Supply Chain Security News

Supply-chain security news: compromised dependencies, build-pipeline attacks and third-party software risk.

A supply-chain attack compromises a trusted upstream component (a software dependency, build pipeline or vendor tool) so the malicious code rides along into every downstream product that uses it. Compromised packages, build-system breaches and third-party risk disclosures land here. These incidents tend to have an outsized blast radius: a single compromised dependency can affect thousands of downstream projects.

Recent Supply Chain items

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M 🖋️ The attacker who stole about 388 million from the cryptocurrency exchange Bitget gained access through a vulnerabilit…
@cibsecurity · Sep 28, 2026
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M https://ift.tt/Jt310rw
@ctinow · Sep 28, 2026
Bitget says an attacker exploited a third-party security product flaw, stole high-level internal credentials, and used them in a $388M theft. The wallet system accepted fraudulent withdrawal commands…
@thehackernews · Sep 28, 2026
The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches https://ift.tt/DcZdCEh
@ctinow · Sep 28, 2026
CVE-2026-79708 GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed…
@cveNotify · Sep 28, 2026
CVE-2026-18825 An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request. 🎖
@cveNotify · Sep 28, 2026
Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure https://cloud.google.com/blog/topics/threat-intelligence/hardening-code-pipelines-and-ci-cd-infrastructure
@secharvester · Sep 28, 2026
CVE-2026-101044 pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not validate dependency alias/name paths taken from a lo…
@cveNotify · Sep 27, 2026
CVE-2026-100747 Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and ove…
@cveNotify · Sep 27, 2026
GitHub Actions re-enabled with Mini Shai-Hulud payload still active Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained…
@bleepingcomputer · Sep 26, 2026
OpenAI's AI agents accidentally uploaded user-provided images to third-party sites OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out rese…
@bleepingcomputer · Sep 26, 2026
OpenAI's AI agents accidentally uploaded user-provided images to third-party sites https://ift.tt/4t6xGFw
@ctinow · Sep 26, 2026
CVE-2026-100598 OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction intended to resolve a structured approval request could in…
@cveNotify · Sep 26, 2026
CVE-2026-100597 OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdi…
@cveNotify · Sep 26, 2026
CVE-2026-100593 OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An authorized no…
@cveNotify · Sep 26, 2026
CVE-2026-100585 OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge.…
@cveNotify · Sep 26, 2026
CVE-2026-100580 OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution…
@cveNotify · Sep 26, 2026
Example Domains in Developer Docs Lead to ClickFix and Scams A domain that looks like disposable text in a software manual can still belong to somebody. Manifold Security found third-party[.]com servi…
@topcybersecurity · Sep 25, 2026
CVE-2026-84458 Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third…
@cveNotify · Sep 25, 2026
A widely used placeholder domain from developer docs third-party[.]com is now serving a ClickFix lure targeting Windows users. See the analysis and collect IOCs 👨💻 We analyzed the malicious script cha…
@anyrun_app · Sep 25, 2026
Attacks hidden in trusted infrastructure are designed to be detected late. ⚡ To close this gap, extend coverage to newly registered domains mimicking legitimate software keywords, unexpected code-sign…
@anyrun_app · Sep 25, 2026
CVE-2026-93577 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowe…
@cveNotify · Sep 25, 2026
CVE-2026-89078 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowe…
@cveNotify · Sep 25, 2026
CVE-2026-77321 TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiring trips:read…
@cveNotify · Sep 24, 2026
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content https://ift.tt/DHQEhjs
@ctinow · Sep 24, 2026
third-party[.]com is now serving Windows users a ClickFix lure disguised as a Cloudflare check.The domain is referenced as a placeholder across 1,700+ repositories. The lure copies a PowerShell comman…
@thehackernews · Sep 24, 2026
AI-assisted commits leak secrets at roughly twice the rate of human-written ones.Coding agents can read .env files and MCP configs, while the same credentials may persist across CI/CD, tickets, and co…
@thehackernews · Sep 24, 2026
Malicious npm Packages That Evade Defenses https://ift.tt/i1h0CVb
@ctinow · Sep 24, 2026
GitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD Jobs https://gbhackers.com/gitlab-email-token/
@PentestingNews · Sep 24, 2026
CVE-2026-93577 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowe…
@cveNotify · Sep 24, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.