Supply Chain Security News
Supply-chain security news: compromised dependencies, build-pipeline attacks and third-party software risk.
A supply-chain attack compromises a trusted upstream component (a software dependency, build pipeline or vendor tool) so the malicious code rides along into every downstream product that uses it. Compromised packages, build-system breaches and third-party risk disclosures land here. These incidents tend to have an outsized blast radius: a single compromised dependency can affect thousands of downstream projects.
Recent Supply Chain items
Other topics
CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.