Sponsor of the Day:
Jerkmate
https://www.indusface.com/learning/what-is-a-supply-chain-attack/
Supply Chain Attacks: Examples & Prevention | Indusface
Discover how supply chain attacks work, their types, real-world examples, and key prevention strategies to protect your business from these growing threats.
supply chain attacksexamples preventionindusface
https://securelist.com/model-context-protocol-for-ai-integration-abused-in-supply-chain-attacks/117473/
Malicious MCP servers used in supply chain attacks | Securelist
Sep 15, 2025 - Kaspersky experts discuss the Model Context Protocol used for AI integration. We describe the MCP’s architecture, attack vectors and follow a proof of concept...
supply chain attacksmcp serversmalicioususedsecurelist
https://www.helpnetsecurity.com/tag/supply-chain-attacks/
supply chain attacks Archives - Help Net Security
supply chain attacksarchives helpsecurity
https://www.infosecurity-magazine.com/news/surge-in-software-supply-chain/
Surge in Software Supply Chain Attacks - Infosecurity Magazine
Dec 19, 2022 - Survey found lack of visibility and awareness of how to combat supply chain attacks
software supply chainattacks infosecurity magazinesurge
https://us.pycon.org/2026/schedule/presentation/79/
Breaking Bad (Packages): Why Traditional Vulnerability Tracking Fails Supply Chain Attacks - PyCon...
supply chain attacksbreaking badpackagestraditionalvulnerability
https://www.stepsecurity.io/
StepSecurity - Detect, Prevent, and Respond to Software Supply Chain Attacks
Detect, prevent, and respond to software supply chain attacks. End-to-end protection for AI agents, developer machines, npm packages, and CI/CD pipelines.
software supply chaindetect preventstepsecurityrespondattacks
https://www.csoonline.com/article/4081492/modern-supply-chain-attacks-and-their-real-world-impact.html
Modern supply-chain attacks and their real-world impact | CSO Online
Nov 6, 2025 - Supply-chain attacks have evolved considerably in the last two years going from dependency confusion or stolen SSL among others once common attacks to...
modern supply chainreal world impactcso onlineattacks
https://blog.pypi.org/posts/2026-04-02-incident-report-litellm-telnyx-supply-chain-attack/
Incident Report: LiteLLM/Telnyx supply-chain attacks, with guidance - The Python Package Index Blog
Python Package Index shares insights and provides guidance following LiteLLM/Telnyx supply-chain attacks
supply chain attackspython package indexincident reportlitellmtelnyx
https://help.accuknox.com/use-cases/knoxguard-supply-chain/
Mitigate Supply Chain Attacks with KnoxGuard -
Learn how to mitigate supply chain attacks with KnoxGuard by blocking deployments that use images from untrusted registries.
supply chain attacksmitigate
https://finance.yahoo.com/news/2025-cybersecurity-trends-vipre-smes-090000239.html
2025 Cybersecurity Trends from VIPRE: SMEs a Target and AI Malware to Fuel Supply Chain Attacks,...
Jan 7, 2025 - 2024 saw increasingly sophisticated cybersecurity threats as criminals leveraged all forms of AI to create difficult-to-detect phishing attacks, deepfakes, and...
supply chain attacks2025 cybersecuritytrendsvipresmes
https://www.helpnetsecurity.com/2026/03/25/teampcp-supply-chain-attacks/
LiteLLM PyPI packages compromised in expanding TeamPCP supply chain attacks - Help Net Security
Mar 27, 2026 - A slew of supply chain attacks against popular open source tools and packages appears to have been orchestrated by TeamPCP cybercriminals.
teampcp supply chainlitellm pypipackages compromisedattacks helpexpanding
https://cointelegraph.com/news/crypto-hacks-2026-certik-blockchain-investigator-attack-vectors
Phishing, Deepfakes, Supply Chain Attacks To Fuel 2026's Biggest Crypto Hacks
CertiK’s senior blockchain investigator says real-time deepfakes, supply chain compromises and cross-chain vulnerabilities will dominate crypto exploits in...
supply chain attacksfuel 2026biggest cryptophishingdeepfakes
https://obsidian.md/blog/less-is-safer/
Less is safer: how Obsidian reduces the risk of supply chain attacks - Obsidian
Supply chain attacks are malicious updates that sneak into open source code used by many apps. Here’s how we design Obsidian to ensure that the app is a secure...
supply chain attackslesssaferobsidianreduces
https://cloudflare.tv/shows/security-week/evolving-protections-against-browser-supply-chain-attacks/DvNkBPaw
🔒 Evolving protections against browser supply chain attacks - Cloudflare TV
Welcome to Cloudflare Security Week 2023! During this year's Security Week, we'll make Zero Trust even more accessible and enterprise-ready, better protect...
supply chain attackscloudflare tvevolvingprotectionsbrowser
https://www.activestate.com/resources/videos/the-rise-of-software-supply-chain-attacks/
The Rise of Software Supply Chain Attacks - ActiveState
Jan 15, 2025 - Explore the rise of software supply chain attacks, open source vulnerabilities, and security measures on the ActiveState Podcast.
software supply chainriseattacksactivestate
https://www.sans.org/webcasts/when-trusted-senders-become-threats-stopping-bec-supply-chain-attacks-selflearning-ai
When Trusted Senders Become Threats: Stopping BEC and Supply Chain Attacks with Self‑Learning AI |...
Your biggest email threats aren’t strangers, they’re trusted partners whose accounts have been compromised. Discover how self‑learning AI uncovers subtle...
supply chain attackstrustedsendersbecomethreats
https://circleci.com/docs/guides/security/security-supply-chain/
Protecting against supply chain attacks - CircleCI Docs
supply chain attackscircleci docsprotecting
https://arstechnica.com/information-technology/2019/08/the-year-long-rash-of-supply-chain-attacks-against-open-source-is-getting-worse/
The year-long rash of supply chain attacks against open source is getting worse - Ars Technica
Aug 21, 2019 - Backdoors snuck into 12 OSS packages were downloaded hundreds of thousands of times.
supply chain attacksyear longopen sourcegetting worsears technica
https://www.itprotoday.com/attacks-breaches/china-s-silk-typhoon-apt-shifts-to-it-supply-chain-attacks
China's Silk Typhoon APT Shifts to IT Supply Chain Attacks
Mar 6, 2025 - The nation-state threat group has been breaching providers of remote management tools, identity management providers, and other IT companies to access networks...
supply chain attackssilk typhoonchinaaptshifts
https://www.infoworld.com/article/4151016/context-hub-vulnerable-to-supply-chain-attacks-says-tester.html
Context Hub vulnerable to supply chain attacks, says tester | InfoWorld
Mar 27, 2026 - The new AI tool highlights the risk when developers point their bots at non-authoritative information sources, with predictable consequences.
supply chain attackscontexthubvulnerablesays
https://dev.to/soytuber/supply-chain-attacks-plague-npm-cloud-devs-expose-thousands-of-secrets-2aig
Supply Chain Attacks Plague npm, Cloud Devs Expose Thousands of Secrets - DEV Community
Apr 23, 2026 - Supply Chain Attacks Plague npm, Cloud Devs Expose Thousands of Secrets Today's... Tagged with security, cybersecurity, vulnerability.
supply chain attackscloud devsplaguenpmexpose
https://securelist.com/webinars/global-it-outages-and-supply-chain-attacks-2024s-lessons-and-tomorrows-cyberthreats/
KSB 2024: Global IT outages and supply chain attacks | Securelist
As part of the Kaspersky Security Bulletin 2024, this webinar delves into the risks posed by supply chain weaknesses and global IT disruptions.
supply chain attacks2024 globalksboutagessecurelist
https://www.sonatype.com/press-releases/sonatype-finds-700-average-increase-in-open-source-supply-chain-attacks
Sonatype Finds 700% Rise in Open Source Supply Chain Attacks
Early findings from Sonatype's 8th Software Supply Chain Report reveal a surge in cyberattacks on open source ecosystems.
open source supplychain attackssonatypefinds700
https://www.itsecuritypro.gr/to-breach-tis-evropaikis-epitropis-kai-to-neo-prosopo-ton-supply-chain-attacks/
Το breach της Ευρωπαϊκής Επιτροπής και το νέο πρόσωπο των supply chain attacks | SECURITY NEWS
Η πρόσφατη κυβερνοεπίθεση στην Ευρωπαϊκή Επιτροπή δεν είναι απλώς ένα ακόμη περιστατικό διαρροής δεδομένων. Αντίθετα, αποτελεί μια χαρακτηριστική ένδειξη της...
supply chain attackssecurity newsbreach
https://semgrep.dev/blog/2025/block-malicious-dependencies-with-semgrep-supply-chain/
Protect Against Open Source Malware Attacks with Semgrep Supply Chain | Semgrep
Malicious dependency detection is now generally available for Semgrep Supply Chain customers. Practitioners can configure policies to automatically block these...
open source malwaresupply chainprotectattackssemgrep
https://www.forbes.com/sites/edwardsegal/2023/12/17/attacks-on-ships-in-red-sea-could-be-first-sign-of-a-supply-chain-crisis/?sh=24ce541b76a3
Attacks On Ships In Red Sea Could Be First Sign Of A Supply Chain Crisis
Dec 21, 2023 - The recent attacks on ships in the Red Sea are an early warning sign that another international supply chain crisis could happen in the immediate future.
supply chain crisisred seafirst signattacksships
https://jfrog.com/blog/supply-chain-attackers-are-coming-for-your-agents/
JFrog Adds Protection from Attacks on Agentic Software Supply Chain
Apr 5, 2026 - The LiteLLM attack marks a shift in the SDLC: attackers are now targeting the AI agents developers rely on. Learn how to secure your agentic supply chain with...
software supply chainjfrogaddsprotectionattacks
https://onehack.st/t/killchain-a-unified-console-to-perform-the-kill-chain-stages-of-attacks/104420
Killchain | A Unified Console To Perform The "Kill Chain" Stages Of Attacks - Tools & Scripts -...
Sep 2, 2020 - What is “Kill Chain”? From Wikipedia: The term kill chain was originally used as a military concept related to the structure of an attack; consisting of target...
kill chaintools scriptsunifiedconsoleperform