threat-intel Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix A 2024 safety recall for Bendix’s EC80 heavy-truck brake controller, initially issued to address memory corruption issues, has been revealed to contain a significant set of vulnerabilities, including a remotely accessibl… SecurityWeek · Aug 7, 2026 High USCAvulnerabilityremote-code-executiondenial-of-service
threat-intel TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign The threat actor known as TeamPCP has been active since 2020, engaging in a series of campaigns targeting internet-facing infrastructure and expanding into sophisticated supply chain attacks. Their tactics have evolved s… The Hacker News · Aug 7, 2026 High IRsupply-chainkubernetesreact
threat-intel ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories This week's 'ThreatsDay' bulletin highlights a diverse range of security threats, including a China-linked telecom risk, a multi-stage phishing attack leveraging ClickOnce files, a supply chain attack involving 846 softw… The Hacker News · Aug 6, 2026 High CVE-2025-21079CVE-2025-58486CVE-2026-25177CHUSsupply-chainmalwarephishing
vulnerability ABB Ability Zenon ABB has issued a security advisory regarding multiple vulnerabilities in its Ability Zenon industrial automation platform. These vulnerabilities, primarily related to MongoDB, could allow attackers to bypass security, cr… CISA Advisories · Aug 6, 2026 High CVE-2025-14847CVE-2020-7928CVE-2020-7921WOvulnerabilitydata-breachmalware
threat-intel CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps A vulnerability in the CryptoJS library's random number generator has led to approximately $5.7 million in cryptocurrency drains affecting five wallet applications. Coinspect discovered that the weak random number genera… The Hacker News · Aug 6, 2026 High cryptowalletvulnerability
threat-intel Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway A Chinese router vendor, Longchen, initially denied that its firmware contained backdoors, but subsequently paused downloads to address security concerns. This follows reports of potential vulnerabilities and a desire to… The Register · Aug 6, 2026 Medium CHUSsupply-chainrouterbackdoor
threat-intel Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says A House Committee investigation, spurred by the Salt Typhoon hack, revealed that Chinese telecommunications giants – China Mobile, China Unicom, and China Telecom – maintain a significant and deeply embedded presence in… The Record · Aug 5, 2026 High CHcybersecuritytelecomstate-sponsored
supply-chain Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th) A sophisticated supply-chain attack leveraging compromised npm packages (keyv and cacheable) has been active since August 4th, 2026. Attackers exploited a vulnerability to inject malicious code into widely used libraries… SANS Internet Storm Center · Aug 5, 2026 High supply-chainnpmcredential theft
threat-intel QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer A long-standing supply chain attack targeting QuickFox, a VPN tool used by overseas Chinese users, has been ongoing since August 2025. The attack, attributed to tactical overlaps with the Chinese state-sponsored threat a… The Hacker News · Aug 5, 2026 High CNsupply-chainmalwarechina
threat-intel Polish convenience store chain Żabka hacked through third-party account Polish convenience store chain Żabka was hacked through a third-party contractor's account, leading to the potential exposure of internal data and systems. While payment systems and customer data were reportedly unaffect… The Record · Aug 4, 2026 Medium PLsupply-chainthird-partydata-breach
threat-intel Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks A sophisticated npm worm, linked to the Keyv vulnerability and attributed to the Shai-Hulud threat actor family, has spread across hundreds of packages, injecting credential-stealing and malicious code. The worm leverage… The Hacker News · Aug 4, 2026 High npmsupply-chaincredential-stealing
threat-intel Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access A multi-wave campaign leveraging social engineering to deploy Remote Monitoring and Management (RMM) software, specifically ScreenConnect, is actively targeting users with fake Adobe and Zoom updates, as well as business… The Hacker News · Aug 4, 2026 High phishingmalwaresupply-chain
threat-intel The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software Palo Alto Unit 42’s research demonstrates a significant shift in vulnerability discovery due to the emergence of frontier AI. Their system, NOVA, autonomously analyzed 3,915 open-source projects in just two months, uncov… Palo Alto Unit 42 · Aug 4, 2026 High vulnerabilityopen-sourceai
threat-intel Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen A popular Bitcoin hardware wallet manufacturer, Coinkite, destroyed its remaining inventory after a firmware vulnerability was exploited, leading to the theft of over $88 million in Bitcoin. The vulnerability, discovered… The Record · Aug 3, 2026 Critical bitcoinhardware walletfirmware
supply-chain Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites Adform, an advertising technology company, suffered a supply-chain attack where attackers injected malicious JavaScript code into their tracking script, allowing them to swap cryptocurrency wallet addresses across custom… The Hacker News · Aug 1, 2026 High supply-chainjavascriptcryptocurrency
threat-intel In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research Several cybersecurity incidents and vulnerabilities were reported this week, ranging from a data breach at the UK Department for Education to supply-chain attacks linked to North Korea. OpenAI released a new open-source… SecurityWeek · Jul 31, 2026 High UNNOsupply-chainvulnerabilitycryptanalysis
threat-intel You were onto something with “It’s the Climb,” Miley This week's Threat Source newsletter highlights a significant spike in authentication abuse and sophisticated phishing tactics, driven by attackers leveraging QR codes and advanced platforms like ARToken to bypass multi-… Cisco Talos · Jul 30, 2026 High USphishingauthenticationransomware
vulnerability Schneider Electric IGSS Schneider Electric has identified and issued a security advisory (SEVD-2026-195-01) regarding a critical out-of-bounds write vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) p… CISA Advisories · Jul 30, 2026 High CVE-2026-12927scadaindustrial control systemscwe-787
threat-intel Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet Amazon has attributed the September 2025 compromise of npm packages debug and chalk, along with subsequent incidents involving typo-crypto and axios, to North Korea’s Sapphire Sleet group. While initial reports attribute… The Hacker News · Jul 30, 2026 High KPnpmthreat intelligencemalware
threat-intel When AppSec Scanners Become a Supply Chain Attack Vector Security scanners used in the software supply chain can be exploited to introduce vulnerabilities and compromise downstream systems. Researchers at ZeroPath discovered that attackers can craft malicious code repositories… Dark Reading · Jul 29, 2026 High supply-chainvulnerabilitysecurity