#supplychaincompromise — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #supplychaincompromise, aggregated by home.social.
-
How state-sponsored attackers hijacked Notepad++ updates https://www.helpnetsecurity.com/2026/02/02/2025-notepad-supply-chain-compromise/ #government-backedattacks #supplychaincompromise #telecommunications #financialindustry #Don'tmiss #Hotstuff #News #Asia
-
Gainsight breach: Salesforce details attack window, issues investigation guidance https://www.helpnetsecurity.com/2025/11/26/gainsight-breach-salesforce-details-attack-window/ #supplychaincompromise #PaloAltoNetworks #Salesforce #Don'tmiss #datatheft #Gainsight #Hotstuff #Mandiant #News #SaaS
-
Salesforce investigates new incident echoing Salesloft Drift compromise https://www.helpnetsecurity.com/2025/11/20/salesforce-investigates-new-incident-echoing-salesloft-drift-compromise/ #supplychaincompromise #GoogleCloud #Salesforce #Don'tmiss #datatheft #Gainsight #Hotstuff #Mandiant #News #SaaS
-
Sometimes I wonder what would happen if
oss developers simply list out every single bug report they receive on their website and clearly note we don’t have resources to fix it.
And then list every single mega corp that uses that OSS library and clearly send out message informing the world we don’t fix bugs and since all of these orgs don’t like helping anyone using them is vulnerable.
May be just may be that would give people an idea about putting pressure on wrong set of individuals.
But most importantly it will make it clear for people where the responsibility of security for your customers lie with you or with third party.
#softwaresupplychainsecurity #supplychaincompromise #opensource
-
Fake npm 2FA reset email led to compromise of popular code packages https://www.helpnetsecurity.com/2025/09/09/npm-packages-supply-chain-compromise/ #supplychaincompromise #accounthijacking #AikidoSecurity #ReversingLabs #AcumenCyber #JavaScript #Don'tmiss #Hotstuff #phishing #Sonatype #GitHub #Nodejs #News
-
Salesloft Drift data breach: Investigation reveals how attackers got in https://www.helpnetsecurity.com/2025/09/08/salesloft-drift-data-breach-investigation-results/ #supplychaincompromise #credentials #Salesforce #Don'tmiss #datatheft #Salesloft #Hotstuff #Mandiant #News
-
Cloudflare confirms data breach linked to Salesloft Drift supply chain compromise https://www.helpnetsecurity.com/2025/09/03/cloudflare-confirms-data-breach-linked-to-salesloft-drift-supply-chain-compromise/ #supplychaincompromise #credentials #Cloudflare #databreach #Proofpoint #Salesforce #Don'tmiss #Hotstuff #Rubrik #OAuth #News #SaaS
-
Breaches are up, budgets are too, so why isn’t healthcare safer? https://www.helpnetsecurity.com/2025/08/11/resilience-top-healthcare-cybersecurity-risks/ #supplychaincompromise #supplychainattacks #cyberresilience #cybersecurity #securityROI #healthcare #resilience #cyberrisk #report #News
-
Malicious RVTools installer found on official site
https://www.helpnetsecurity.com/2025/05/19/rvtools-installer-malware/
-
Malicious RVTools installer found on official site, researcher warns https://www.helpnetsecurity.com/2025/05/19/rvtools-installer-malware/ #supplychaincompromise #virtualization #Don'tmiss #Hotstuff #VMware #News #Dell
-
How Lazarus Group built a cyber espionage empire https://www.helpnetsecurity.com/2025/01/29/lazarus-group-cyber-espionage-supply-chain-attack/ #supplychaincompromise #SecurityScorecard #cyberattribution #cybersecurity #NorthKorea #Don'tmiss #report #News
-
Lottie Player supply chain compromise: Sites, apps showing crypto scam pop-ups https://www.helpnetsecurity.com/2024/10/31/lottie-player-compromise/ #supplychaincompromise #cryptocurrency #cybercrime #JavaScript #Don'tmiss #Hotstuff #News
-
The role of compromised cyber-physical devices in modern cyberattacks https://www.helpnetsecurity.com/2024/10/17/fyodor-yarochkin-trend-micro-compromised-cyber-physical-devices/ #supplychaincompromise #securitycameras #smartbuilding #TrendMicro #Don'tmiss #ICS/SCADA #smartgrid #smarthome #Features #Hotstuff #router #News #IIoT #IoT #OT
-
Ghost: Criminal communication platform compromised, dismantled by international law enforcement https://www.helpnetsecurity.com/2024/09/18/ghost-encrypted-communication/ #supplychaincompromise #securecommunications #lawenforcement #cybercrime #encryption #government #Don'tmiss #Australia #Hotstuff #Europol #arrest #crime #News
-
Chinese hackers compromised an ISP to deliver malicious software updates https://www.helpnetsecurity.com/2024/08/05/compromised-isp-dns-malware/ #supplychaincompromise #cyberespionage #Don'tmiss #Hotstuff #Symantec #Volexity #malware #China #News #ESET #APT #DNS #ISP
-
Compromised plugins found on WordPress.org https://www.helpnetsecurity.com/2024/06/26/compromised-plugins-wordpress/ #supplychaincompromise #Don'tmiss #Wordfence #WordPress #Hotstuff #backdoor #plugin #News
-
Compromised recording software was served from vendor’s official site, threat researchers say https://www.helpnetsecurity.com/2024/05/23/javs-viewer-malware/ #supplychaincompromise #Don'tmiss #Hotstuff #malware #Rapid7 #News
-
XZ Utils backdoor: Detection tools, scripts, rules https://www.helpnetsecurity.com/2024/04/08/detect-xz-backdoor/ #supplychaincompromise #Bitdefender #opensource #Don'tmiss #Hotstuff #backdoor #Binarly #Elastic #GitHub #Linux #News
-
Red Hat Issues a Warning to Fedora Linux Users Related to a Critical 10-out-of-10 Vulnerability: https://www.reviewspace.info/unveiling-the-xz-supply-chain-compromise-red-hat-s-warning-to-fedora-linux-users
#RedHat #FedoraLinux #xzLibrary #SupplyChainCompromise #Cybersecurity #CVE20243094 #OpenSSH #systemd #Cybersecurity #TechnologyNews
-
Beware! Backdoor found in XZ utilities used by many Linux distros (CVE-2024-3094) https://www.helpnetsecurity.com/2024/03/29/cve-2024-3094-linux-backdoor/ #supplychaincompromise #vulnerability #opensource #Don'tmiss #Hotstuff #backdoor #Debian #Fedora #RedHat #Linux #News #CISA #SUSE #CVE
-
"Your computer is going to start burning, good luck. :)"
Supply chain attack via Python obfuscation packages
⬇️
"Python obfuscation traps"
👇
https://checkmarx.com/blog/python-obfuscation-traps/