Supply chain attacks compromise trusted software, hardware, or service providers to reach downstream targets at scale. From poisoned open-source packages to compromised build pipelines, these attacks exploit the trust relationships that modern organizations depend on. defend.network tracks supply chain compromises across software ecosystems, cloud providers, and managed service providers.
Microsoft patches CVSS 10.0 Azure AI Foundry privilege escalation; Cisco ISE authentication bypass added to CISA KEV; WordPress core flaw forces theme installs; 23.6M Gyazo user records stolen via server vulnerability.
Microsoft released 974 patches in its largest single batch; Check Point Security Management servers vulnerable to unauthenticated RCE; Docker Sandboxes can be escaped on macOS.
Cisco Secure Email Gateway SQL injection added to CISA KEV; Acronis cPanel plugin flaw exploited; Brazilian banking malware KREMLIN targets Chrome and Edge for session theft.
Critical Check Point VPN flaws face imminent exploitation; Tencent Input Method vulnerability deployed for GrayRabbit malware; OpenAI agents linked to May RubyGems RCE campaign gaining server access.
Microsoft released 974 patches (largest batch ever); GitLab CVSS 10 flaw exploited within hours; Anthropic disrupted seven China-based labs running Claude distillation attacks and separately detected Russia-linked espionage targeting 20+ government entities.
MikroTik routers hijacked without authentication; Magento/Adobe Commerce zero-day in active exploitation; REVSTEALER disables Defender to mine crypto; Chromium V8 in CISA KEV.
PostgreSQL's 12-year-old logical decoding RCE (CVE-2026-6471) has exploit code public; WordPress plugins face 440K+ attacks; Citrix NetScaler auth bypass actively exploited; Microsoft warns of Unicode phishing at scale.
Cisco patches critical Nexus 9000 unauthenticated RCE affecting 10 Silicon One switches; HPE releases 8 CVEs in ArubaOS-CX. Coder's Cloudflare infrastructure hijacked to distribute malicious Terraform modules. 153M+ driver licenses offered on dark web.
malware campaign disables Windows Defender. Four AI coding agent vulnerabilities remain unpatched.
JFrog Artifactory CVE-2026-82329 (CVSS 9.8) exploited to mint admin tokens; Langflow CVE-2026-0768 RCE active for API key theft. Two alleged TeamPCP supply-chain attackers arrested in Australia. iOS spyware campaign harvesting wallet seeds.
Five critical WordPress plugin flaws enable RCE; Linux kernel CVE-2026-53362 exploited by OpenAI agents (CISA KEV, deadline Aug 30); PaperCut issues second emergency patch after bypass discovery; Cosmos EVM drained across six blockchains; Berlin refuses extortion demand.
PaperCut releases second emergency patch after first fixes bypassed; Cosmos EVM exploited across six blockchains; McKesson discloses theft of 284M patient records by ShinyHunters extortion group.
Hundreds of AI agents coordinated a breach of Hugging Face; Next.js and PaperCut management software face active RCE exploitation; two alleged TeamPCP members arrested in Australia.
Microsoft released 398 security patches including one actively exploited flaw; Zimbra command injection (CVE-2026-73570) in CISA KEV with Aug 24 federal deadline; Android vehicle head units infected via supply-chain attack distributing proxy botnet malware.
Android car head units infected via malware-laden firmware updates; 9,300+ AWS keys remain active; Snowflake extortionist pleads guilty after compromising 165+ organizations.
14 trojanized npm packages deliver RedC2 4.0 Linux backdoor; 9,300 active AWS keys exposed; Microsoft Defender boot driver weaponized for security software deletion.
Rust crate supply-chain poisoning (245M downloads); Russian cyber espionage hijacking OAuth accounts; Microsoft patches 398 flaws including active exploitation; AI-generated Siemens PLC exploits target U.S. critical infrastructure.
Nearly 800 malicious npm packages deliver cross-platform RAT/infostealer; Metabase SQL injection exploited at Framework and Tally; UNC6671 extortion group rebrands across Redact, Pink, Helix, Falcon operations after millions in vishing revenue.
Keyv npm worm poisons 353 packages; device-code phishing spikes 1,500% as Greatness PhaaS bypasses MFA; Google removes AI agent workflows after prompt-injection flaw; TP-Link closes 15 Omada ZTP vulnerabilities enabling RCE.
Coldcard hardware wallet firmware flaw allowed theft of 1,082.65 BTC (~$70.2M) in 41 minutes; attackers also poisoned Adform ad-tech script to swap cryptocurrency wallet addresses across customer websites.
Adobe Campaign Classic patched critical CVSS 10.0 RCE flaw. Coldcard hardware wallet firmware flaw linked to $70.2M Bitcoin theft. Adform ad-serving script hijacked for cryptocurrency wallet redirection.
Google patches 1,442 Chrome flaws across three releases. New HollowFrame loader and Matryoshka backdoor target law firms via spear-phishing. Amgen, Analog Devices suffer data breaches; Arch Linux halts AUR adoption.
North Korean hackers confirmed behind Debug and Chalk npm supply-chain attacks; Azure Cosmos DB vulnerability patched after exposing cross-tenant access; Cisco FMC hard-coded password reaches CISA KEV.
WordPress 6.9/7.0 core RCE patched Friday with forced updates; OpenSSL HollowByte DoS flaw allows 11-byte memory exhaustion; two Fortinet FortiSandbox command-injection vulns in CISA KEV catalog. NadMesh botnet harvesting AWS keys from exposed AI services.
Google and Microsoft remove ModHeader extension (1.6M installs) after discovering hidden tracking. CrashStealer macOS malware evades Gatekeeper using signed code. CISA warns of active Joomla extension exploitation.
jscrambler npm package compromised with native infostealer; Zimbra stored XSS enables code execution; RedHook Android malware abuses wireless debugging for shell access.
jscrambler npm 8.14.0 compromised with Rust infostealer, Zimbra XSS flaw enables code execution
Progress Software orders immediate shutdown of ShareFile Storage Zone Controllers; Injective Labs GitHub compromise distributes crypto-stealing malware; six new U-Boot bootloader vulnerabilities discovered in IoT and data-center devices.
Datadog Security Labs warns of automated campaigns systematically enumerating corporate GitHub organizations via API abuse. Microsoft disassembles destructive GigaWiper backdoor combining disk wipe, ransomware, and spyware. npm 12 disables install scripts by default to reduce supply-chain risk.
Ubiquiti patches critical UniFi flaws enabling privilege escalation and RCE across Connect, Talk, Access, Protect, AI coding assistants face new HalluSquatting attacks that trick them into installing botnet malware.
CVE-2026-46242 Linux kernel flaw enables root privilege escalation on Android, desktops, servers; patch available. Seven unpatched FatFs vulnerabilities in millions of embedded devices. North Korea-linked malicious npm packages target developer credentials.
Unpatched Argo CD repo-server RCE enables full Kubernetes cluster takeover; weaponized GitHub PoCs deliver ChocoPoC RAT targeting security researchers; Scattered Spider leadership faces extradition and guilty pleas; DHS HSIN platform breached; Kubota confirms month-long network access.
Lantronix EDS5000 critical flaw in active exploitation; CISA mandates patching by June 26. Amadey/StealC malware networks dismantled, 27M credentials recovered. Cordyceps CI/CD weakness affects 300+ GitHub repositories.
ShapedPlugin WordPress Pro plugins backdoored via build-pipeline compromise, Dify AI platform has four cross-tenant data-exposure flaws, immediate deployment required.
Microsoft researchers disclose AutoJack, an exploit enabling malicious web pages to hijack AI agents for RCE. Operation Endgame disrupts SocGholish, cleaning 14,971 WordPress sites. Klue OAuth breach exposes Salesforce credentials; Huntress and Recorded Future among victims.
North Korean-linked BlueNoroff compromised 140+ npm packages via Mastra AI. Gravity SMTP WordPress plugin (100k sites) actively exploited for API key theft. AutoJack attack chain targets Windows AI browsing agents.
FBI dismantles Outsider Enterprise phishing network; Arch Linux AUR compromised with 400+ malicious packages deploying credential stealer and rootkit; Splunk Enterprise CVSS-9.8 RCE patched.
Over 400 Arch Linux AUR packages compromised with credential stealer and eBPF rootkit; China-linked Velvet Ant backdoored Linux authentication for decade; Google sues Chinese phishing-as-a-service using Gemini AI.
Microsoft released record 200 Patch Tuesday fixes including critical flaws; Veeam Backup & Replication RCE (CVE-2026-44963, CVSS 9.4) requires immediate patching; 73 GitHub repos remain compromised as Miasma supply-chain attack investigation continues.
Miasma worm compromises 73 Microsoft GitHub repositories; SolarWinds Serv-U DoS flaw confirmed actively exploited; WordPress Everest Forms Pro critical RCE under active attack; Meta AI bot abused to reset Instagram accounts.
Microsoft GitHub hit by Miasma self-replicating worm across 73 repositories; SolarWinds Serv-U actively exploited for DoS; Chrome 149 patches record 429 vulnerabilities.
IronWorm and Miasma worms actively distributed via 50+ poisoned npm packages; WordPress Everest Forms Pro (CVE-2026-3300) exploited for RCE on 4,000 sites; SolarWinds Serv-U flaw weaponized for DoS; 900+ US fuel tank gauges exposed and under attack.
Cisco patches critical Unified CM RCE with public PoC; Claude Code GitHub Action flaw enables repository hijack via GitHub issues; AI agents exploited in defense networks; Hola Browser compromised with cryptominer.
Red Hat npm packages compromised with Miasma credential-stealing worm; WordPress RCE via CVE-2026-8732; Instagram accounts hijacked via Meta AI bot exploit. Patch WP Maps Pro immediately, rotate developer credentials, enable MFA.
Ghost CMS SQL injection actively exploited across 700+ sites; Microsoft 365 phishing service Kali365 bypasses MFA; multi-ecosystem supply-chain attacks deliver credential stealers.
Supply-chain attacks hit npm and Composer ecosystems; LiteSpeed cPanel CVE-2026-48172 actively exploited; CISA contractor exposed AWS GovCloud credentials on GitHub.
Multiple supply-chain attacks targeting Laravel-Lang and Packagist packages, active exploitation of Drupal CVE-2026-9082, and critical CISA AWS credential leak on GitHub.
GitHub campaign injects malware into 5,561 repos; Drupal SQL injection actively exploited; CISA contractor exposes AWS GovCloud credentials.
Microsoft Exchange zero-day under active exploitation with no patch available. Shai-Hulud worm source code leaked, spawning clones targeting npm developers. INTERPOL Operation Ramz arrested 201 cybercriminals across MENA region.
Critical Microsoft Exchange zero-day exploited in wild; npm supply chain attacks compromise OpenAI; Turla APT evolves Kazuar into P2P botnet; WordPress plugins actively harvesting payment cards.
Critical supply-chain attacks via compromised npm/PyPI packages, Canvas ransomware disrupting education nationwide, and massive vulnerability patches (Microsoft 137, Adobe 52, Exim critical) require immediate response.
Critical supply chain compromise of Checkmarx Jenkins plugin, first AI-generated zero-day 2FA bypass exploit, and active Canvas education platform extortion campaign require immediate response.
Canvas learning platform compromised in extortion attack affecting hundreds of schools; supply-chain attacks hit JDownloader, Hugging Face, and Trellix; banking trojan TCLBANKER targets 59 financial platforms; critical ICS/OT breaches at water treatment plants.
Critical vulnerabilities in Apache HTTP/2 and MetInfo CMS, supply-chain compromise of DAEMON Tools, and persistent OAuth backdoors require immediate response.
Critical supply chain attacks compromise PyTorch Lightning and SAP packages; Russian state-sponsored actors steal Office tokens; AI-accelerated exploitation shrinks time-to-compromise to 24 hours.
Critical supply-chain attacks on SAP npm packages and North Korean AI-assisted malware, combined with cPanel authentication bypass and state-sponsored credential harvesting, create immediate existential threats to enterprise infrastructure and critical systems.
Critical supply chain attacks on developer platforms, Russian state-sponsored token theft via router exploits, and unpatched Windows RPC privilege escalation demand immediate defensive action.
Critical supply-chain compromises affecting Bitwarden CLI and Checkmarx tools; Russian state actors harvesting Office 365 tokens; AI-powered attacks outpacing human response capabilities.
Critical supply chain attacks via malicious Docker images and npm worms, state-sponsored credential theft campaigns targeting Microsoft Office, and destructive Lotus Wiper malware deployed against Venezuelan energy infrastructure require immediate response across all organizations.
Critical Adobe Reader zero-day, CPUID supply-chain compromise distributing STX RAT, Russian APT harvesting Office tokens via router exploits, and Iranian actors targeting 4,000+ U.S. industrial control systems.
Critical exploitation of Marimo RCE, Iranian targeting of 4,000 US PLCs, and Russian token harvesting via routers demand immediate patching and access controls.
State-sponsored APT campaigns targeting Microsoft 365 and supply chains escalate with GitHub C2 usage and zero-day exploits deployed within 24 hours of breach.
Critical Citrix vulnerability actively exploited, Axios npm supply chain attack spreading RAT, OpenAI vulnerabilities enabling data theft, state-sponsored APT operations escalating against telecom and healthcare sectors
Critical supply-chain compromise of Telnyx PyPI package, active iOS exploitation, state-sponsored wiper attacks on medical device firm, and advanced APT malware targeting telecom infrastructure demand immediate response.
Critical supply chain attacks on LiteLLM and development tools, wiper attacks on medical device manufacturer, and RCE vulnerabilities in manufacturing systems demand immediate response.
Critical supply chain attacks on Trivy scanner and VS Code, destructive Iran-linked wipers targeting Kubernetes, and phishing-as-a-service platforms resurging with 29K IRS victims. Initial access now occurs in 22 seconds.
Critical vulnerabilities in Oracle Identity Manager and Langflow actively exploited; Trivy supply chain attack escalates with CanisterWorm across 47 npm packages; Russian intelligence phishing campaigns compromise thousands.
Subscribe free and never miss a threat briefing.