Supply Chain Attacks

Feeds to Scour
SubscribedAll
Scoured 195 posts in 24.9 ms

NCSC Warns Of Rising Software Supply Chain Attacks Targeting Open-Source Packages

 🔗Supply Chain Intelligence
petri.com·

Software supply chain attacks: check your dependencies

 📦Dependency Confusion  Content type: Blog
ncsc.gov.uk·

Risky Bulletin: RubyGems adds dependency cooldowns to counter supply chain attacks

 🔒Cybersecurity
risky.biz·

The Median App and the Median User-Minute

 🔀Dispersion Trading
thediff.co
·

Massive PyPI Supply Chain Attack Harvests Cloud Credentials via Python Startup Hooks

 📦Dependency Confusion
orca.security·

Supply chain attack alert: .github/setup.js

 🔒Cybersecurity  Content type: Discussion

I Researched the Red Hat npm Incident — Here's What Every Developer Should Know

 📦Dependency Confusion  Content type: Code
github.com··DEV

someone actually leaked the Miasma supply chain attack toolkit source code on github

 🐙GitHub

Eliminating long-lived credentials with trusted publishing

 🔒Cybersecurity
lwn.net
·

Shai-Hulud copycat campaign targets Python developers through PyPI typosquatting

 💻WMI Abuse  Content type: Blog
about.gitlab.com·

New IronWorm malware hits 36 packages in npm supply-chain attack

 📦Dependency Confusion

Organizations struggle with third-party risk management after vendor approval | TechTarget

 🔗Supply Chain Intelligence  Content type: News
techtarget.com
·

OWASP Dependency-Track 5.0 Is Now Generally Available

 📋SBOM  Content type: Blog
owasp.org·

sinewaveai/agent-security-scanner-mcp: Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix.

 🔒Security  Content type: Code
github.com··Hacker News

VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

 📦Package Managers

The NVD Backlog Is a Symptom. Vulnerability Management Has a Scaling Problem

 🔓Vulnerability Research  Content type: Blog
nowsecure.com·

CVE Lite CLI closes dependency gap — but won't stop modern threats

 🔒Cybersecurity  Content type: Blog
reversinglabs.com·

IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks

 🐙GitHub
thehackernews.com·

Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

 📦Dependency Confusion
thehackernews.com·

New IronWorm Malware Hits 36 Packages In npm Supply-Chain Attack

 📦Dependency Confusion
it.slashdot.org·

Keyboard Shortcuts

Navigation

Next / previous item
j/k
Open post
oorEnter
Preview post
v

Post Actions

Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s

Recommendations

Add interest / feed
Enter
Not interested
x

Go to

Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/

General

Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help