Supply Chain Security News

Supply-chain security news — compromised dependencies, build-pipeline attacks and third-party software risk.

A supply-chain attack compromises a trusted upstream component — a software dependency, build pipeline or vendor tool — so the malicious code rides along into every downstream product that uses it. This feed tracks compromised packages, build-system breaches and third-party risk disclosures as they are reported. These incidents tend to have an outsized blast radius, since a single compromised dependency can affect thousands of downstream projects.

Recent Supply Chain items

CVE-2026-47229Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm_csrf_token` on every state-changing branch except `enable`. The `…
@cveNotify · Aug 12, 2026
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attackhttps://ift.tt/oInLJwD
@ctinow · Aug 12, 2026
CVE-2026-66832When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent use…
@cveNotify · Aug 11, 2026
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Targethttps://gbhackers.com/litellm-attack-shows-ai-infrastructure/
@PentestingNews · Aug 11, 2026
CVE-2026-73162Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /account/follow * /account/delete_notification * /account/mark_notification_re…
@cveNotify · Aug 11, 2026
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Adminshttps://ift.tt/0H9YpPh
@ctinow · Aug 11, 2026
CVE-2026-18245Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, develope…
@cveNotify · Aug 10, 2026
WordPress Supply Chain Attack Exploits BdThemes Plugins to Create Rogue Admin Accounts and Install Webshellshttps://gbhackers.com/wordpress-supply-chain-attack-exploits-bdthemes-plugins/
@PentestingNews · Aug 10, 2026
Russian Hackers Use AI Slopsquatting to Publish 700+ Malicious npm Packageshttps://gbhackers.com/russian-hackers-use-ai-slopsquatting/
@PentestingNews · Aug 8, 2026
CVE-2026-64655GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer…
@cveNotify · Aug 8, 2026
CVE-2026-60812Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15.…
@cveNotify · Aug 7, 2026
CVE-2026-60810Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15.…
@cveNotify · Aug 7, 2026
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealerhttps://ift.tt/gvhNFmQ
@ctinow · Aug 7, 2026
Nearly 800 malicious npm packages are delivering a cross-platform RAT and infostealer.The campaign targets Windows, macOS, and Linux, with WEL1DROPPER fetching platform-specific payloads and falling b…
@thehackernews · Aug 7, 2026
The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Riskshttps://thecyberexpress.com/tce-weekly-roundup-data-breaches-h1/
@PentestingNews · Aug 7, 2026
CVE-2026-54215Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the applic…
@cveNotify · Aug 7, 2026
CVE-2026-62516Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.15. Easily explo…
@cveNotify · Aug 7, 2026
CVE-2026-61041Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.15. Easily explo…
@cveNotify · Aug 7, 2026
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaignhttps://ift.tt/IebCcMv
@ctinow · Aug 7, 2026
Updoc Data Breach Exposes Patient Contact Information Following Third-Party Security Incidenthttps://thecyberexpress.com/updoc-data-breach/
@PentestingNews · Aug 7, 2026
Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attackshttps://gbhackers.com/critical-flaws-in-claude-code-gemini-cli-and-openai-codex/
@PentestingNews · Aug 7, 2026
TeamPCP’s trail goes back to 2020.Oligo links its recent AI botnet and software supply chain campaigns to earlier Redis attacks, connecting years of activity across Redis, Ray, Docker and React.How th…
@thehackernews · Aug 7, 2026
CVE-2026-45623PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses…
@cveNotify · Aug 7, 2026
CVE-2026-62241clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because G…
@cveNotify · Aug 6, 2026
CVE-2026-61266Vulnerability in the Oracle Supply Chain Globalization product of Oracle E-Business Suite (component: Copy Inventory Organization). Supported versions that are affected are 12.2.3-12.2.1…
@cveNotify · Aug 6, 2026
CVE-2026-19041A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the file src/controllers/packages.ts of th…
@cveNotify · Aug 6, 2026
CVE-2026-16954The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to…
@cveNotify · Aug 6, 2026
On-premise TeamCity is under attack.CISA says attackers are exploiting CVE-2026-63077 in the wild. The 9.8-rated flaw can let unauthenticated attackers run OS commands, putting stored credentials, bui…
@thehackernews · Aug 6, 2026
New npm Supply Chain Attack: Keyv & Mini Shai-Hulud Malware IoCs (DevSecOps Fix)https://ift.tt/imuJABc
@ctinow · Aug 6, 2026
CVE-2026-70617Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a…
@cveNotify · Aug 5, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.