Security News

RVTools hit in supply chain attack to deliver Bumblebee malware
2025-05-20 14:39

The official website for the RVTools VMware management tool was taken offline in what appears to be a supply chain attack that distributed a trojanized installer to drop the Bumblebee malware...

Earth Ammit Breached Drone Supply Chains via ERP in VENOM, TIDRONE Campaigns
2025-05-14 11:11

A cyber espionage group known as Earth Ammit has been linked to two related but distinct campaigns from 2023 to 2024 targeting various entities in Taiwan and South Korea, including military,...

Supply chain attack hits npm package with 45,000 weekly downloads
2025-05-08 19:03

An npm package named 'rand-user-agent' has been compromised in a supply chain attack to inject obfuscated code that activates a remote access trojan (RAT) on the user's system. [...]

⚡ Weekly Recap: Nation-State Hacks, Spyware Alerts, Deepfake Malware, Supply Chain Backdoors
2025-05-05 11:29

What if attackers aren't breaking in—they're already inside, watching, and adapting? This week showed a sharp rise in stealth tactics built for long-term access and silent control. AI is being...

Malicious Go Modules Deliver Disk-Wiping Linux Malware in Advanced Supply Chain Attack
2025-05-03 14:31

Cybersecurity researchers have discovered three malicious Go modules that include obfuscated code to fetch next-stage payloads that can irrevocably overwrite a Linux system's primary disk and...

Magento supply chain attack compromises hundreds of e-stores
2025-05-02 18:09

A supply chain attack involving 21 backdoored Magento extensions has compromised between 500 and 1,000 e-commerce stores, including one belonging to a $40 billion multinational. [...]

Securing the invisible: Supply chain security trends
2025-04-30 04:30

Adversaries are infiltrating upstream software, hardware, and vendor relationships to quietly compromise downstream targets. Whether it’s a malicious update injected into a CI/CD pipeline, a rogue...

Ripple NPM supply chain attack hunts for private keys
2025-04-23 18:28

A mystery thief and a critical CVE involved in crypto cash grab Many versions of the Ripple ledger (XRPL) official NPM package are compromised with malware injected to steal cryptocurrency.…

Ripple's xrpl.js npm Package Backdoored to Steal Private Keys in Major Supply Chain Attack
2025-04-23 07:17

The Ripple cryptocurrency npm JavaScript library named xrpl.js has been compromised by unknown threat actors as part of a software supply chain attack designed to harvest and exfiltrate users'...

Why CISOs are watching the GenAI supply chain shift closely
2025-04-21 04:00

In supply chain operations, GenAI is gaining traction. But according to Logility’s Supply Chain Horizons 2025 report, many security leaders remain uneasy about what that means for data protection,...