Brevo supply-chain attack injected ClickFix scripts on customer sites
(bleepingcomputer.com)
1.
2.
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
(bleepingcomputer.com)
3.
Trusting-Trust Attack against an Entire Linux Distribution
(news.ycombinator.com)
4.
Terabytes of credentials leaked in massive supply-chain attack
(arstechnica.com)
5.
Keyv and friends compromised in active Shai-Hulud supply chain attack
(news.ycombinator.com)
6.
Ernst & Young data breach claimed by ShinyHunters extortion gang
(bleepingcomputer.com)
7.
Polymarket customers lose $3 million in supply-chain attack
(bleepingcomputer.com)
8.
Dozens of Red Hat packages backdoored through its official NPM channel
(arstechnica.com)
9.
10.
'No way to prevent this,' says only package manager where this regularly happens
(news.ycombinator.com)
11.
Popular node-ipc npm package compromised to steal credentials
(bleepingcomputer.com)
12.
JDownloader site hacked to replace installers with Python RAT malware
(bleepingcomputer.com)
13.
DAEMON Tools devs confirm breach, release malware-free version
(bleepingcomputer.com)
14.
15.
DAEMON Tools trojanized in supply-chain attack to deploy backdoor
(bleepingcomputer.com)
16.
17.
Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
(news.ycombinator.com)
18.
19.
How the Trivy supply chain attack harvested credentials from secrets managers
(news.ycombinator.com)
20.
21.
22.
23.
Widely used Trivy scanner compromised in ongoing supply-chain attack
(arstechnica.com)
24.
AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code
(bleepingcomputer.com)
25.