes sensitive CI/CD secrets to an attacker-co...

T1195

GBHackers →

The Hacker News Supply Chain GitHub May 19

GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials

In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious...

T1041 T1195

The Hacker News →

The Hacker News Supply Chain Docker May 18

Developer Workstations Are Now Part of the Software Supply Chain

Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software poss...

T1195

The Hacker News →

Security Affairs Supply Chain May 16

OpenAI hit by supply chain attack linked to malicious TanStack packages

OpenAI said the TanStack supply chain attack compromised two employee devices and exposed credentials from code repositories. OpenAI confirmed that the recen...

T1195

Security Affairs →

SentinelOne Blog Supply Chain May 15

Living Off the Pipeline: Defending Against CI/CD Subversion

Learn how adversaries weaponize CI/CD pipelines and how continuous behavioral monitoring helps protect against software supply chain attacks.

T1195

SentinelOne Blog →

The Hacker News Supply Chain Apple Intel May 15

TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates

OpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply chain attack on TanStack, but...

T1195

The Hacker News →

«Previous page 1 2 3 4 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA