Supply Chain Security News
Supply-chain security news — compromised dependencies, build-pipeline attacks and third-party software risk.
A supply-chain attack compromises a trusted upstream component — a software dependency, build pipeline or vendor tool — so the malicious code rides along into every downstream product that uses it. This feed tracks compromised packages, build-system breaches and third-party risk disclosures as they are reported. These incidents tend to have an outsized blast radius, since a single compromised dependency can affect thousands of downstream projects.
Recent Supply Chain items
Other topics
CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.