https://thehackernews.com/2026/05/daemon-tools-supply-chain-attack.html
DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware
DAEMON Tools supply chain attack since April 8, 2026 infects signed installers, enabling targeted malware delivery globally.
supply chain attackdaemon toolscompromisesofficialinstallers
https://www.malwarebytes.com/blog/news/2026/03/axios-supply-chain-attack-chops-away-at-npm-trust?ref=christophermoravec.com
Axios supply chain attack chops away at npm trust | Malwarebytes
Mar 31, 2026 - Developers using the axios package from npm may have downloaded a malicous version that drops a Remote Access Trojan
supply chain attackaxioschopsawaynpm
https://www.trendmicro.com/pt_br/research/26/d/vercel-breach-oauth-supply-chain.html
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment...
Apr 20, 2026 - An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify...
supply chain attack
https://cloud.google.com/blog/topics/threat-intelligence/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor?hl=en
SolarWinds Supply Chain Attack Uses SUNBURST Backdoor | Google Cloud Blog
A highly evasive attacker leverages a supply chain attack trojanizing SolarWinds Orion business software updates in order to distribute SUNBURST malware.
supply chain attackgoogle cloudsolarwindsusessunburst
https://www.kaspersky.com/blog/copay-supply-chain-attack/24786/
A supply-chain attack against an open source library | Kaspersky official blog
A supply-chain attack against Copay cryptowallets through an open-source library enables bitcoin theft.
supply chain attackopen source library
https://thehackernews.com/2026/03/glassworm-supply-chain-attack-abuses-72.html?version=meter+at+null
GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers
GlassWorm campaign used 72 malicious Open VSX extensions and infected 151 GitHub repositories, enabling stealth supply-chain attacks on developers.
supply chain attack
https://www.trendmicro.com/en_gb/research/23/g/supply-chain-attack-targeting-pakistani-government-delivers-shad.html
Possible Supply Chain Attack Targeting Pakistani Government Delivers Shadowpad | Trend Micro (UK)
Jul 14, 2023 - We recently found that an MSI installer built by the National Information Technology Board (NITB), a Pakistani government entity, delivered a Shadowpad sample,...
supply chain attack
https://www.eset.com/in/about/newsroom/press-releases/research/eset-discovers-operation-signsight-supply-chain-attack-against-a-certification-authority-in-southea/
ESET discovers operation SignSight: Supply-chain attack against a certification authority in...
Your source for cyber security news, reviews, expert opinions and upcoming events.
supply chain attack
https://thehackernews.com/2021/02/dependency-confusion-supply-chain.html
Dependency Confusion Supply-Chain Attack Hit Over 35 High-Profile Companies
A Novel Dependency Confusion Supply-Chain Attack Hit Over 35 Organizations
supply chain attackdependency confusionhigh profile
https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/
GitHub Actions Supply Chain Attack: A Targeted Attack on Coinbase Expanded to the Widespread...
Apr 3, 2025 - A compromise of the GitHub action tj-actions/changed-files highlights how attackers could exploit vulnerabilities in third-party actions to compromise supply...
supply chain attack
https://thehackernews.com/2020/12/software-supply-chain-attack-hits.html
Software Supply-Chain Attack Hits Vietnam Government Certification Authority
Supply Chain Attack Hit Vietnam Government Certification Authority Users With Trojanized Digital Signature Toolkit
software supply chaingovernment certificationattackhitsvietnam
https://vercel.com/changelog/s1ngularity-supply-chain-attack-in-nx-packages
s1ngularity: supply chain attack in Nx packages - Vercel
A critical vulnerability was published in Nx and some of its supporting libraries. Vercel builds are safe from this vulnerability by default.
supply chain attacknxpackagesvercel
https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/?pdf=download&lg=en&_wpnonce=86e71d14ac
GitHub Actions Supply Chain Attack: A Targeted Attack on Coinbase Expanded to the Widespread...
Apr 3, 2025 - A compromise of the GitHub action tj-actions/changed-files highlights how attackers could exploit vulnerabilities in third-party actions to compromise supply...
supply chain attack
https://rodtrent.substack.com/p/security-check-in-quick-hits-escan
Security Check-in Quick Hits: eScan Supply Chain Attack, SonicWall Ransomware Fallout, Microsoft...
For February 3, 2026
supply chain attack
https://unit42.paloaltonetworks.com/ja/tag/software-supply-chain-attack-ja/
software supply-chain attack Archives - Unit 42
software supply chainattackarchivesunit
https://thehackernews.com/2024/03/hackers-hijack-github-accounts-in.html
Hackers Hijack GitHub Accounts in Supply Chain Attack Affecting Top-gg and Others
Sophisticated attack targets Discord bot site Top.gg + devs. Attackers stole browser cookies, pushed malicious code, and created fake Python packages.
supply chain attack
https://www.sophos.com/ja-jp/blog/php-community-sidesteps-its-third-supply-chain-attack-in-three-years
PHP community sidesteps its third supply chain attack in three years | SOPHOS
Third time lucky! (The first two times were lucky, too, luckily.)
supply chain attack
https://www.proofpoint.com/it/threat-reference/supply-chain-attack
Supply Chain Attack: definizione ed esempi | Proofpoint IT
Jun 17, 2025 - Durante un attacco alla supply chain i criminali informatici rubano dati e installano ransomware. Continua a leggere per scoprire come difenderti!
supply chain attackdefinizioneedesempiproofpoint
https://rodtrent.substack.com/p/security-check-in-quick-hits-notepad
Security Check-in Quick Hits: Notepad++ Supply Chain Attack, Microsoft Office Zero-Day...
For February 4, 2026
supply chain attack
https://www.trendmicro.com/it_it/research/26/d/vercel-breach-oauth-supply-chain.html
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment...
Apr 20, 2026 - An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify...
supply chain attack
https://thehackernews.com/2022/03/a-threat-actor-dubbed-red-lili-has-been.html
A Large-Scale Supply Chain Attack Distributed Over 800 Malicious NPM Packages
Researchers uncover an ongoing large-scale supply-chain attack which exploits dependency confusion attacks against the NPM package repository.
supply chain attacklarge scale
https://advisories.gitlab.com/npm/@lightdash/cli/GHSA-3hfp-gqgh-xc5g/
Axios supply chain attack - dependency in @lightdash/cli may resolve to compromised axios versions...
GHSA-3hfp-gqgh-xc5g Axios supply chain attack - dependency in @lightdash/cli may resolve to compromised axios versions: A supply chain attack on the axios npm...
supply chain attack
https://unit42.paloaltonetworks.com/model-namespace-reuse/?pdf=download&lg=en&_wpnonce=949b5ed951
Model Namespace Reuse: An AI Supply-Chain Attack Exploiting Model Name Trust
Sep 3, 2025 - Model namespace reuse is a potential security risk in the AI supply chain. Attackers can misuse platforms like Hugging Face for remote code execution.
ai supply chainmodelnamespacereuse
https://www.computerweekly.com/news/252514016/Toyota-production-to-resume-after-supply-chain-attack
Toyota production to resume after supply chain attack | Computer Weekly
Toyota production has been set back by over 10,000 vehicles following a cyber attack on a critical components supplier in Japan.
supply chain attacktoyotaproductionresumecomputer
https://www.bitdefender.com/en-us/business/infozone/what-is-a-supply-chain-attack
What is a Supply Chain Attack? - Bitdefender InfoZone
Discover what a supply chain attack is, how it operates, and the essential strategies to protect your business from these emerging cybersecurity threats.
what is a supply chainattackbitdefenderinfozone
https://www.trendmicro.com/en/research/26/d/vercel-breach-oauth-supply-chain.html
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment...
Apr 20, 2026 - An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify...
supply chain attack
https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
Shai Hulud 2.0 Strikes Again: Malware Supply-Chain Attack Hits Zapier & ENS Domains
Mar 17, 2026 - The threat actor behind “Shai Hulud 2.0” launched a new malware campaign compromising the supply chain of Zapier, ENS Domains and more — exposing secrets,...
https://thehackernews.com/2022/05/malicious-npm-packages-target-german.html?m=1
Malicious NPM Packages Target German Companies in Supply Chain Attack
Researchers uncover a new NPM supply-chain attack campaign in which attackers distribute malicious packages to compromise leading German companies.
npm packagesgerman companiesin supplymalicioustarget
https://www.trendmicro.com/ko_kr/research/26/c/axios-npm-package-compromised.html
Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly...
https://hackaday.com/2025/03/21/this-week-in-security-the-github-supply-chain-attack-ransomware-decryption-and-paragon/
This Week In Security: The Github Supply Chain Attack, Ransomware Decryption, And Paragon | Hackaday
Mar 21, 2025 - Last Friday Github saw a supply chain attack hidden in a popular Github Action. To understand this, we have to quickly cover Continuous Integration (CI) and...
this week in security
https://thehackernews.com/2022/10/comm100-chat-provider-hijacked-to.html
Comm100 Chat Provider Hijacked to Spread Malware in Supply Chain Attack
Chinese hackers are believed to be behind a new supply chain attack that hijacked the Comm100 Live Chat application to spread a JavaScript backdoor.
chat providerin supplyhijacked
https://www.trendmicro.com/fr_fr/research/26/c/axios-npm-package-compromised.html
Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly...
https://www.trendmicro.com/es_mx/research/26/c/axios-npm-package-compromised.html
Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly...