Posts Tagged ‘supply chain’
AsyncAPI npm Supply Chain Attack: No Token Stolen
The AsyncAPI npm supply chain attack shows that neither of the two controls teams were told to trust — cryptographic provenance and blocking install scripts — actually stopped it: an attacker published four trojanized packages with valid SLSA/OIDC provenance attestations, without ever stealing an npm token, and the payload runs regardless of –ignore-scripts. What Happened…
Read MorePolinRider Supply Chain Attack Hits 108 Packages
The PolinRider supply chain attack has been confirmed by Socket.dev, SecurityWeek and SC Media: a North Korea-linked actor has flooded four separate open-source ecosystems — npm, Packagist, Go modules and the Chrome Web Store — with 108 malicious packages designed to steal developer and cloud credentials. What Happened Researchers attribute the PolinRider supply chain attack…
Read MoreTop 5 Cybersecurity News Stories July 10, 2026
The five stories in this week’s Cybersecurity News Stories July 10, 2026 share a structural property: in each case, the system that was compromised or weaponised is one that the organisation had placed into a category other than “security risk.” An AI workflow orchestration platform is operational infrastructure for teams experimenting with automation — it…
Read MoreSimpleHelp CVE-2026-48558 RMM Bypass Exploited
A critical SimpleHelp CVE-2026-48558 authentication bypass is letting attackers forge a login token and seize a fully authenticated technician session in the remote monitoring and management (RMM) software thousands of managed service providers use to run client networks. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 29, and researchers have already…
Read More
