Supply Chain Security News

Supply-chain security news — compromised dependencies, build-pipeline attacks and third-party software risk.

A supply-chain attack compromises a trusted upstream component — a software dependency, build pipeline or vendor tool — so the malicious code rides along into every downstream product that uses it. This feed tracks compromised packages, build-system breaches and third-party risk disclosures as they are reported. These incidents tend to have an outsized blast radius, since a single compromised dependency can affect thousands of downstream projects.

Recent Supply Chain items

CVE-2026-18056 The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the a…
@cveNotify · Sep 6, 2026
CVE-2026-50237 A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary UR…
@cveNotify · Sep 5, 2026
Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security https://gbhackers.com/chainguard-hits-1-billion-build-manifests/
@PentestingNews · Sep 5, 2026
CVE-2026-84936 The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated bill…
@cveNotify · Sep 5, 2026
CVE-2026-85700 Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers with basic au…
@cveNotify · Sep 4, 2026
CVE-2026-85061 MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while remove…
@cveNotify · Sep 3, 2026
Organizations are increasingly relying on AI-generated and third-party code across the software supply chain. But once that code is compiled into a stripped binary, much of the original source context…
@thehackernews · Sep 3, 2026
Shai-Hulud now checks 469 locations for credentials.Earlier variants checked 189. The worm now scans developer environments, CI/CD tooling, cloud configs, and AI tool settings. Stolen publishing token…
@thehackernews · Sep 3, 2026
CVE-2026-79754 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. From version 1.6.19 to before version 1.17.2, Nuclio's Dashboard build pipeline does not sanitize the spec.b…
@cveNotify · Sep 2, 2026
Firefox for iPhone Adds Built-In Ad Blocker to Block Third-Party Ads and Trackers https://gbhackers.com/firefox-for-iphone-adds-built-in-ad-blocker/
@PentestingNews · Sep 2, 2026
CVE-2026-8151 The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into chang…
@cveNotify · Sep 2, 2026
ArrayRef Supply Chain Attack: How a Compromised Rust Crate Delivered Malware at Build Time https://ift.tt/ufHgKRc
@ctinow · Sep 1, 2026
Malicious npm Package Steals GitHub, Cloud, and CI/CD Secrets and Spreads to Other Packages https://gbhackers.com/npm-supply-chain-attack-2/
@PentestingNews · Sep 1, 2026
CVE-2026-19032 jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a st…
@cveNotify · Sep 1, 2026
CVE-2026-82393 pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/…
@cveNotify · Aug 31, 2026
CVE-2026-82392 pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name…
@cveNotify · Aug 31, 2026
CVE-2026-53507 oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request. Before version 0.0.51, the oasdiff actions resolved external $r…
@cveNotify · Aug 31, 2026
CVE-2026-16104 A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management.…
@cveNotify · Aug 31, 2026
CVE-2026-68821 Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. 🎖
@cveNotify · Aug 29, 2026
CVE-2026-81729 Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs/api/class/api_documents.class.php calls dol_check_secure_access_…
@cveNotify · Aug 28, 2026
CVE-2026-81719 openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in p…
@cveNotify · Aug 28, 2026
CVE-2026-21752 HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented securi…
@cveNotify · Aug 28, 2026
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more https://ift.tt/gKpTwXQ
@ctinow · Aug 28, 2026
CVE-2026-81729 Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs/api/class/api_documents.class.php calls dol_check_secure_access_…
@cveNotify · Aug 27, 2026
CVE-2026-71051 Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploita…
@cveNotify · Aug 27, 2026
CVE-2026-71050 Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploita…
@cveNotify · Aug 27, 2026
CVE-2026-71049 Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploita…
@cveNotify · Aug 27, 2026
CVE-2026-81719 openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in p…
@cveNotify · Aug 27, 2026
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks https://ift.tt/vHjOef5
@ctinow · Aug 27, 2026
CVE-2026-32593 Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through th…
@cveNotify · Aug 26, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.