Skip to content
Threat Digest
Explainers Data Breaches Vulnerabilities & CVEs Ransomware & Malware
Nation-State Threats Security Tools Compliance & Policy Cloud Security Threat Intelligence

#supply-chain-attack

Abstract representation of code with glowing malicious elements, symbolizing a cyber attack on GitHub repositories.
Vulnerabilities & CVEs

GitHub Attack [5,561 Repos] Uses Malicious CI/CD Workflows

Forget shiny new features; the real news in tech is often how the bad guys are figuring out new ways to mess with our stuff. A recent GitHub attack, Megalodon, shows just how vulnerable our automated development pipelines have become.

5 min read 7 hours ago
Illustration of a stylized worm or sandworm tunneling through code packages.
Vulnerabilities & CVEs

170+ Packages Wormed: TeamPCP's Mini Shai-Hulud Campaign Explained

A sophisticated, self-propagating worm has silently infected over 170 open-source packages, marking a disturbing new escalation in supply chain attacks. This isn't just a breach; it's a breach of trust, and the implications are staggering.

6 min read 2 days, 6 hours ago
Diagram illustrating a supply chain attack with compromised dependencies leading to a company's code repository.
Data Breaches

Supply Chain Attack Hits Grafana Labs

The open-source world just got a stark reminder of its interconnected fragility. Grafana Labs confirmed a recent code breach stemmed directly from a compromise within the TanStack development ecosystem.

5 min read 2 days, 12 hours ago
Abstract representation of code and network connections with a red warning symbol.
Data Breaches

GitHub Breach: How One Malicious VS Code Extension Did This

A seemingly innocuous VS Code extension became the gateway for a devastating breach at GitHub, exposing thousands of internal repositories. This isn't just another headline; it's a wake-up call for the entire software supply chain.

5 min read 2 days, 16 hours ago
Visual Studio Code IDE interface with a red warning symbol overlayed, symbolizing a security breach.
Data Breaches

GitHub Breach: Malicious VS Code Extension Exposes 3,800 Repos

GitHub is grappling with a significant breach stemming from a compromised Visual Studio Code extension. The incident highlights the escalating risks within the developer tooling supply chain.

5 min read 3 days, 7 hours ago
Illustration of a digital lock being broken with code flowing out.
Data Breaches

GitHub Breach: TeamPCP Lists 4,000 Repositories For Sale

GitHub's internal source code is reportedly up for grabs on the dark web, and the company's scrambling to figure out what happened. This latest incident highlights the ever-present danger lurking in the supply chain.

6 min read 3 days, 16 hours ago
Abstract representation of digital data streams with a lock icon, symbolizing a data breach.
Data Breaches

NYC Health Data Breach: Biometrics, Bank Details Exposed

A months-long breach at NYC Health + Hospitals has compromised the data of 1.8 million people, exposing everything from medical histories to biometric identifiers.

7 min read 4 days, 6 hours ago
A screenshot of the VS Code editor with a warning symbol overlayed on the Nx Console extension icon.
Vulnerabilities & CVEs

Nx Console Hijacked: VS Code Developers Targeted

They say developers are paranoid. Turns out, they're right. A popular VS Code extension, Nx Console, just became the latest vector for a sophisticated credential stealer.

5 min read 4 days, 13 hours ago
Abstract digital network with interconnected nodes, some glowing red to indicate compromise.
Vulnerabilities & CVEs

Mini Shai-Hulud: Your Code is Now a Highway for Hackers

The digital equivalent of finding a Trojan horse in your code library just got a lot scarier. The Mini Shai-Hulud campaign is here, and it's not just about hitting tech giants; it's about every developer and every organization that relies on open-source software.

6 min read 4 days, 16 hours ago
Abstract representation of code being stolen from a server
Vulnerabilities & CVEs

GitHub Actions Hijacked: Your Code Now a Spyware Gateway

Forget the fancy code; the real news is that the tools you trust to build your software might now be the ones stealing your secrets. A clever hijacking of popular GitHub Actions means your CI/CD pipelines could be quietly coughing up credentials.

5 min read 4 days, 16 hours ago
Illustration of a computer screen displaying code with a menacing digital entity emerging from it.
Ransomware & Malware

npm Under Siege: Shai-Hulud's Unchecked Spread

A leaked malware strain is now fueling a fresh wave of attacks against the Node Package Manager. Developers' secrets and systems are increasingly at risk.

6 min read 5 days, 4 hours ago
Abstract representation of interconnected network nodes with warning symbols.
Vulnerabilities & CVEs

Exchange 0-Day & npm Worm: Are Your Dependencies Truly Secure?

A barrage of critical vulnerabilities, including a zero-day on Microsoft Exchange and a rapidly spreading npm worm, underscores the precarious state of digital supply chains. Are you prepared for the next wave?

5 min read 5 days, 4 hours ago
Page 1 of 4 Older →

Categories

Explainers Data Breaches Vulnerabilities & CVEs Ransomware & Malware Nation-State Threats Security Tools Compliance & Policy Cloud Security
Threat Digest

Threat intelligence. Zero noise.

More

  • RSS Feed
  • Sitemap
  • About
  • Editorial Process
  • Advertise

Legal

  • Privacy
  • Terms
  • Work With Us

Our Network

The AI Catchup AI & Machine Learning Threat Digest Cybersecurity Legal AI Beat Legal Tech Fintech Rundown Finance & Banking DevTools Feed Developer Tools Open Source Beat Open Source Fintech Dose Crypto & DeFi Chip Beat Semiconductors AdTech Beat Ad Technology Supply Chain Beat Logistics

© 2026 Threat Digest. All rights reserved.

🏠Home 🔍Search 🔖Saved 📂Categories
Privacy & cookies

We use a privacy-respecting analytics tool to count page views — no personal profiles, no ad tracking, no third-party cookies. Accept to help us understand which stories matter to readers.

Details