ZCyberNews
中文

#supply-chain

56 articles

Over 85 articles published between April 12 and May 17, 2026, examine supply-chain security, with 15 critical and 49 high-severity incidents reported. Threat actors Lazarus Group, TeamPCP, and CanisterSprawl were observed targeting technology, software development, cryptocurrency, logistics, and manufacturing sectors globally, with particular impact across North America, Europe, Asia, and the United States. Key vulnerabilities include CVE-2026-1731, CVE-2026-45033, CVE-2026-39987, CVE-2026-41650, and CVE-2026-44664, reflecting a mix of critical and medium-severity flaws.

Grafana GitHub Token Breach Lets Attacker Download Full CodebaseHIGH
Industry News

Grafana GitHub Token Breach Lets Attacker Download Full Codebase

An attacker used a compromised GitHub token to download Grafana's entire private codebase. The company says no customer data was accessed and the incident involved an extortion...

3 min read
MCP Registry OIDC Flaw CVE-2026-44428 Lets Attackers Hijack GitHubMEDIUM
Vulnerabilities

MCP Registry OIDC Flaw CVE-2026-44428 Lets Attackers Hijack GitHub

CVE-2026-44428 (CVSS 4.7) in the MCP Registry before 1.7.6 lets attackers reuse stolen GitHub OIDC tokens across registry instances, enabling unauthorized server publishing and...

CVE-2026-44428
4 min read
fast-xml-builder Flaw CVE-2026-44664 Enables XML Injection viaMEDIUM
Vulnerabilities

fast-xml-builder Flaw CVE-2026-44664 Enables XML Injection via

CVE-2026-44664 (CVSS 6.1) in fast-xml-builder lets attackers break out of XML comments and inject arbitrary content via triple-dash sequences; fixed in version 1.1.6.

CVE-2026-44664CVE-2026-41650
4 min read
GitHub Copilot CLI Flaw CVE-2026-45033 Enables RCE via Malicious ReposCRITICAL
Vulnerabilities

GitHub Copilot CLI Flaw CVE-2026-45033 Enables RCE via Malicious Repos

CVE-2026-45033 (CVSS 9.8) in GitHub Copilot CLI before 1.0.43 lets attackers achieve remote code execution by embedding a malicious bare git repository in a project directory.

CVE-2026-45033
3 min read
Foxconn Confirms Ransomware Attack on North American FactoriesHIGH
Industry News

Foxconn Confirms Ransomware Attack on North American Factories

Nitrogen ransomware gang claims 8TB of stolen data from Foxconn's North American factories, including technical files from major tech clients.

2 min readNitrogen
TeamPCP Hijacks TanStack CI/CD, Poisons 170+ NPM/PyPI PackagesCRITICAL
Threat Intel

TeamPCP Hijacks TanStack CI/CD, Poisons 170+ NPM/PyPI Packages

TeamPCP chained three GitHub Actions flaws to hijack TanStack's CI/CD, publishing 84 malicious artifacts across 42 packages.

4 min readTeamPCP
FCC Delays Ban on Security Updates for Foreign-Made Routers to 2029MEDIUM
Industry News

FCC Delays Ban on Security Updates for Foreign-Made Routers to 2029

The FCC extended the deadline for banning software updates on foreign-made routers from March 2027 to January 2029, citing public interest concerns and industry pushback.

3 min read
SailPoint Discloses GitHub Repo Breach via Third-Party AppHIGH
Industry News

SailPoint Discloses GitHub Repo Breach via Third-Party App

SailPoint reported to the SEC that attackers accessed a subset of its GitHub repositories on April 20 via a third-party app vulnerability.

3 min read
Fake OpenAI Repo on Hugging Face Pushes Rust InfostealerHIGH
Malware

Fake OpenAI Repo on Hugging Face Pushes Rust Infostealer

A typosquatted OpenAI repository reached #1 on Hugging Face with 244,000 downloads, delivering a Rust-based infostealer that targets browser credentials, crypto wallets, and VPN...

3 min readWinos 4.0
Cyber Tax Raises Consumer Prices After Breaches, Podcast WarnsMEDIUM
Industry News

Cyber Tax Raises Consumer Prices After Breaches, Podcast Warns

Malwarebytes Lock and Code podcast: Eva Velasquez details how small business cyberattacks create a 'cyber tax' that raises prices for all consumers — no sector immune.

2 min read
FBI Warns Cybercriminals Driving $725M Cargo Theft SurgeHIGH
Industry News

FBI Warns Cybercriminals Driving $725M Cargo Theft Surge

FBI warns cargo theft losses hit $725M in US and Canada in 2025, driven by cybercriminals exploiting logistics IT systems to intercept shipments and redirect loads.

2 min read
PyTorch Lightning Compromised in PyPI Supply Chain AttackCRITICAL
Malware

PyTorch Lightning Compromised in PyPI Supply Chain Attack

Threat actors pushed malicious PyTorch Lightning versions 2.6.2 and 2.6.3 to PyPI on April 30, 2026, stealing credentials via a typosquatted dependency — Aikido Security, Socket,…

2 min read
Russian GRU Targets Western Logistics, Tech Firms in Ukraine AidHIGH
Threat Intel

Russian GRU Targets Western Logistics, Tech Firms in Ukraine Aid

CISA warns Russian GRU hackers target Western logistics and tech firms supporting Ukraine aid since 2022.

2 min readGRU
Vimeo Breach Tied to Anodot Vendor Hack, No Video Data ExposedMEDIUM
Industry News

Vimeo Breach Tied to Anodot Vendor Hack, No Video Data Exposed

Vimeo attributed a security incident to a breach at analytics vendor Anodot; hackers accessed internal systems but not video content, logins, or payment data.

2 min read
Vercel Breach via Context.ai OAuth Token TheftHIGH
Industry News

Vercel Breach via Context.ai OAuth Token Theft

Vercel disclosed a breach after stolen OAuth tokens from Context.ai enabled unauthorized access to internal systems via a connected app. No customer data exposed.

2 min read
Axios npm Supply Chain Attack Delivers Cross-Platform RATCRITICAL
Malware

Axios npm Supply Chain Attack Delivers Cross-Platform RAT

Elastic Security Labs details a supply chain compromise of the axios npm package that deployed a unified RAT across platforms, impacting an unknown number of downstream…

2 min read
ESET: March 2026 Cyber Threats Show Resilience GapsMEDIUM
Industry News

ESET: March 2026 Cyber Threats Show Resilience Gaps

ESET's Tony Anscombe warns that March 2026 attacks — including ransomware, supply chain compromises, and AI-driven phishing — reveal systemic gaps in organizational…

2 min read
Itron Breach: Utility Firm Discloses Internal IT Network IntrusionHIGH
Industry News

Itron Breach: Utility Firm Discloses Internal IT Network Intrusion

Itron disclosed a cybersecurity incident in an SEC 8-K filing: an unauthorized third party accessed internal IT systems.

2 min read
State Hackers Target Mining Sector Over Critical Minerals SupplyMEDIUM
Threat Intel

State Hackers Target Mining Sector Over Critical Minerals Supply

Recorded Future warns state-sponsored cyber operations increasingly target mining firms for critical minerals and rare earth elements, as China's refining dominance reshapes…

2 min read
26 Fake Crypto Wallet Apps on Apple App Store Steal Seed PhrasesHIGH
Threat Intel

26 Fake Crypto Wallet Apps on Apple App Store Steal Seed Phrases

Kaspersky found 26 malicious apps on the Apple App Store since fall 2025 that impersonate wallets like MetaMask and Coinbase to steal recovery phrases and private keys via…

2 min read
Tropic Trooper Uses Trojanized SumatraPDF to Deploy AdaptixC2HIGH
Threat Intel

Tropic Trooper Uses Trojanized SumatraPDF to Deploy AdaptixC2

Zscaler ThreatLabz links Tropic Trooper to a campaign using trojanized SumatraPDF to drop AdaptixC2 Beacon and abuse VS Code tunnels for remote access, targeting Chinese-speaking…

2 min readTropic Trooper
CanisterSprawl Worm Hijacks npm Packages, Steals Developer TokensHIGH
Malware

CanisterSprawl Worm Hijacks npm Packages, Steals Developer Tokens

The CanisterSprawl supply chain worm hijacks npm packages, uses stolen developer tokens to self-propagate, and exfiltrates data to an ICP canister, according to Socket and…

2 min readCanisterSprawl
Checkmarx KICS Supply-Chain Breach Hits Docker, VS CodeCRITICAL
Malware

Checkmarx KICS Supply-Chain Breach Hits Docker, VS Code

Attackers compromised Checkmarx KICS Docker images and VS Code extensions to steal cloud credentials, API keys, and source code from developer environments.

3 min read
North Korean Hackers Steal $12 Million in Crypto via TrojanizedHIGH
Malware

North Korean Hackers Steal $12 Million in Crypto via Trojanized

North Korean hackers siphoned over $12 million from crypto users in Q1 2026 using trojanized trading apps like CoinStats and TradingView AI Agent to steal recovery phrases and…

2 min readLazarus Group
Agentic AI Systems Introduce Novel Enterprise Security RisksHIGH
AI Security

Agentic AI Systems Introduce Novel Enterprise Security Risks

Recorded Future warns that autonomous 'agentic' AI systems, now being integrated into enterprise software, create new attack surfaces for prompt injection, data poisoning, and…

3 min read
North Korean Fake Job Scams Spread Malware via 'Contagious Interview'HIGH
Threat Intel

North Korean Fake Job Scams Spread Malware via 'Contagious Interview'

North Korean operatives use a 'contagious interview' tactic, where a compromised developer's GitHub repo spreads RATs to other job seekers.

3 min readLazarus Group
Bomgar RMM Exploit Fuels Ransomware and Supply Chain AttacksCRITICAL
Vulnerabilities

Bomgar RMM Exploit Fuels Ransomware and Supply Chain Attacks

CVE-2026-1731, a critical 9.8 CVSS flaw in BeyondTrust's Bomgar RMM, is being actively exploited to deploy ransomware and compromise IT service providers in global supply chain attacks.

CVE-2026-1731
3 min read
Malicious Crypto Apps Hijack Recovery Phrases from Apple App StoreHIGH
Malware

Malicious Crypto Apps Hijack Recovery Phrases from Apple App Store

Apple removed 45 malicious cryptocurrency apps from its App Store after they stole recovery phrases and private keys from users, mimicking legitimate wallets like MetaMask and Coinbase.

3 min read
CISA Warns Axios npm Package Compromised in Supply Chain AttackCRITICAL
Threat Intel

CISA Warns Axios npm Package Compromised in Supply Chain Attack

CISA alerts that the Axios npm package, with over 60 million weekly downloads, was compromised in a supply chain attack, injecting malicious code into downstream applications.

3 min read
GitHub Issue Notifications Hijacked for Developer Phishing via OAuth AppsHIGH
Threat Intel

GitHub Issue Notifications Hijacked for Developer Phishing via OAuth Apps

Threat actors are using GitHub's trusted notification system to phish developers, pushing malicious OAuth apps that steal account data and hijack repositories. The campaign exploits the platform's own infrastructure to bypass traditional email security.

3 min read
Vercel Breach Exposes Customer Credentials via Compromised AI ToolHIGH
Threat Intel

Vercel Breach Exposes Customer Credentials via Compromised AI Tool

Vercel confirms a breach exposing limited customer credentials after attackers compromised an employee's account via a third-party AI tool, Context.ai. The cloud platform is resetting passwords and API tokens for affected users.

3 min read
108 Malicious Chrome Extensions Hijack Browsers, Steal Google and Telegram DataHIGH
Malware

108 Malicious Chrome Extensions Hijack Browsers, Steal Google and Telegram Data

Socket identified 108 malicious Chrome extensions that infected 20,000 users, stealing Google and Telegram session cookies and injecting ads via a shared command-and-control server.

3 min read
TeamPCP Supply Chain Attack Fuels Payroll Fraud and RansomwareHIGH
Threat Intel

TeamPCP Supply Chain Attack Fuels Payroll Fraud and Ransomware

TeamPCP threat actors compromised trusted software tools to steal credentials from over 100 organizations, enabling $1.5M in payroll fraud, logistics theft, and ransomware extortion.

3 min readTeamPCP
Vercel Confirms Data Breach After Hackers Attempt to Sell Stolen InformationHIGH
Threat Intel

Vercel Confirms Data Breach After Hackers Attempt to Sell Stolen Information

Vercel disclosed a security breach after threat actors attempted to sell stolen data, including customer account information and internal project details, on a hacking forum. The cloud platform is investigating the scope of the incident.

2 min read
Business Impersonation Fraud Evolves with AI-Powered Shopping ScamsMEDIUM
Threat Intel

Business Impersonation Fraud Evolves with AI-Powered Shopping Scams

Recorded Future details how threat actors exploit corporate identity verification gaps, pivoting from cashing stolen checks to orchestrating AI-powered shopping scams that impersonate legitimate businesses to steal goods.

4 min read
Cybercriminals Hijack Logistics Systems to Steal High-Value Physical CargoHIGH
Threat Intel

Cybercriminals Hijack Logistics Systems to Steal High-Value Physical Cargo

Threat actors are compromising trucking and freight brokerage firms to manipulate shipments and steal physical cargo, moving beyond data theft to target high-value goods in transit.

3 min read
Ransomware Attack Disrupts Automotive Data Giant Autovista GroupHIGH
Threat Intel

Ransomware Attack Disrupts Automotive Data Giant Autovista Group

Autovista Group, a major European automotive data and analytics firm, confirms a ransomware attack disrupting operations. The company is investigating with external experts, but impact on customer data remains unclear.

3 min read
Adware Campaign Hijacks DNS to Expose Thousands of OT and Government EndpointsHIGH
Malware

Adware Campaign Hijacks DNS to Expose Thousands of OT and Government Endpoints

A malicious adware campaign, active since at least 2023, hijacked DNS settings on over 25,000 systems to redirect traffic through attacker-controlled servers, exposing endpoints in critical OT and government networks to further compromise.

4 min read
Asia's Digital Supply Chain Poses Distinct Security ChallengesMEDIUM
Industry News

Asia's Digital Supply Chain Poses Distinct Security Challenges

Asia's interconnected digital ecosystems, divergent regulatory regimes, and rapid AI adoption are creating unique and complex security risks for regional and global supply chains, according to a new analysis.

3 min read
EssentialPlugin WordPress Suite Compromised to Deploy Backdoor on Thousands ofHIGH
Malware

EssentialPlugin WordPress Suite Compromised to Deploy Backdoor on Thousands of

The EssentialPlugin suite, comprising over 30 popular WordPress plugins, has been compromised to inject a backdoor granting attackers administrative access to thousands of websites. The supply chain attack is actively being exploited.

4 min read
Legitify Open-Source Tool Scans GitHub, GitLab for Security MisconfigurationsINFORMATIONAL
Tools & Techniques

Legitify Open-Source Tool Scans GitHub, GitLab for Security Misconfigurations

Legit Security releases Legitify, an open-source scanner that identifies security misconfigurations in GitHub and GitLab organizations, repositories, and CI/CD runners to combat software supply chain risks.

4 min read
Signed Adware Tool Disables Antivirus with SYSTEM PrivilegesHIGH
Malware

Signed Adware Tool Disables Antivirus with SYSTEM Privileges

A digitally signed adware tool, 'PC App Store', has been abused to deploy scripts that disable antivirus software with SYSTEM privileges, impacting thousands of endpoints in sectors like education and government.

3 min read
Threat Actors Weaponize n8n Workflow Platform for Phishing and Payload DeliveryHIGH
Threat Intel

Threat Actors Weaponize n8n Workflow Platform for Phishing and Payload Delivery

Attackers have been abusing the legitimate n8n workflow automation platform since October 2025 to send phishing emails and deliver malware, leveraging its trusted infrastructure to bypass email security filters.

3 min read
WordPress Plugin Supply Chain Attack Deploys Backdoor After 8-Month DormancyHIGH
Threat Intel

WordPress Plugin Supply Chain Attack Deploys Backdoor After 8-Month Dormancy

A threat actor purchased a legitimate WordPress plugin business and hid a backdoor in updates for eight months before activating it, compromising thousands of sites in a sophisticated supply chain attack.

4 min read
Fake Ledger Live App on Apple App Store Steals $9.5M in CryptocurrencyHIGH
Malware

Fake Ledger Live App on Apple App Store Steals $9.5M in Cryptocurrency

A malicious Ledger Live app distributed via Apple's official App Store for macOS stole approximately $9.5 million from 50 victims by harvesting recovery phrases.

4 min read
Malicious Chrome Extensions Hijack OAuth Tokens, Deploy BackdoorsHIGH
Malware

Malicious Chrome Extensions Hijack OAuth Tokens, Deploy Backdoors

Over 100 malicious extensions in the official Chrome Web Store are stealing Google OAuth2 tokens, deploying backdoors, and committing ad fraud, impacting millions of users.

3 min read
Critical PHP Composer Flaws Allow Remote Command Execution via Perforce DriverHIGH
Vulnerabilities

Critical PHP Composer Flaws Allow Remote Command Execution via Perforce Driver

Two high-severity command injection vulnerabilities (CVE-2026-40176, CVE-2026-40177) in PHP Composer's Perforce driver enable arbitrary command execution on developer systems during package operations.

CVE-2026-40176CVE-2026-40177
3 min read
CPUID Software Downloads Compromised, Delivered STX RAT MalwareHIGH
Malware

CPUID Software Downloads Compromised, Delivered STX RAT Malware

Threat actors compromised CPUID's download infrastructure for six hours, redirecting users to malicious sites serving the STX RAT. Official signed files were not affected.

3 min read
CPUID Website Compromised to Distribute Trojanized System UtilitiesHIGH
Malware

CPUID Website Compromised to Distribute Trojanized System Utilities

A Russian-speaking threat actor hacked the CPUID website, replacing legitimate download links for CPU-Z and HWMonitor with trojanized installers delivering the STX RAT malware.

3 min readRussian-speaking threat actor
Fake Claude AI Website Delivers PlugX RAT via DLL SideloadingHIGH
Malware

Fake Claude AI Website Delivers PlugX RAT via DLL Sideloading

A fraudulent website impersonating Anthropic's Claude AI distributes a self-deleting installer that deploys the PlugX remote access trojan via DLL sideloading.

4 min read
Critical Marimo RCE Flaw Exploited Within Hours of DisclosureCRITICAL
Vulnerabilities

Critical Marimo RCE Flaw Exploited Within Hours of Disclosure

A critical pre-authentication remote code execution vulnerability (CVE-2026-39987) in the Marimo Python notebook was exploited in the wild within 10 hours of public disclosure, posing a severe risk to data science environments.

CVE-2026-39987
3 min read
Backdoored Smart Slider 3 Pro Update Deployed via Compromised Plugin ServersHIGH
Threat Intel

Backdoored Smart Slider 3 Pro Update Deployed via Compromised Plugin Servers

Unknown threat actors compromised the update infrastructure for the Smart Slider 3 Pro WordPress plugin, pushing a backdoored version (3.5.1.35) to users. The attack leverages a supply chain compromise to gain administrative access.

4 min read
GlassWorm Uses New Zig Dropper to Target Developer IDEs via Fake VS Code ExtensionHIGH
Threat Intel

GlassWorm Uses New Zig Dropper to Target Developer IDEs via Fake VS Code Extension

Researchers discovered GlassWorm’s latest Zig dropper hidden in a malicious VS Code extension, allowing silent infection of multiple IDEs on developer workstations.

4 min read
North Korean Lazarus Group Compromises OpenAI via Axios Supply Chain AttackHIGH
Threat Intel

North Korean Lazarus Group Compromises OpenAI via Axios Supply Chain Attack

North Korea's Lazarus Group compromised OpenAI's internal systems via a supply chain attack on the Axios client library, using a stolen macOS code-signing certificate to sign malware.

3 min readLazarus Group
Orange Business Integrates AI into Enterprise Voice, Raises Security QuestionsMEDIUM
Industry News

Orange Business Integrates AI into Enterprise Voice, Raises Security Questions

Orange Business is embedding generative AI into its enterprise voice platforms, a move that expands the attack surface and introduces novel data security and privacy risks.

4 min read
Oberon System 3 Native Port for Raspberry Pi Raises Supply Chain Security ConcernsMEDIUM
Threat Intel

Oberon System 3 Native Port for Raspberry Pi Raises Supply Chain Security Concerns

A native port of the Oberon System 3 for Raspberry Pi 3, distributed via a pre-configured SD card image, presents a potential supply chain attack vector. The image's provenance and integrity cannot be fully verified, highlighting risks in third-party firmware distribution.

4 min read

Stay Updated

Get the latest cybersecurity news delivered to your inbox.