Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
10 results for “supply-chain”
BdThemes plugins supply-chain hack creates rogue WordPress admins
A supply-chain attack compromised BdThemes' infrastructure to inject malicious code into WordPress admin interfaces, enabling unauthorized administrator account creation.
Aug 11, 2026
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A weekly cybersecurity news recap highlights recurring vulnerabilities, supply-chain compromises, and default-trust risks in AI-adjacent systems without reporting a specific new incident or policy change.
Aug 10, 2026
Massive ChainDrop npm supply-chain attack infects hundreds of packages
A self-propagating malware campaign dubbed 'ChainDrop' has infected over 1,300 npm packages totaling 2 billion monthly downloads, representing a large-scale, automated supply-chain compromise in the JavaScript ecosystem.
Aug 4, 2026
Online ad firm Adform’s script compromised to steal cryptocurrency
Adform, an online advertising firm, experienced a supply-chain compromise that injected malicious cryptocurrency-stealing scripts into websites using its ad platform, enabling attackers to hijack clipboard-copied crypto wallet addresses.
Aug 1, 2026
Judge says Trump admin still lacks evidence for Anthropic ‘supply-chain risk’ label
A federal judge ruled that the Trump administration failed to provide sufficient evidence to support its designation of Anthropic as a 'supply-chain risk', undermining the legal basis for banning its AI technology.
Jul 31, 2026
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon attributed recent npm supply-chain attacks involving malicious packages 'Debug' and 'Chalk' to North Korean state-sponsored actors, positioning itself as a key threat intelligence contributor in open-source security.
Jul 31, 2026
Freehand raises $75m for AI agents that manage supply chain spend
Freehand, an AI startup serving enterprise supply-chain finance clients like Meta and Pfizer, secured $75M in new funding to scale its AI agent platform.
Jul 30, 2026
Ernst & Young data breach claimed by ShinyHunters extortion gang
A cybersecurity incident involving Ernst & Young was exploited by the ShinyHunters extortion gang, which claims to have accessed internal systems through a supply-chain compromise.
Jul 27, 2026
GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub and PyPI implemented time-based defenses in Dependabot to mitigate supply-chain attacks by limiting the window for malicious package substitution.
Jul 26, 2026
AsyncAPI npm packages infected with credential-stealing malware
Five compromised AsyncAPI npm packages delivered credential-stealing malware via a supply-chain attack, exposing developers and downstream systems to unauthorized access and data theft.
Jul 15, 2026