Supply Chain Attack
New GitHub, PyPI Policies Boost Supply Chain Security
Three days for GitHub, fourteen for PyPI — the poisoned-package window narrows this week.
Analyzing the weaponization of the software and hardware lifecycle. Coverage of NPM hijacks, vendor compromises, and SBOM security strategies.
Supply Chain Attack
Three days for GitHub, fourteen for PyPI — the poisoned-package window narrows this week.
Ransomware
The Nichirei cold-chain cyberattack closes with recovery and an extortion-group claim — supply-chain continuation this week.
Supply Chain Attack
A scale-significant GitHub impersonation campaign hits AI-tooling users — defender inventory work this week.
Supply Chain Attack
Ecosystem supply-chain compromises now extend to RubyGems — three malicious gems built to skip CI runners and land on developer machines make this week's defender inventory work a Ruby-dependency audit.
Data Breaches
A first-of-its-kind AI-agent breach hits the world's largest AI model repository — defender posture and AI-supply-chain review are the week's practical takeaways for organizations that depend on Hugging Face-hosted models, datasets, and Spaces.
Supply Chain Attack
A code-signing-integrity attribution against a Chinese cybercrime subgroup — and a prompt for supply-chain defenders to review how much trust their pipelines place in a valid signature.
Supply Chain Attack
Another JavaScript-ecosystem compromise with a novel blockchain-C2 angle — seven scoped npm packages impersonating the Vite tooling namespace, and defender inventory work this weekend.
Supply Chain Attack
Microsoft goes deep on the AsyncAPI npm compromise — a defender review for CI/CD workflows and @asyncapi dependencies this week.
Supply Chain Attack
A cold-chain cyberattack ripples into KFC Japan and supermarket supplies — supply-chain sector-advisory coverage this week.
Supply Chain Attack
Another JavaScript-ecosystem supply-chain compromise, confirmed by four vendors: four @asyncapi npm packages were observed distributing a multi-stage botnet loader, and all five malicious versions have since been pulled from npm — defender inventory work this week.
Supply Chain Attack
A large-scale JavaScript-ecosystem supply-chain compromise — defender inventory work this week.
Artificial Intelligence (AI)
An AI-IDE supply-chain finding — defender review for organizations using Cursor this week.