Posts Tagged ‘supply chain’
TeamCity CVE-2026-63077 RCE: Unauthenticated CI/CD Takeover
TeamCity CVE-2026-63077 RCE lets an unauthenticated attacker send a single crafted request to a TeamCity On-Premises server and execute operating system commands — no login, no valid session, no user interaction. CISA added it to the Known Exploited Vulnerabilities catalog on August 5 with a three-day remediation deadline, and exploitation is now active in the…
Read MoreKeyv npm Supply Chain Attack Hits 2 Billion Installs
The Keyv npm supply chain attack compromised a single GitHub maintainer account and used it to push a credential-stealing worm into hundreds of widely used caching packages. By August 5, trackers put the count at 868 packages and 1,381 versions, spanning a combined 2 billion-plus monthly installs — the largest software supply-chain incident DIESEC has…
Read MoreStadler Rail Everest Ransomware: SFr10m Demand Refused
The Stadler Rail Everest ransomware incident shows what a mature extortion response looks like: the Swiss train manufacturer confirmed that the Everest group stole supplier technical data through a shared data-exchange platform and demanded roughly SFr10m (about $12.3M) — and Stadler refused outright, filing a criminal complaint instead of negotiating. What Happened Stadler Rail, an…
Read MoreGitLab Oj Spill RCE Exploit Goes Public
The GitLab Oj Spill RCE is now public: a working exploit chain and full technical writeup were released on July 24 for a remote-code-execution flaw that GitLab quietly patched six weeks earlier, on June 10. If your self-managed GitLab instance is still on 18.10.7 or older, any developer who can push a commit can now…
Read MoreAsyncAPI npm Supply Chain Attack: No Token Stolen
The AsyncAPI npm supply chain attack shows that neither of the two controls teams were told to trust — cryptographic provenance and blocking install scripts — actually stopped it: an attacker published four trojanized packages with valid SLSA/OIDC provenance attestations, without ever stealing an npm token, and the payload runs regardless of –ignore-scripts. What Happened…
Read More
