Sponsor of the Day:
Jerkmate
https://securityaffairs.com/189856/hacking/44-aqua-security-repositories-defaced-after-trivy-supply-chain-breach.html
44 Aqua Security repositories defaced after Trivy supply chain breach
Mar 24, 2026 - Malicious Trivy images on Docker Hub spread infostealer malware, exposing developers after a supply chain attack.
trivy supply chainaqua security44repositoriesdefaced
https://fieldeffect.com/blog/vercel-supply-chain-breach-ai-tool
Vercel confirms supply-chain breach linked to third-party AI tool
Apr 20, 2026 - Vercel confirms a supply-chain breach tied to a third-party AI tool, exposing risks in OAuth integrations, environment variables, and enterprise security...
third party aivercel confirmssupply chainbreach linkedtool
https://www.databreachtoday.com/dermatology-clinic-chain-breach-affects-24-million-a-17074
Dermatology Clinic Chain Breach Affects 2.4 Million
Forefront Dermatology S.C., a Wisconsin-based dermatology practice with affiliated offices in 21 states plus Washington, D.C., is notifying 2.4 million...
2 4 milliondermatology clinicchain breachaffects
https://www.networkworld.com/article/4154185/cert-eu-blames-trivy-supply-chain-attack-for-europa-eu-data-breach-2.html
CERT-EU blames Trivy supply chain attack for Europa.eu data breach | Network World
Apr 3, 2026 - Attackers exploited a vulnerability scanner to steal 350GB of data that they then leaked on the dark web.
cert eu blamestrivy supply chaineuropa data breachnetwork worldattack
https://material.security/resources/healthcares-email-breach-problem-is-a-supply-chain-problem
Healthcare's Email Breach Problem Is a Supply Chain Problem | Material Security
The second in a series analyzing HIPAA breach data from the HHS Office for Civil Rights.
supply chainmaterial securityhealthcareemailbreach
https://www.seqrite.com/blog/google-salesforce-breach-unc6040-threat-research/
Google Salesforce Breach: A Deep dive into the chain and extent of the compromise
Explore the Google Salesforce breach by UNC6040, a cyber attack blending vishing and OAuth app abuse. Learn how the ShinyHunters group stole business data, the...
salesforce breachdeep divegooglechainextent
https://community.gurucul.com/articles/ThreatResearch/LiteLLM-Supply-Chain-Compromise-15-4-2026
LiteLLM Supply Chain Compromise: Downstream Impact Analysis with Mercor Breach Case Study |...
The supply chain compromise involving LiteLLM demonstrates how attackers, potentially leveraging social engineering tactics, injected malicious code that...
litellm supply chainimpact analysiscase studycompromisedownstream
https://www.techtarget.com/searchsecurity/news/252499956/Codecov-breach-raises-concerns-about-software-supply-chain
Codecov breach raises concerns about software supply chain | TechTarget
After a Codecov breach was disclosed on April 15, new information has turned the initial incident into a full-blown supply chain attack.
software supply chainbreach raisescodecovconcernstechtarget
https://www.obsidiansecurity.com/blog/the-vercel-breach-and-the-growing-saas-supply-chain-challenge
The Vercel Breach and the Growing SaaS Supply Chain Challenge
vercel breachgrowing saassupply chainchallenge
https://www.infoworld.com/article/4154187/cert-eu-blames-trivy-supply-chain-attack-for-europa-eu-data-breach-3.html
CERT-EU blames Trivy supply chain attack for Europa.eu data breach | InfoWorld
Apr 3, 2026 - Attackers exploited a vulnerability scanner to steal 350GB of data that they then leaked on the dark web.
cert eu blamestrivy supply chaineuropa data breachattackinfoworld
https://devtalk.com/t/the-vercel-breach-oauth-supply-chain-attack-exposes-the-hidden-risk-in-platform-environment-variables/242279
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment...
An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify...
supply chain attackvercel breachexposes hiddenplatform environmentoauth
https://hashnode.com/posts/trizetto-healthcare-breach-patient-data-exposure-attack-chain-ttps/69ad7b6c34565578f04e34e7
Discussion on "TriZetto Healthcare Breach: Patient Data Exposure Attack Chain TTPs" | Hashnode
trizetto healthcarepatient dataattack chaindiscussionbreach
https://www.reco.ai/blog/vercel-context-ai-breach
Vercel Breach: How Context AI Became the Supply Chain
Vercel’s April 2026 breach began wit§h a compromised OAuth token from Context AI. Here’s the full attack chain and what security teams should do now.
vercel breachcontext aisupply chainbecame
https://www.trendmicro.com/en_gb/research/26/d/vercel-breach-oauth-supply-chain.html
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment...
An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defences and amplify...
supply chain attackvercel breachexposes hiddenplatform environmentoauth
https://www.cbsnews.com/news/wawa-data-breach-convenience-store-chain-discloses-9-month-breach-potentially-affecting-credit-card-all-locations/
Wawa data breach: Convenience store chain discloses 9-month data breach potentially affecting...
Dec 20, 2019 - The breach exposed customers' credit and debit card numbers, as well as expiration dates and cardholder names.
convenience store chaindata breach9 monthpotentially affectingwawa
https://www.comparitech.com/news/north-carolina-car-dealership-chain-hacked-breach-claimed-by-ransomware-gang/
North Carolina car dealership chain hacked, breach claimed by ransomware gang - Comparitech
Jan 3, 2025 - North Carolina car dealer Modern Auto notified people about a July 2024 data breach claimed by ransomware group BlackByte.
north carolina carransomware gangdealershipchainhacked
https://fedtechmagazine.com/article/2026/04/supply-chain-breach-vector-data-recovery-power-move
The Supply Chain Is the Breach Vector. Data Recovery Is the Power Move. | FedTech Magazine
Apr 27, 2026 - Federal agencies must keep a watchful eye and implement zero trust.
supply chainvector datapower movefedtech magazinebreach
https://www.csoonline.com/article/4154176/cert-eu-blames-trivy-supply-chain-attack-for-europa-eu-data-breach.html
CERT-EU blames Trivy supply chain attack for Europa.eu data breach | CSO Online
Apr 3, 2026 - Attackers exploited a vulnerability scanner to steal 350GB of data that they then leaked on the dark web.
cert eu blamestrivy supply chaineuropa data breachcso onlineattack
https://www.itsecuritypro.gr/to-breach-tis-evropaikis-epitropis-kai-to-neo-prosopo-ton-supply-chain-attacks/
Το breach της Ευρωπαϊκής Επιτροπής και το νέο πρόσωπο των supply chain attacks | SECURITY NEWS
Η πρόσφατη κυβερνοεπίθεση στην Ευρωπαϊκή Επιτροπή δεν είναι απλώς ένα ακόμη περιστατικό διαρροής δεδομένων. Αντίθετα, αποτελεί μια χαρακτηριστική ένδειξη της...
supply chain attackssecurity newsbreach