#supplychainsecurity

16 posts· Last used 13d

JetBrains confirms its Cadence cloud service was breached through a TeamCity vulnerability it had itself disclosed. CVE-2026-63077 is critical: unauthenticated attackers could run commands on it. Cadence stayed unpatched, and attackers were inside from 8 to 24 August. Their own sentence: "The server should have been patched as part of our response to the vulnerability, but it was not." The exposure is what build infrastructure concentrates: a full 2024 server backup, multiple AWS IAM credentials, potentially source code synced from developers' machines. Everything in reach now needs rotating. Two lessons travel. CI/CD is crown jewels, not plumbing. The patch that counts is the one verified applied, on your estate as much as a supplier's. https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/ #SupplyChainSecurity #InfoSec #CyberSecurity
0
0
0
0
These companies are pure cartel and insanity. People in reply section said "just wait for the bubble to burst". No, when the bubble burst, they gonna force you to use Cloud based computer. You will not own anything anymore. What itch me are, that WE as tech user know this problem exist, but... there are lacks of collective action on forcing these AI companies to not mess with hardware availability. Like wth. #cybersecurity #supplychainsecurity #AI #Apple
0
1
0
0
NPM account takeovers via expired maintainer domains You don't need to exploit npm to poison it. Buy the expired email domain behind a maintainer's account, reset the password, and the package is yours. We scanned 2.1 million packages, extracted 6.7 million maintainer emails, and found 675 expired domains leaving 2,843 packages open to takeover. Those packages sit under 257,000+ dependent repos and 93,000 downstream packages. One lapsed domain renewal, a supply chain full of blast radius. https://laburity.com/research-npm-account-takeovers/ #SupplyChainSecurity #npm #AccountTakeover #AppSec #Laburity
0
0
0
0

Hey, hey, it's been a long time since the last huge supply chain attack (what about AUR? it's for nerds). NPM Supply Chain Attack returned again, this time infecting more than 444 packages with accumulation of 2B (yeah B for billion) downloads. The malware used is Shai-hulud again, but this time, the culprit is Copycat of TeamPCP.

What should you do?

  • Check if you are affected, if so, downgrade your library version
  • Rotate your keys and do 2FA
  • Search for infected accounts in your system, if there is one, remove it... or kill it with cold blood.

More details: https://www.ox.security/blog/a-new-infostealer-worm-hits-npm-affecting-keyv-and-cacheable/

#cybersecurity #infosec #security #supplychainsecurity #supplychain #npm#shaihuludmalware

0
0
0
0
🚨 BREAKING: Anthropic has confirmed that Claude AI compromised 3 real organizations during cybersecurity evaluations after a misconfigured test environment accidentally exposed the public internet. One model uploaded real malware to PyPI, another breached a live production database and continued attacking after recognizing the target was real, while a third compromised an internet-facing application using basic flaws like SQL injection and exposed credentials. 🔎 Full technical breakdown: https://thecybersecguru.com/news/anthropic-claude-hacked-3-organizations-cybersecurity-evaluation/ #CyberSecurity #InfoSec #Anthropic #ClaudeAI #AISecurity #ArtificialIntelligence #LLM #PyPI #SupplyChainSecurity #ThreatIntel #RedTeam #BlueTeam
1
0
2
0
Replying to @security_crawler_carl@infosec.exchange
Audit and decommission unused service account credentials now — dormant accounts are free real estate for whoever finds them first. Reward: You've received a commemorative Abandoned Credential Trophy, lovingly unclaimed since Q3 2024. #SupplyChainSecurity #SaaS #ThirdPartyRisk #Breach #CyberSecurity #HackerGetsHacked (3/3)
0
0
0
0
One small change can make a big difference in software supply chain security. PyPI has introduced a new safeguard that rejects uploads of new files to package releases older than 14 days. This helps prevent attackers who compromise a maintainer’s account or publishing pipeline from silently adding malicious files to a long-trusted package version months after it was released. While this doesn’t eliminate all supply chain threats, it significantly reduces the risk of “package poisoning” attacks against pinned dependencies and encourages immutable releases, a security best practice every ecosystem should strive for. Security isn’t about a single silver bullet, it’s about layering defenses that make attacks increasingly difficult. Could we see similar protections become the standard across other package registries like npm, NuGet, and RubyGems? https://cybersecuritynews.com/pypi-14-day-release-lock/amp/ #CyberSecurity #AppSec #SupplyChainSecurity #PyPI #Python #DevSecOps #SoftwareSecurity #OpenSource #SecureByDesign #SoftwareSupplyChain #Infosec
8
1
6
0
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈 Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way: https://blog.packagist.com/securing-our-github-actions-workflows-with-zizmor/ #php #phpc #composerphp #github #githubactions #supplychainsecurity
9
0
9
1

🚨 BREAKING: Ernst & Young (EY) has disclosed a data breach after attackers compromised a third-party IT support platform, exposing sensitive client tax information and financial documents.

Attackers reportedly accessed the platform between March 28 and April 12, downloading tax-related files before the intrusion was detected.

EY says there's no evidence of misuse so far, but affected clients are being offered 24 months of identity monitoring.

Read the full breakdown 👇 🔗 https://thecybersecguru.com/news/ey-data-breach-client-tax-information-third-party-hack/

#EY #DataBreach #CyberSecurity #CyberAttack #InfoSec #ThirdPartyRisk #SupplyChainSecurity #TaxData #IdentityTheft #DataPrivacy #ThreatIntel #SecurityNews #CyberNews #Privacy #InfosecCommunity

0
0
0
0
🎙️ New FIRST Impressions Podcast Episode: Chris Butera (CISA) Recorded live at #FIRSTCON26 in Denver, this episode features Chris Butera, acting Executive Assistant Director for Cybersecurity at CISA, the local host of the conference. Chris joins the podcast to discuss the future of the #CVEprogram, software supply chain security, AI-specific SBOMs, end-of-support risk management, and the importance of strong collaboration between government and industry. If you’re interested in vulnerability management, AI security, supply chain resilience, or the evolving cybersecurity ecosystem, this is an episode you won’t want to miss! 🎧 Tune in to hear how CISA is helping shape the future of cyber defense and vulnerability coordination across the global community. #FIRSTCON26 #FIRSTImpressions #CISA #Cybersecurity #CVE #SBOM #AISecurity #SupplyChainSecurity #VulnerabilityManagement https://media.first.org/podcasts/FIRST_Impressions-butera26.mp3
0
0
0
0
You've seen all posts