Supply Chain Security
Compromised packages, dependency attacks and the software supply chain.
US Reliance on Chinese Memory Chips Is a Supply-Chain Trap No One's Fixing
As DRAM prices surge 55-60% amid AI-driven demand, Apple, Dell, and HP qualify Chinese memory chips from CXMT. US lawmakers warn this exposes Western manufacturers to state-subsidized Chinese memory and are pushing for an executive order to block the purchases — even as CXMT prices a record $85 billion Shanghai IPO.
The AI Cybersecurity Threat Nobody's Fixing: How OAuth Abuse Is Rewriting the Rules of Supply Chain Attacks
The Klue Battlecards breach exposed a structural flaw in how enterprises trust third-party integrations. As AI agents increasingly rely on OAuth-connected APIs, the non-human identity problem is becoming the defining cybersecurity vulnerability of 2026.
Polymarket Commits to Full User Reimbursement Following $3M Supply-Chain Breach
An analysis of the Polymarket $3 million supply-chain breach, focusing on the dangers of frontend trust in third-party vendors, from a security & compliance analyst perspective.
The Supply-Chain Time Bomb AI Cybersecurity Tools Just Uncovered
Dan Lorenc, CEO of Chainguard and leader of the new Athena coalition, warns of a 'messy' summer as AI uncovers thousands of hidden open-source vulnerabilities. A newly formed group of two dozen companies—including BNY, Cisco, Cloudflare, Docker, and PwC—is rushing to coordinate patching before attackers exploit the flood of disclosures.
What If the Founding Fathers Had Google Workspace? A 250th Anniversary AI Ad Reimagines American Independence
Google's latest commercial imagines the Founding Fathers using modern Google Workspace tools and AI to draft the Declaration of Independence, blending historical homage with product showcases.
Miasma Campaign Automates Credential Theft via Leo Platform and RStreams npm Packages
The latest wave of the Miasma supply chain attack has targeted npm packages in the Leo Platform and RStreams ecosystems, leveraging compromised maintainer accounts to automate the theft of developer and CI/CD secrets.
Klue-Linked SaaS Supply Chain Campaign Intensifies as Extortionists Leak Extracted Salesforce CRM Data
The Icarus extortion group has begun leaking stolen CRM records, widening the impact of the Klue OAuth integration breach as additional enterprise victims confirm compromise of their Salesforce environments.
Microsoft Swiftly Remediates GitHub Repositories Compromised in Supply-Chain Campaign
Following a swift containment action, Microsoft restores 73 GitHub repositories after it was discovered they were being leveraged to distribute password-stealing malware in a supply-chain campaign.
Before the Breach: How Underground Markets Reveal Supply-Chain Attacks in Progress
Software supply-chain attacks don't appear out of nowhere — early warning signs circulate in underground forums and marketplaces long before public incident reports. This article examines how Flare researchers identified pre-incident indicators across GitHub access sales, source-code leaks, and package-ecosystem compromises, using Shai-Hulud, the Vercel OAuth incident, TeamPCP, and LiteLLM as case studies.
ChocoPoC RAT: Stealthy Supply-Chain Poisoning via PyPI Dependencies in GitHub PoCs
A Python-based remote access trojan delivered by hijacking PyPI package dependencies within weaponized GitHub proof-of-concept exploits, targeting cybersecurity researchers with evasive malware injection techniques.
AI-Triggered Credential Theft: The Microsoft Supply Chain Breach in Focus
An analysis of the recent Miasma supply chain worm that compromised 73 Microsoft-signed open-source packages, targeting developer AI coding assistants.
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
The attacks stemmed from a GitHub account that was also compromised in a previous Miasma attack on Microsoft last month.