Skip to content

Topic

Software Supply Chain Attacks

Cyberattacks that compromise trusted software distribution channels—installers, updates, or packages—to implant malware and reach downstream users.

Current stories

security3 publishers

Microsoft says China-linked operators hand-install NeedyMantis to keep hold of breached networks

Microsoft says China-linked operators have used NeedyMantis since at least October 2025 to keep access to telecom, university and government-linked networks. It goes in after the break-in, so defenders have to hunt for it inside networks already breached.

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 67%
Investor
Investor 11%

Reality

Evidence62
Adoption
Insufficient
Hype gap+18
Incentives40
Confidence60
security6 publishers

A backdoor that fires at cargo build: the arrayref poisoning puts your build boxes in scope

Malicious versions of three Rust crates ran code at compile time on August 20. Wiz says the infrastructure overlaps with DPRK operations, so the campaign should be treated as live.

Perspective Coverage

6 publishers
Builder
Builder 45%
Operator
Operator 48%
Investor
Investor 7%

Reality

Evidence80
Adoption30
Hype gap+25
Incentives55
Confidence75
security4 publishers

Two TrueConf Server flaws hit KEV, and BOD 26-04 turns them into a compromise check

CISA says CVE-2026-72529 and CVE-2026-72530 are under active exploitation. For federal civilian agencies, patching an exposed instance is only half of the obligation.

Perspective Coverage

4 publishers
Builder
Builder 25%
Operator
Operator 68%
Investor
Investor 7%

Reality

Evidence72
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence70
security8 publishers

The firmware updater in the dashboard: car head units enrolled into a proxy botnet

Kaspersky says malware reached Android car head units through the vendor's own update mechanism, using a flag that installs apps the device never had. The payload has no interface at all.

Perspective Coverage

8 publishers
Builder
Builder 36%
Operator
Operator 50%
Investor
Investor 14%

Reality

Evidence70
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence68
security1 publisher

Kothamine RAT tunnels its commands through Tailscale's tailcat

Malwarebytes found Kothamine, an undocumented Windows RAT hidden in malicious npm packages, that takes its 30-plus commands over Tailscale's tailcat. The encrypted channel leaves no command-and-control domain to block, pushing detection onto the endpoint.

Publishers:malwarebytes.com

Reality

Evidence60
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence58
security3 publishers

Attackers used a stolen Ribon app key to read shopper records across BigCommerce stores

A credential held by a third-party app vendor gave attackers four days of access to shopper records in BigCommerce stores. Cutting off that access meant uninstalling the app.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 62%
Investor
Investor 11%

Reality

Evidence60
Adoption
Insufficient
Hype gap+10
Incentives55
Confidence60

Earlier coverage

  1. GitGuardian finds a Shai-Hulud variant sweeping 469 credential paths across CI/CD and AI configs

    Security · September 3, 2026 · 1 publisher

  2. TeamPCP poisoned more than 1,000 packages with tactics anyone can copy

    Security · August 28, 2026 · 1 publisher

  3. Thirteen Packagist theme packages hand site visitors a WebKit-to-kernel iOS chain

    Security · September 1, 2026 · 2 publishers

  4. An attacker hijacked Hetzner routing for 33 hours to push malicious Virtualizor updates

    Security · September 1, 2026 · 5 publishers

  5. Pandex hooked a Fortune 500 agent four minutes after claiming a package name from llms.txt

    Build · September 2, 2026 · 1 publisher

  6. Thirteen Packagist themes push mobile ad-fraud, with an iPhone-only kernel exploit chain

    Build · August 31, 2026 · 1 publisher

  7. Jackal IV's 58 arrests cover under a third of the suspects INTERPOL identified

    Security · August 28, 2026 · 1 publisher

  8. TeamPCP hid its infostealer inside the scanners that audit everyone else's code

    Science · August 28, 2026 · 1 publisher

  9. A backdoored litellm release turns every CI job that installed it into a credential incident

    Science · August 28, 2026 · 1 publisher

  10. Oligo dates the crew behind ShadowRay 2.0's self-propagating botnet back to 2020

    Security · August 28, 2026 · 1 publisher

  11. No CVE required: DoFun head units installed whatever their MQTT update broker sent

    Build · August 22, 2026 · 1 publisher

  12. TrueConf's update directory is the delivery route: two KEV bugs, one swapped installer

    Build · August 21, 2026 · 1 publisher

  13. The runner holds your deploy keys, and nobody put it in the scanning program

    Build · August 21, 2026 · 1 publisher

  14. VECT 2.0 shreds anything over 128 KB, which makes paying its ransom pointless

    Leadership · August 18, 2026 · 1 publisher