⤷ Title: How a Russian-Founded Widget Vendor Hid Malicious Code in a White House App — And What It Cost
════════════════════════
𐀪 Author: Oran F
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 13:45:16 GMT
════════════════════════
⌗ Tags: #supply_chain #application_security #web_security #elfsight #data_privacy
════════════════════════
𐀪 Author: Oran F
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 13:45:16 GMT
════════════════════════
⌗ Tags: #supply_chain #application_security #web_security #elfsight #data_privacy
Medium
How a Russian-Founded Widget Vendor Hid Malicious Code in a White House App — And What It Cost
July 2026: A new app, deployed for internal communications among White House and federal workers, including the FAA, was found to contain…
⤷ Title: Malicious npm Worm Targets AI Software Supply Chains
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 14:00:59 +0000
════════════════════════
⌗ Tags: #Malware #AI security #CrowdStrike #cybersecurity #npm Worm #supply chain attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 14:00:59 +0000
════════════════════════
⌗ Tags: #Malware #AI security #CrowdStrike #cybersecurity #npm Worm #supply chain attack
Information Security News
Malicious npm Worm Targets AI Software Supply Chains
Stealthy Infiltration Tactics A sophisticated new malware conceals itself within standard software development processes. Furthermore, it perfectly mimics legitimate automation tools. Security sys…
⤷ Title: Beyond the Vendor Perimeter: Strategic Pentest for Third-Party Supply Chain Attacks
════════════════════════
𐀪 Author: Rajyavardhan Handa
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 21:20:17 GMT
════════════════════════
⌗ Tags: #application_security #penetration_testing #cybersecurity #supply_chain_security
════════════════════════
𐀪 Author: Rajyavardhan Handa
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 21:20:17 GMT
════════════════════════
⌗ Tags: #application_security #penetration_testing #cybersecurity #supply_chain_security
Medium
Beyond the Vendor Perimeter: Strategic Pentest for Third-Party Supply Chain Attacks
As reliance on third-party SaaS and PaaS solutions grows, vendor software has become a critical, yet vulnerable, extension of the corporate…
⤷ Title: SANDWORM_MODE Worm Exploits AI Toolchains and Supply Chains
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 10:47:32 +0000
════════════════════════
⌗ Tags: #Malware #AI Toolchain #CrowdStrike #NPM Malware #SANDWORM_MODE #supply chain attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 10:47:32 +0000
════════════════════════
⌗ Tags: #Malware #AI Toolchain #CrowdStrike #NPM Malware #SANDWORM_MODE #supply chain attack
Information Security News
SANDWORM_MODE Worm Exploits AI Toolchains and Supply Chains
The Emergence of AI Infrastructure Worms Malicious packages have evolved to inconspicuously masquerade as routine operations executed by artificial intelligence assistants and automated build syst…
⤷ Title: The Docket: The GitLab Patch Table Is Not the Incident Boundary
════════════════════════
𐀪 Author: Karla Ortiz-Flores
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 13:01:39 GMT
════════════════════════
⌗ Tags: #supply_chain #application_security #the_docket
════════════════════════
𐀪 Author: Karla Ortiz-Flores
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 13:01:39 GMT
════════════════════════
⌗ Tags: #supply_chain #application_security #the_docket
Medium
The Docket: The GitLab Patch Table Is Not the Incident Boundary
A GitLab RCE claim turns source control into an incident-scope question, not just a version-check ticket. The Docket: The GitLab Patch Table Is Not the Incident Boundary GitLab’s June patch table …
⤷ Title: Kimsuky Hacked South Korean Groupware Vendors With New Gomir Variants
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:01:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BirdTroy #DriveTroy #Gomir #HttpTroy #Kimsuky #Linux Backdoor #North Korea #supply chain attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:01:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BirdTroy #DriveTroy #Gomir #HttpTroy #Kimsuky #Linux Backdoor #North Korea #supply chain attack
Daily CyberSecurity
Kimsuky Hacked South Korean Groupware Vendors With New Gomir Variants
At a glance Actor or group Kimsuky, a North Korea-linked group also tracked as Springtail, Thallium and APT43 Activity type Espionage, supply-chain pivoting, credential theft, Linux backdoor deplo…
⤷ Title: CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 01:02:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CI/CD security #CVE_2026_45293 #PHP_CodeSniffer #PHPCS #Static Analysis #Supply Chain Security #WordPress Coding Standards #WordPressCS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 01:02:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CI/CD security #CVE_2026_45293 #PHP_CodeSniffer #PHPCS #Static Analysis #Supply Chain Security #WordPress Coding Standards #WordPressCS
Daily CyberSecurity
CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs
TL;DR A flaw in WordPress Coding Standards lets malicious PHP run code on the machine that lints it. Tracked as CVE-2026-45293, the bug carries a CVSS score of 8.6. The advisory calls it “an…
⤷ Title: Dependabot and PyPI Add Supply Chain Cooldowns
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 06:34:12 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Dependabot #Github #PyPI #Supply Chain Security
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 06:34:12 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Dependabot #Github #PyPI #Supply Chain Security
Information Security News
Dependabot and PyPI Add Supply Chain Cooldowns
GitHub and the Python Package Index (PyPI) have introduced strategic delays into dependency updates, discouraging developers from inadvertently deploying malicious packages upon initial release. D…
⤷ Title: When Trusted Advertising Infrastructure Becomes a Malware Delivery Channel
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 18:22:25 GMT
════════════════════════
⌗ Tags: #supply_chain_security #application_security #web_security #cybersecurity #third_party_risk
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 18:22:25 GMT
════════════════════════
⌗ Tags: #supply_chain_security #application_security #web_security #cybersecurity #third_party_risk
Medium
When Trusted Advertising Infrastructure Becomes a Malware Delivery Channel
A trusted digital advertising platform can reach thousands or even millions of users through websites that depend on its services. That…
⤷ Title: npm Supply Chain Attack Delivers a Cross-Platform RAT to Alibaba Developers
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 08:03:44 +0000
════════════════════════
⌗ Tags: #Malware #Alibaba #Cross_Platform RAT #DingTalk #malicious npm packages #npm Supply Chain Attack #Socket #Supply Chain Security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 08:03:44 +0000
════════════════════════
⌗ Tags: #Malware #Alibaba #Cross_Platform RAT #DingTalk #malicious npm packages #npm Supply Chain Attack #Socket #Supply Chain Security
Daily CyberSecurity
npm Supply Chain Attack Delivers a Cross-Platform RAT to Alibaba Developers
At a glance Malware family Unnamed cross-platform RAT (final payload “aone-cli”) Threat actor Unattributed; suspected Chinese-speaking actor Target Developers at Alibaba Group units, i…