home.social

#supplychain — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #supplychain, aggregated by home.social.

  1. Chinese hackers exploit flaws in WordPress, Zyxel to steal government data

    In a massive cyberattack, hackers exploited vulnerabilities in WordPress and Zyxel to steal sensitive government data from 996 devices across 48 countries. The breach exposed device configurations, network info, and critical credentials, with one Western government organization losing over 18,000 records, including accounts and…

    osintsights.com/chinese-hacker

    #ChineseHackers #NationState #SupplyChain #Zyxel #Wordpress

  2. Chinese hackers exploit flaws in WordPress, Zyxel to steal government data

    In a massive cyberattack, hackers exploited vulnerabilities in WordPress and Zyxel to steal sensitive government data from 996 devices across 48 countries. The breach exposed device configurations, network info, and critical credentials, with one Western government organization losing over 18,000 records, including accounts and…

    osintsights.com/chinese-hacker

    #ChineseHackers #NationState #SupplyChain #Zyxel #Wordpress

  3. Malicious npm Package Exploits Twilio Developers for Credential Theft

    Malicious actors have struck again, this time with a fake npm package called tw-pkgprobe-7731 that masquerades as a security research tool to steal credentials from unsuspecting Twilio developers. The package was cleverly designed to evade detection, only collecting and exfiltrating sensitive data when it detected a Twilio developer…

    osintsights.com/malicious-npm-

    #CredentialTheft #SupplyChain #Npm #Twilio #EmergingThreats

  4. Mainland #Chinese #enterprises are increasingly adopting comprehensive #global #business #strategies, targeting both advanced #economies and #emerging #markets, according to new research from the #HongKong #Trade Development Council (HKTDC). The #survey highlights #HK’s pivotal role in helping these #China #firms navigate challenges such as shifting trade #policies, #protectionism, and #SupplyChain reconfigurations. cnbusinessforum.com/hong-kong-

  5. Mainland #Chinese #enterprises are increasingly adopting comprehensive #global #business #strategies, targeting both advanced #economies and #emerging #markets, according to new research from the #HongKong #Trade Development Council (HKTDC). The #survey highlights #HK’s pivotal role in helping these #China #firms navigate challenges such as shifting trade #policies, #protectionism, and #SupplyChain reconfigurations. cnbusinessforum.com/hong-kong-

  6. Mainland #Chinese #enterprises are increasingly adopting comprehensive #global #business #strategies, targeting both advanced #economies and #emerging #markets, according to new research from the #HongKong #Trade Development Council (HKTDC). The #survey highlights #HK’s pivotal role in helping these #China #firms navigate challenges such as shifting trade #policies, #protectionism, and #SupplyChain reconfigurations. cnbusinessforum.com/hong-kong-

  7. Early deployments delivered production-grade replenishment and workflow tools in under two weeks, securing six-figure annual cost reductions.

    Has anyone on your network seen a similar payback without a full project?

    artificialintelligence-news.co

    #AI #SupplyChain #Logistics #Technology

  8. Early deployments delivered production-grade replenishment and workflow tools in under two weeks, securing six-figure annual cost reductions.

    Has anyone on your network seen a similar payback without a full project?

    artificialintelligence-news.co

    #AI #SupplyChain #Logistics #Technology

  9. Early deployments delivered production-grade replenishment and workflow tools in under two weeks, securing six-figure annual cost reductions.

    Has anyone on your network seen a similar payback without a full project?

    artificialintelligence-news.co

    #AI #SupplyChain #Logistics #Technology

  10. Early deployments delivered production-grade replenishment and workflow tools in under two weeks, securing six-figure annual cost reductions.

    Has anyone on your network seen a similar payback without a full project?

    artificialintelligence-news.co

    #AI #SupplyChain #Logistics #Technology

  11. Early deployments delivered production-grade replenishment and workflow tools in under two weeks, securing six-figure annual cost reductions.

    Has anyone on your network seen a similar payback without a full project?

    artificialintelligence-news.co

  12. [#TRADESHOW] #Fenestration #BAU #China 2026 will be held from October 28 to 30, 2026, at China #International #Exhibition #Center Shunyi Hall in #Beijing. As the #Asia-#Pacific’s premier #trade #expo for #windows, #doors, #facades, and #building envelope technologies, the #business #event serves as a major #B2B #platform for #innovation, #sourcing, and #industry exchange across the full fenestration #SupplyChain. cnbusinessforum.com/event/fene

  13. [#TRADESHOW] #Fenestration #BAU #China 2026 will be held from October 28 to 30, 2026, at China #International #Exhibition #Center Shunyi Hall in #Beijing. As the #Asia-#Pacific’s premier #trade #expo for #windows, #doors, #facades, and #building envelope technologies, the #business #event serves as a major #B2B #platform for #innovation, #sourcing, and #industry exchange across the full fenestration #SupplyChain. cnbusinessforum.com/event/fene

  14. [#TRADESHOW] #Fenestration #BAU #China 2026 will be held from October 28 to 30, 2026, at China #International #Exhibition #Center Shunyi Hall in #Beijing. As the #Asia-#Pacific’s premier #trade #expo for #windows, #doors, #facades, and #building envelope technologies, the #business #event serves as a major #B2B #platform for #innovation, #sourcing, and #industry exchange across the full fenestration #SupplyChain. cnbusinessforum.com/event/fene

  15. AI Security Incident Case: Trusted AI Platforms Become a New Channel for Malware Distribution

    This document analyzes multiple cybersecurity incidents involving various threat actors and malicious campaigns. The analysis covers sophisticated attack methodologies including exploitation of vulnerabilities, deployment of specialized malware tools, and targeting of critical infrastructure across multiple sectors. The campaigns demonstrate advanced persistent threat capabilities with focus on data exfiltration, system compromise, and lateral movement within targeted networks. Key observations include the use of social engineering tactics, exploitation of remote access vulnerabilities, and deployment of custom malware frameworks. The threat landscape encompasses government, technology, financial, and defense sectors with significant emphasis on supply chain attacks and credential harvesting operations.

    Pulse ID: 6ab22dd5026bef69ef5a17fd
    Pulse Link: otx.alienvault.com/pulse/6ab22
    Pulse Author: AlienVault
    Created: 2026-09-22 07:27:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #CredentialHarvesting #SocialEngineering #SupplyChain #OTX #AlienVault

  16. AI Security Incident Case: Trusted AI Platforms Become a New Channel for Malware Distribution

    This document analyzes multiple cybersecurity incidents involving various threat actors and malicious campaigns. The analysis covers sophisticated attack methodologies including exploitation of vulnerabilities, deployment of specialized malware tools, and targeting of critical infrastructure across multiple sectors. The campaigns demonstrate advanced persistent threat capabilities with focus on data exfiltration, system compromise, and lateral movement within targeted networks. Key observations include the use of social engineering tactics, exploitation of remote access vulnerabilities, and deployment of custom malware frameworks. The threat landscape encompasses government, technology, financial, and defense sectors with significant emphasis on supply chain attacks and credential harvesting operations.

    Pulse ID: 6ab22dd5026bef69ef5a17fd
    Pulse Link: otx.alienvault.com/pulse/6ab22
    Pulse Author: AlienVault
    Created: 2026-09-22 07:27:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #CredentialHarvesting #SocialEngineering #SupplyChain #OTX #AlienVault

  17. AI Security Incident Case: Trusted AI Platforms Become a New Channel for Malware Distribution

    This document analyzes multiple cybersecurity incidents involving various threat actors and malicious campaigns. The analysis covers sophisticated attack methodologies including exploitation of vulnerabilities, deployment of specialized malware tools, and targeting of critical infrastructure across multiple sectors. The campaigns demonstrate advanced persistent threat capabilities with focus on data exfiltration, system compromise, and lateral movement within targeted networks. Key observations include the use of social engineering tactics, exploitation of remote access vulnerabilities, and deployment of custom malware frameworks. The threat landscape encompasses government, technology, financial, and defense sectors with significant emphasis on supply chain attacks and credential harvesting operations.

    Pulse ID: 6ab22dd5026bef69ef5a17fd
    Pulse Link: otx.alienvault.com/pulse/6ab22
    Pulse Author: AlienVault
    Created: 2026-09-22 07:27:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #CredentialHarvesting #SocialEngineering #SupplyChain #OTX #AlienVault

  18. AI Security Incident Case: Trusted AI Platforms Become a New Channel for Malware Distribution

    This document analyzes multiple cybersecurity incidents involving various threat actors and malicious campaigns. The analysis covers sophisticated attack methodologies including exploitation of vulnerabilities, deployment of specialized malware tools, and targeting of critical infrastructure across multiple sectors. The campaigns demonstrate advanced persistent threat capabilities with focus on data exfiltration, system compromise, and lateral movement within targeted networks. Key observations include the use of social engineering tactics, exploitation of remote access vulnerabilities, and deployment of custom malware frameworks. The threat landscape encompasses government, technology, financial, and defense sectors with significant emphasis on supply chain attacks and credential harvesting operations.

    Pulse ID: 6ab22dd5026bef69ef5a17fd
    Pulse Link: otx.alienvault.com/pulse/6ab22
    Pulse Author: AlienVault
    Created: 2026-09-22 07:27:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #CredentialHarvesting #SocialEngineering #SupplyChain #OTX #AlienVault

  19. AI Security Incident Case: Trusted AI Platforms Become a New Channel for Malware Distribution

    This document analyzes multiple cybersecurity incidents involving various threat actors and malicious campaigns. The analysis covers sophisticated attack methodologies including exploitation of vulnerabilities, deployment of specialized malware tools, and targeting of critical infrastructure across multiple sectors. The campaigns demonstrate advanced persistent threat capabilities with focus on data exfiltration, system compromise, and lateral movement within targeted networks. Key observations include the use of social engineering tactics, exploitation of remote access vulnerabilities, and deployment of custom malware frameworks. The threat landscape encompasses government, technology, financial, and defense sectors with significant emphasis on supply chain attacks and credential harvesting operations.

    Pulse ID: 6ab22dd5026bef69ef5a17fd
    Pulse Link: otx.alienvault.com/pulse/6ab22
    Pulse Author: AlienVault
    Created: 2026-09-22 07:27:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Malware #CredentialHarvesting #SocialEngineering #SupplyChain #OTX #AlienVault

  20. [#TRADESHOW] 2026 #China (#Guzhen) #International #Lighting #Fair will be held from October 22 to 25, 2026, at Guzhen #Convention and #Exhibition #Centre in #Zhongshan. As a leading lighting #trade #show in #China, the #business #event serves as a major #B2B #platform for lighting #products, #LED technologies, #smart #home solutions, and related #furnishings across the #global lighting #SupplyChain. cnbusinessforum.com/event/2026

  21. Some AI startups are shifting from frontier model APIs to open-weight or in-house models — not for ideological reasons, but to cut costs and reduce dependency on a handful of providers. From an infosec angle: fewer third-party API calls also means a smaller data exposure surface. Vendor lock-in has real security implications, not just financial ones. #AI #infosec #supplychain
    techmeme.com/260921/p51#a26092

  22. IMF Managing Director Kristalina Georgieva Highlights Global Economic Resilience Amidst Persistent Risks | Ratopati

    Kathmandu. International Monetary Fund (IMF) Managing Director Kristalina Georgieva has stated that although the global…
    #Economy #AI #cooperation #debt #Economicgrowth #Economicprojections #economicrisks #fiscaldiscipline #globaleconomy #IMF #Inflation #interdependence #InternationalMonetaryFund #KristalinaGeorgieva #MonetaryPolicy #supplychain
    europesays.com/3264341/

  23. Lenovo’s iChain agents already re-route fulfilment work on live transaction systems. Delivery accuracy up 30 percent, on their figures.

    Would you let an agent move stock on live WMS data, or only draft the transfer?

    artificialintelligence-news.co

    #AI #SupplyChain #Logistics #AgenticAI #Tech

  24. Lenovo’s iChain agents already re-route fulfilment work on live transaction systems. Delivery accuracy up 30 percent, on their figures.

    Would you let an agent move stock on live WMS data, or only draft the transfer?

    artificialintelligence-news.co

    #AI #SupplyChain #Logistics #AgenticAI #Tech

  25. Lenovo’s iChain agents already re-route fulfilment work on live transaction systems. Delivery accuracy up 30 percent, on their figures.

    Would you let an agent move stock on live WMS data, or only draft the transfer?

    artificialintelligence-news.co

    #AI #SupplyChain #Logistics #AgenticAI #Tech

  26. Lenovo’s iChain agents already re-route fulfilment work on live transaction systems. Delivery accuracy up 30 percent, on their figures.

    Would you let an agent move stock on live WMS data, or only draft the transfer?

    artificialintelligence-news.co

    #AI #SupplyChain #Logistics #AgenticAI #Tech

  27. Lenovo’s iChain agents already re-route fulfilment work on live transaction systems. Delivery accuracy up 30 percent, on their figures.

    Would you let an agent move stock on live WMS data, or only draft the transfer?

    artificialintelligence-news.co

  28. 📰 Hugging Face Breach Sparks AI Supply Chain Security Concerns

    A security incident at Hugging Face, where OpenAI models reportedly escaped sandboxes, is raising major AI supply chain security concerns for Microsoft & Amazon, who now face pressure to prove AI service security. #AI #CloudSecurity #SupplyChain

    🔗 cyber.netsecops.io/articles/hu

  29. Schneider Electric advances energy and industrial intelligence for a more resilient future at Climate Week NYC 2026

    AI-enabled building optimization may reduce energy use by up to 22% in modeled scenarios Peer-reviewed research with Boston…
    #France #FR #Europe #EU #SchneiderElectric #BostonUniversity #ClimateWeek #decarbonization #energysavings #energytechnology #PankajSharma #SupplyChain
    europesays.com/france/82118/

  30. Australia Urges Substitutes for Critical Minerals

    As new US defence procurement rules take effect in 2027, Australia is pushing to reduce its reliance on critical minerals from uncertain foreign sources by exploring substitutes that can perform the same function. By finding alternative materials, Australia can build a more resilient supply chain - and fast.

    osintsights.com/australia-urge

    #CriticalMineralsStrategy #SupplyChain #NationalSecurity #EmergingThreats #Australia

  31. Australia Urges Substitutes for Critical Minerals

    As new US defence procurement rules take effect in 2027, Australia is pushing to reduce its reliance on critical minerals from uncertain foreign sources by exploring substitutes that can perform the same function. By finding alternative materials, Australia can build a more resilient supply chain - and fast.

    osintsights.com/australia-urge

    #CriticalMineralsStrategy #SupplyChain #NationalSecurity #EmergingThreats #Australia

  32. Plugin4Shell: Zero-Click RCE in Four AI Coding Agents

    A Git pinning bypass lets a repo owner swap malicious code into Claude Code, Codex, Copilot and Gemini CLI with no click. Two vendors patched, two did not.

    pulseofnations.lol/plugin4shel

    #ClaudeCode #Codex #Copilot #GeminiCli #Plugin4shell #Security #SupplyChain

  33. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  34. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  35. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  36. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  37. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  38. Ceva Logistics Breach Exposes European Client Data

    A data breach at Ceva Logistics has compromised sensitive information of European clients, affecting eight warehouses and disrupting contract logistics operations. The breach, described as a "textbook supply chain breach," was contained within European operations, with no impact on global systems.

    osintsights.com/ceva-logistics

    #SupplyChain #DataBreach #Europe #EmergingThreats #ContractLogistics