home.social

#supply-chain — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #supply-chain, aggregated by home.social.

fetched live
  1. Security researchers report the “Shai-Hulud” npm worm variant “ChainDrop” poisoned 444 packages, spreading via tarballs and stealthy dev-tool hooks that trigger when opening infected branches in VS Code/Claude. It can harvest write-privileged npm tokens + credentials, then republish itself. 🐛🔒 #SupplyChain #Npm theregister.com/security/2026/

  2. Security researchers report the “Shai-Hulud” npm worm variant “ChainDrop” poisoned 444 packages, spreading via tarballs and stealthy dev-tool hooks that trigger when opening infected branches in VS Code/Claude. It can harvest write-privileged npm tokens + credentials, then republish itself. 🐛🔒 #SupplyChain #Npm theregister.com/security/2026/

  3. @velliajs/discord (npm) contains CRITICAL malicious code in versions 1.0.3 – 1.0.7: hardcoded GitHub PATs enable remote code execution & a hidden kill-switch disables bots unless allow-listed. Remove & audit now. No CVE. Details: radar.offseq.com/threat/malici #OffSeq #npm #infosec #supplychain

  4. Apple's plan to source memory chips from Chinese firms CXMT and YMTC faces opposition from the U.S. government due to national security concerns. The administration urges Apple to find alternative solutions, reflecting the ongoing tension between supply chain needs and geopolitical factors in tech manufacturing.

    #Apple #MemoryChips #SupplyChain #NationalSecurity #TechNews #USChinaRelations

    thedailytechfeed.com/us-commer

  5. DecryptAds, built by Svart Works Inc., turns hidden ad supply chains into public insight 📊🧩 It maps ads.txt/app-ads.txt plus sellers.json/buyers.json/adagents.json, surfaces geographic risk, and flags quiet removals. Researchers and enterprises use a REST API + MCP server. 🔍 decryptads.com/ #adtech #supplychain #transparency

    infosec.exchange/@briankrebs/1

    This is friggin amazing 🤩

  6. DecryptAds, built by Svart Works Inc., turns hidden ad supply chains into public insight 📊🧩 It maps ads.txt/app-ads.txt plus sellers.json/buyers.json/adagents.json, surfaces geographic risk, and flags quiet removals. Researchers and enterprises use a REST API + MCP server. 🔍 decryptads.com/ #adtech #supplychain #transparency

    infosec.exchange/@briankrebs/1

    This is friggin amazing 🤩

  7. arstechnica.com/security/2026/

    “A window of roughly 40 minutes in which the LiteLLM dependency was hacked led to over 430,000 instances in which millions of secrets were harvested. This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry.”

    A partial listing of the affected companies follows; the arstechnica article has a link to the full list.

  8. arstechnica.com/security/2026/

    #AI #SecurityBreach #SupplyChain #litellm

    “A window of roughly 40 minutes in which the LiteLLM dependency was hacked led to over 430,000 instances in which millions of secrets were harvested. This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry.”

    A partial listing of the affected companies follows; the arstechnica article has a link to the full list.

  9. 📢⚠️ #TeamPCP used a poisoned Trivy scanner to hijack LiteLLM releases. Researchers linked the breach to 2,500+ companies and 434K CI/CD pipelines. The malware stole cloud, developer, and AI credentials.

    Listen/Read: hackread.com/litellm-breach-25

    #CyberSecurity #LiteLLM #DataBreach #SupplyChain

  10. 📢⚠️ #TeamPCP used a poisoned Trivy scanner to hijack LiteLLM releases. Researchers linked the breach to 2,500+ companies and 434K CI/CD pipelines. The malware stole cloud, developer, and AI credentials.

    Listen/Read: hackread.com/litellm-breach-25

    #CyberSecurity #LiteLLM #DataBreach #SupplyChain

  11. In a supply chain attack on the popular LiteLLM library in March this year, around 434,000 build pipelines – which were in use at more than 2,500 companies – are believed to have been compromised: cloudsek.com/blog/ai-supply-ch
    How you can protect yourselves against such and similar attacks is explained in our @Python4DataScience tutorial: python4data.science/en/latest/
    #Python #ITSecurity #SupplyChain #LiteLLM

  12. In a supply chain attack on the popular LiteLLM library in March this year, around 434,000 build pipelines – which were in use at more than 2,500 companies – are believed to have been compromised: cloudsek.com/blog/ai-supply-ch
    How you can protect yourselves against such and similar attacks is explained in our @Python4DataScience tutorial: python4data.science/en/latest/
    #Python #ITSecurity #SupplyChain #LiteLLM

  13. Alluminio: nuovi guai in Amazzonia con Alunorte che taglia la produzione del 50%
    metallirari.com/alluminio-nuov
    Il taglio di produzione di allumina ad Alunorte, deciso da Norsk Hydro per problemi di fornitura gas, si somma alla crisi mediorientale legata alla guerra in Iran e spinge l’alluminio a un massimo di sette settimane, con le scorte LME ai minimi dal 1990.
    #Alluminio #Alunorte #NorskHydro #Iran #LME #MercatoMetalli #CommoditiesTrading #Allumina #Geopolitica #SupplyChain #Brasile

  14. Apple's MacBook Air is facing significant supply constraints, with delivery estimates extending weeks. Alternative retailers like Amazon offer immediate availability for select models, some at discounted prices. Exploring these options may help secure a MacBook Air sooner.

    #MacBookAir #Apple #TechNews #SupplyChain #Amazon #Refurbished

    thedailytechfeed.com/macbook-a

  15. Pegatron confirms Apple's base iPhone 18 model will launch in early 2027, following the Pro versions' 2026 release. This shift may address supply chain challenges and market dynamics, aiming to optimize production efficiency and consumer engagement.

    #Apple #iPhone18 #Pegatron #TechNews #SupplyChain #ProductLaunch

    thedailytechfeed.com/apples-ip

  16. RE: mstdn.social/@hkrn/11708302366

    This is related to what I talked about at #opensourcenorth this year. Small volunteer teams maintaining massively used open source projects are part of the supply chain weaknesses we are seeing exploited. The only lasting way we have to combat against this going forward is to be a community and help each other with the work.

    #FOSS #supplychain #ublockorigin

  17. RE: mstdn.social/@hkrn/11708302366

    This is related to what I talked about at #opensourcenorth this year. Small volunteer teams maintaining massively used open source projects are part of the supply chain weaknesses we are seeing exploited. The only lasting way we have to combat against this going forward is to be a community and help each other with the work.

    #FOSS #supplychain #ublockorigin

  18. Gunra Ransomware Targets Infrastructure via Fortinet Flaws

    Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

    osintsights.com/gunra-ransomwa

    #GunraRansomware #Fortinet #Cve202455591 #Ransomware #SupplyChain

  19. Gunra Ransomware Targets Infrastructure via Fortinet Flaws

    Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

    osintsights.com/gunra-ransomwa

    #GunraRansomware #Fortinet #Cve202455591 #Ransomware #SupplyChain

  20. Apple's M4 Mac Mini, featuring the M4 chip and redesigned compact chassis, is now available on Amazon amid previous supply constraints. The base model, with 16GB RAM and a 512GB SSD, is priced at $999, with delivery between August 18 and 20. This offers a timely opportunity for users seeking to upgrade their desktop setups without prolonged wait times.

    #Apple #MacMini #M4 #TechNews #Amazon #SupplyChain

    thedailytechfeed.com/amazon-re