ProBackend
Software Supply Chain Security

Software Supply Chain Security

Articles about security vulnerabilities in open source software, dependency chains, and third-party library risks.

software supply chain security3 weeks ago5 min

Artificial Intelligence AI Cybersecurity: How FakeGit Poisoned 7,600 Repos to Target Autonomous Agents

Analysis of the FakeGit campaign by threat actor Water Kurita, which deployed over 7,600 malicious GitHub repos and 800 fake MCP servers to compromise developers and autonomous AI agents.

software supply chain securityJul 3, 20265 min

PixelSmash (CVE-2026-8461): FFmpeg Flaw Lets Attackers Execute Code on Jellyfin via Media Library Scans

A newly disclosed heap out-of-bounds write in FFmpeg's MagicYUV decoder (CVE-2026-8461) — dubbed PixelSmash — enables remote code execution on Jellyfin under ASLR-disabled conditions and denial-of-service attacks across media apps including Kodi, OBS Studio, PhotoPrism, Emby, and Nextcloud.