PROBABLYPWNED
Home/Tag/Supply Chain

Supply Chain

77 articles tagged with "Supply Chain"

Agentjacking Hijacks AI Coding Agents via Sentry MCP Injection
Vulnerabilities4 min read

Agentjacking Hijacks AI Coding Agents via Sentry MCP Injection

Researchers at Tenet Security discovered Agentjacking, an attack that tricks AI coding assistants like Claude Code and Cursor into executing arbitrary code through malicious Sentry error events.

Vulnerability DeskJun 14, 2026
EU Unveils Tech Sovereignty Package to Cut US, China Dependency
Announcements5 min read

EU Unveils Tech Sovereignty Package to Cut US, China Dependency

European Commission announces Chips Act 2.0 and Cloud and AI Development Act to reduce reliance on US cloud giants and Chinese telecom vendors. Four-tier trust framework for cloud services incoming.

ProbablyPwned Editorial TeamJun 5, 2026
VS Code Flaw Enabled One-Click GitHub Token Theft
Vulnerabilities4 min read

VS Code Flaw Enabled One-Click GitHub Token Theft

A vulnerability in GitHub.dev allowed attackers to steal GitHub OAuth tokens with full repo access via a single malicious link. Microsoft patched the flaw within 24 hours.

Vulnerability DeskJun 5, 2026
Flowise One-Click RCE — Import a Chatflow, Lose Your Server
Vulnerabilities3 min read

Flowise One-Click RCE — Import a Chatflow, Lose Your Server

CVE-2026-40933 (CVSS 9.9) allows attackers to compromise self-hosted Flowise AI agent builders by tricking users into importing a malicious chatflow. The payload executes during import without user action.

Vulnerability DeskMay 31, 2026
Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours
Malware4 min read

Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours

Automated Megalodon campaign pushed 5,718 malicious commits to GitHub repos on May 18, injecting CI/CD workflows that exfiltrate cloud credentials, SSH keys, and secrets. SafeDep links it to TeamPCP.

Malware DeskMay 23, 2026
Laravel-Lang Supply Chain Attack Deploys Credential Stealer
Malware4 min read

Laravel-Lang Supply Chain Attack Deploys Credential Stealer

Attackers compromised 700+ versions of Laravel-Lang PHP packages via tag poisoning, deploying a sophisticated stealer targeting cloud credentials, crypto wallets, and browser data. Packagist pulled affected versions.

Malware DeskMay 23, 2026
Nx Console VS Code Extension Hijacked for 11 Minutes
Malware4 min read

Nx Console VS Code Extension Hijacked for 11 Minutes

Attackers published malicious Nx Console 18.95.0 to VS Code Marketplace, stealing developer credentials via triple-channel exfiltration and Sigstore-signed npm package poisoning.

Malware DeskMay 19, 2026
12 Critical Flaws in vm2 Node.js Sandbox Enable Host Takeover
Vulnerabilities4 min read

12 Critical Flaws in vm2 Node.js Sandbox Enable Host Takeover

Security researchers disclosed 12 sandbox escape vulnerabilities in vm2, including three with CVSS 10.0 scores. The popular JavaScript isolation library can no longer be trusted to contain untrusted code.

Vulnerability DeskMay 8, 2026
Vercel Breach Traced to Compromised Third-Party OAuth App
Data Breaches4 min read

Vercel Breach Traced to Compromised Third-Party OAuth App

Compromised Google Workspace OAuth app 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj breached Vercel, exposing API keys and source code. Hackers demand $2M; audit Workspace apps and rotate credentials.

Data Breach DeskApr 19, 2026
36 Fake Strapi Plugins Deploy Redis RCE and Credential Stealers
Malware4 min read

36 Fake Strapi Plugins Deploy Redis RCE and Credential Stealers

Coordinated npm supply chain attack deploys 36 malicious packages masquerading as Strapi CMS plugins. Attackers target cryptocurrency platforms with Redis exploitation, credential harvesting, and persistent backdoors.

Malware DeskApr 7, 2026
TeamPCP Hijacks Checkmarx KICS Using Stolen Trivy Tokens
Malware4 min read

TeamPCP Hijacks Checkmarx KICS Using Stolen Trivy Tokens

Stolen CI credentials from Trivy breach enabled TeamPCP to compromise Checkmarx KICS GitHub Actions, poisoning all 35 version tags with credential-stealing malware in four-hour window.

Malware DeskMar 25, 2026
CanisterWorm Adds Iran-Targeting Kubernetes Wiper
Malware4 min read

CanisterWorm Adds Iran-Targeting Kubernetes Wiper

TeamPCP's supply chain attack expands with a Kubernetes wiper that detects Iranian systems via timezone and locale, wiping clusters while backdooring everyone else.

Malware DeskMar 23, 2026