A commentary argues that the United States should prioritize building products manufactured domestically, citing repeated disruptions from the pandemic, tariffs, and geopolitical conflicts that have exposed vulnerabilities in global supply chains. The piece points to newer, economical and more sustainable American-made building materials as a viable alternative to imported goods.
fastcompany.com
· 2026-09-23
PepsiCo is investing in precision agriculture technology, including drones and data analytics, on farms like a multigenerational operation in Alberta to improve soil health and crop yields. The company relies on roughly 45 billion potatoes annually for Lay's, Ruffles and other snack brands, making stable harvests essential to its supply chain.
fastcompany.com
· 2026-09-22
Security researchers at SafeDep discovered that a malicious npm package called mathmain, disguised as a copy of the popular mathjs library, contains a hidden remote access implant. The malicious code stays encrypted and dormant until a specific equation is solved using the library's lusolve() solver function, which acts as a decryption key to unlock and execute the payload.
safedep.io
· 2026-09-21
A Google Threat Intelligence Group analyst named Larsen ran a covert operation to observe the hacker collective TeamPCP, gaining access to a server where the group stored stolen credentials from numerous victim companies. Google used this visibility to rapidly notify cloud providers like AWS and Microsoft to revoke compromised access tokens before the hackers could exploit them for extortion, rather than trying to contact each victim individually.
arstechnica.com
· 2026-09-20
Checkmarx researchers uncovered a malicious npm package called 'indexed-btree,' which mimics the legitimate 'sorted-btree' library and has racked up 2 million weekly downloads. Rather than embedding malicious code in install scripts—now restricted by npm's June 2026 security measures—the attackers hid a malware loader inside the package's commonly used BTree.prototype.set() method, which activates only when called with a specific key. Once triggered, the malware gathers system data such as hostname, CPU, memory, and uptime, and sends it to attackers who reportedly control a wallet holding 109 ETH, though its link to this campaign is unconfirmed.
bleepingcomputer.com
· 2026-09-20
PS Audio and Naim have both discontinued flagship CD-playing products, the PMG Super Audio CD Transport and Uniti Star, after their optical drive suppliers stopped making key mechanisms. The trouble traces back to D&M Holdings, owner of Denon and Marantz, which in mid-2024 announced it would stop taking orders for its SACD/CD mechanism, prompting a scramble among audio brands that doubled component prices before supply ran out entirely.
tomshardware.com
· 2026-09-20
Google’s threat intelligence team secretly embedded an undercover analyst within the hacking group TeamPCP during its extensive supply chain attack campaign. This inside access allowed Google to monitor the group’s activities, warn potential targets, and assist law enforcement in identifying key members. The operation uncovered critical security lapses and contributed to arrests in Australia last month.
wired.com
· 2026-09-18
LastPass and Delphos Labs identified a malware campaign that uses SEO-optimized GitHub repositories impersonating LastPass and at least 39 other companies to distribute a previously unseen infostealer called Rapuncel. Victims searching for tools like LastPass Authenticator are led to fake repos where oversized ZIP files hide a renamed Microsoft debugger that sideloads the malicious payload and a Microsoft-signed kernel driver capable of killing 145 different antivirus and EDR products.
bleepingcomputer.com
· 2026-09-18
Brevo disclosed that hackers obtained a hardcoded, full-permission Cloudflare API key and used it to deploy a rogue Cloudflare Worker that rewrote content at the CDN edge for roughly 5.5 hours on September 14. The tampered scripts, including Brevo's forms widget, Conversations tool and SDK loader embedded on customer sites, were altered to serve ClickFix malware while stripping security headers to evade detection.
bleepingcomputer.com
· 2026-09-17
WIRED found that Flock, whose license plate readers are used by police nationwide, has quietly stopped specifying where its cameras are manufactured in recent marketing materials, despite years of touting domestic production. A US manufacturer that once listed Flock as a client removed the reference from its website amid growing public backlash against the company's surveillance technology.
wired.com
· 2026-09-17
In a Fast Company interview, Walmart U.S. President and CEO David Guggina described how the retailer is combining its extensive store footprint, supply chain infrastructure, e-commerce operations and customer data into one integrated system. He argued this convergence lets Walmart respond faster to shifting customer needs and extract greater value from its existing assets.
fastcompany.com
· 2026-09-17
A threat actor breached the website of Admin Menu Editor Pro maintainer Janis Elsts and pushed a malicious version 2.35 update that installed a web shell and created a hidden admin account on customer sites. Even after Elsts released a clean version 2.36, the attacker retained access and compromised that release too, affecting an estimated 230 customers and at least 1,500 sites.
bleepingcomputer.com
· 2026-09-15