Supply Chain Security Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks PowerShell and .NET variants of the malware abuse AirWatch’s MDM API to establish a C&C communication channel. Ionut ArghireNovember 3, 2025
Cybersecurity Funding Chainguard Raises $280 Million in Growth Funding Chainguard has raised $636 million in the past six months alone for its software supply chain security solutions. Eduard KovacsOctober 27, 2025
Malware & Threats Supply Chain Attack Targets VS Code Extensions With ‘GlassWorm’ Malware The malware uses invisible Unicode characters to hide its code and blockchain-based infrastructure to prevent takedowns. Ionut ArghireOctober 21, 2025
Application Security GitHub Boosting Security in Response to NPM Supply Chain Attacks GitHub will implement local publishing with mandatory 2FA, granular tokens that expire after seven days, and trusted publishing. Ionut ArghireSeptember 24, 2025
Application Security Shai-Hulud Supply Chain Attack: Worm Used to Steal Secrets, 180+ NPM Packages Hit The packages were injected with malicious code to harvest secrets, dump them to a public repository, and make private repositories public. Ionut ArghireSeptember 17, 2025
Application Security Highly Popular NPM Packages Poisoned in New Supply Chain Attack Designed to intercept cryptocurrency transactions, the malicious code reached 10% of cloud environments. Ionut ArghireSeptember 10, 2025
Supply Chain Security Over 6,700 Private Repositories Made Public in Nx Supply Chain Attack The private repositories of hundreds of organizations were published publicly in the second phase of the Nx supply chain attack. Ionut ArghireSeptember 8, 2025
Supply Chain Security Hackers Target Popular Nx Build System in First AI-Weaponized Supply Chain Attack With more than 4 million weekly downloads, the Nx build platform became the first known supply chain breach where hackers weaponized AI assistants for... Ionut ArghireAugust 28, 2025
Supply Chain Security High-Value NPM Developers Compromised in New Phishing Campaign Hackers have injected malware into popular NPM packages after compromising several developer accounts in a fresh phishing campaign. Ionut ArghireJuly 24, 2025
Application Security RevEng.ai Raises $4.15 Million to Secure Software Supply Chain RevEng.ai has raised $4.15 million in seed funding for an AI platform that automatically detects malicious code and vulnerabilities in software. Ionut ArghireJune 27, 2025
Vulnerabilities Gerrit Misconfiguration Exposed Google Projects to Malicious Code Injection Misconfigured permissions in Google’s Gerrit code collaboration platform could have led to the compromise of ChromiumOS and other Google projects. Ionut ArghireJune 18, 2025
Malware & Threats React Native Aria Packages Backdoored in Supply Chain Attack A threat actor published backdoored versions of 17 NPM packages from GlueStack in a fresh supply chain attack. Ionut ArghireJune 9, 2025
Nation-State Chinese Hackers Hit Drone Sector in Supply Chain Attacks The China-linked hacking group Earth Ammit has launched multi-wave attacks in Taiwan and South Korea to disrupt the drone sector. Ionut ArghireMay 15, 2025
Malware & Threats Popular Scraping Tool’s NPM Package Compromised in Supply Chain Attack Supply chain attack compromises the popular rand-user-agent NPM package to deploy and activate a backdoor. Ionut ArghireMay 9, 2025
Application Security Manifest Raises $15 Million for SBOM Management Platform Software and AI supply chain transparency firm Manifest has raised $15 million in a Series A funding round led by Ensemble VC. Ionut ArghireApril 25, 2025
Funding/M&A Chainguard Raises Hefty $356M Series D at $3.5 Billion Valuation The cash infusion brings Chainguard’s total funding to about $612 million since launching in 2021 and prices the company at $3.5 billion. Ryan NaraineApril 23, 2025
Supply Chain Security AI Hallucinations Create a New Software Supply Chain Threat Researchers uncover new software supply chain threat from LLM-generated package hallucinations. Ionut ArghireApril 14, 2025
Application Security Compromised SpotBugs Token Led to GitHub Actions Supply Chain Hack Evidence shows a SpotBugs token compromised in December 2024 was used in the March 2025 GitHub Actions supply chain attack. Ionut ArghireApril 4, 2025
Supply Chain Security Impact, Root Cause of GitHub Actions Supply Chain Hack Revealed More details have come to light on the recent supply chain attack targeting GitHub Actions, including its root cause. Eduard KovacsMarch 21, 2025
Malware & Threats 100 Car Dealerships Hit by Supply Chain Attack The websites of over 100 auto dealerships were found serving malicious ClickFix code in a supply chain compromise. Ionut ArghireMarch 17, 2025