Structured data rendered for: CollectionPage
Back to Blog
12 posts with this tag

#Supply Chain

12 posts
Hugging Face Diffusers flaws turn model loading into a code execution risk

Hugging Face Diffusers flaws turn model loading into a code execution risk

Hugging Face Diffusers flaws turn model loading into a code execution risk Security researchers have disclosed a set of Hugging Face Diffusers vulnerabilities t...

Last updated on 03/08/2026 at 8:05 AM
6 min read
JetBrains TeamCity RCE Puts Self-Hosted CI/CD Servers on an Urgent Patch Clock

JetBrains TeamCity RCE Puts Self-Hosted CI/CD Servers on an Urgent Patch Clock

JetBrains TeamCity RCE Puts Self-Hosted CI/CD Servers on an Urgent Patch Clock JetBrains has released fixes for CVE-2026-63077, a critical unauthenticated [remo...

Last updated on 17/08/2026 at 12:56 PM
7 min read

U-Boot FIT signature flaws expose a fragile pre-OS trust boundary

U-Boot FIT signature flaws expose a fragile pre-OS trust boundary Firmware security company Binarly has disclosed six vulnerabilities in U-Boot's FIT signature...

Last updated on 17/08/2026 at 12:56 PM
8 min read
Vect and TeamPCP show how stolen build secrets become ransomware access

Vect and TeamPCP show how stolen build secrets become ransomware access

Vect and TeamPCP show how stolen build secrets become ransomware access Sophos says two cybercrime groups, Vect and TeamPCP, have formalized a partnership that...

Last updated on 05/07/2026 at 8:07 AM
7 min read
GitHub breach forces GHES signing-key rotation

GitHub breach forces GHES signing-key rotation

GitHub breach forces GHES signing-key rotation | 2026 GitHub's May 2026 incident is a useful reminder that developer tooling is now part of the production trust...

Last updated on 17/08/2026 at 12:56 PM
6 min read
DAEMON Tools supply-chain attack turns trusted installers into a malware delivery path

DAEMON Tools supply-chain attack turns trusted installers into a malware delivery path

DAEMON Tools supply-chain attack turns trusted installers into a malware delivery path The most important part of the DAEMON Tools incident is not that malware...

Last updated on 17/08/2026 at 12:56 PM
5 min read
PyTorch Lightning supply-chain compromise puts AI developer credentials at risk

PyTorch Lightning supply-chain compromise puts AI developer credentials at risk

PyTorch Lightning supply-chain compromise puts AI developer credentials at risk The most dangerous supply-chain incidents are not always the ones that hit opera...

Last updated on 17/08/2026 at 12:56 PM
5 min read
Bitwarden CLI npm compromise exposes CI/CD credential risk

Bitwarden CLI npm compromise exposes CI/CD credential risk

Bitwarden CLI npm compromise exposes CI/CD credential risk A brief compromise of the Bitwarden CLI npm distribution is still a high-priority defender story beca...

Last updated on 17/08/2026 at 12:56 PM
5 min read
Critical protobuf.js flaw turns untrusted schemas into JavaScript code execution

Critical protobuf.js flaw turns untrusted schemas into JavaScript code execution

Critical protobuf.js flaw turns untrusted schemas into JavaScript code execution A newly disclosed protobuf.js issue deserves attention well beyond the JavaScri...

Last updated on 17/08/2026 at 12:56 PM
5 min read
CPUID breach turned CPU-Z and HWMonitor into a malware delivery path

CPUID breach turned CPU-Z and HWMonitor into a malware delivery path

CPUID breach turned CPU-Z and HWMonitor into a malware delivery path Executive summary A compromise of the CPUID website briefly turned trusted download links f...

Last updated on 17/08/2026 at 12:56 PM
5 min read
TELUS Digital breach: ShinyHunters claims 1PB data theft

TELUS Digital breach: ShinyHunters claims 1PB data theft

TELUS Digital breach: ShinyHunters claims 1PB data theft | 2026 Executive Summary TELUS Digital confirmed on March 12, 2026 that it is investigating unauthorize...

Last updated on 17/08/2026 at 12:55 PM
7 min read
Chrome Extension Supply-Chain Attack: ShotBird and QuickLens

Chrome Extension Supply-Chain Attack: ShotBird and QuickLens

Chrome Extension Supply-Chain Attack: ShotBird and QuickLens | 2026 Executive Summary ShotBird and QuickLens, two Chrome extensions that were previously legitim...

Last updated on 17/08/2026 at 12:55 PM
8 min read