Malware & Threats China Hackers Behind US Treasury Breach Caught Targeting IT Supply Chain Silk Typhoon APT caught using IT supply chain entry points to conduct reconnaissance, siphon data, and move laterally on victim networks. Ryan NaraineMarch 5, 2025
Supply Chain Security Call for Presentations Open for SecurityWeek’s 2025 Supply Chain Security & Third-Party Risk Summit Join Us in Shaping the Future of Supply Chain Security - Don’t miss this chance to be part of the conversation addressing one of... SecurityWeek NewsJanuary 22, 2025
Malware & Threats North Korean Hackers Targeting Freelance Software Developers North Korea-linked Lazarus Group is targeting freelance software developers to compromise the supply chain. Ionut ArghireJanuary 16, 2025
Supply Chain Security Cyber Insights 2025: Open Source and Software Supply Chain Security Open source software (OSS) is a prime target for supply chain cyberattacks and protecting it remains a major challenge. Kevin TownsendJanuary 15, 2025
Funding/M&A Veracode Targets Malicious Code Threats With Phylum Acquisition The deal includes certain Phylum assets, including its malicious package analysis, detection, and mitigation technology. Ryan NaraineJanuary 7, 2025
Supply Chain Security Cyberhaven Chrome Extension Hack Linked to Widening Supply Chain Campaign The recent compromise of Cyberhaven’s Chrome extension appears to be part of a broad campaign that started over a year ago. Ionut ArghireDecember 31, 2024
Supply Chain Security Several Chrome Extensions Compromised in Supply Chain Attack Cyberhaven and other Chrome extensions were compromised in a supply chain attack targeting Facebook advertising users. Ionut ArghireDecember 30, 2024
Supply Chain Security Solana Web3.js Library Backdoored in Supply Chain Attack Supply chain attack leads to decentralized application developers downloading backdoored versions of the Solana Web3.js library. Ionut ArghireDecember 4, 2024
Ransomware Starbucks, Grocery Stores Hit by Blue Yonder Ransomware Attack Supply chain management software provider Blue Yonder has been targeted in a ransomware attack that caused significant disruptions for some customers. Eduard KovacsNovember 26, 2024
Supply Chain Security Lottie-Player Supply Chain Attack Targets Cryptocurrency Wallets LottieFiles has confirmed that Lottie-Player has been compromised in a supply chain attack whose goal is cryptocurrency theft. Eduard KovacsNovember 1, 2024
Supply Chain Security Open Source Package Entry Points May Lead to Supply Chain Attacks Entry points in packages across multiple programming languages are susceptible to exploitation in supply chain attacks. Ionut ArghireOctober 15, 2024
Risk Management Fortifying the Weakest Link: How to Safeguard Against Supply Chain Cyberattacks As organizations have fortified their defenses against direct network attacks, hackers have shifted their focus to exploiting vulnerabilities in the supply chain to gain... Torsten GeorgeSeptember 26, 2024
Application Security Software Security Firm RunSafe Raises $12 Million in Series B Funding RunSafe Security has raised $12 million in a Series B funding round for a solution designed to help companies develop secure software. Eduard KovacsSeptember 17, 2024
Cybersecurity Funding Software Supply Chain Security Firm Lineaje Raises $20M in Series A Funding Software supply chain security startup Lineaje has raised $20 million in a Series A funding round that brings the total to $27 million. Eduard KovacsJuly 30, 2024
Malware & Threats Polyfill Domain Shut Down as Owner Disputes Accusations of Malicious Activity Namecheap shut down polyfill.io amid reports of malicious activity, but the Chinese owner claims it has good intentions. Ionut ArghireJune 28, 2024
Supply Chain Security Polyfill Supply Chain Attack Hits Over 100k Websites More than 100,000 websites are affected by a supply chain attack injecting malware via a Polyfill domain. Ionut ArghireJune 26, 2024
Supply Chain Security Several Plugins Compromised in WordPress Supply Chain Attack Five WordPress plugins were injected with malicious code that creates a new administrative account. Ionut ArghireJune 25, 2024
Data Breaches Sisense Data Breach Triggers CISA Alert and Urgent Calls for Credential Resets The US government issues a red-alert for what appears to be a massive supply chain breach at Sisense, a company that sells big-data analytics... Ryan NaraineApril 11, 2024
Supply Chain Security XZ Utils Backdoor Attack Brings Another Similar Incident to Light The discovery of the XZ Utils backdoor reminds an F-Droid developer of a similar incident that occurred a few years ago. Eduard KovacsApril 3, 2024
Funding/M&A Binarly Attracts $10.5M to Tackle Software Supply Chain Security Los Angeles firmware and software supply chain firm banks $10.5 million in seed-stage funding led by Two Bear Capital. SecurityWeek NewsMarch 26, 2024