supply-chain Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain Unit 42 research reveals a significant shift in supply chain attacks, with attackers now targeting the tools and processes developers use throughout the software development lifecycle (SDLC). The ChainDrop npm worm exemplifies this trend, silently infiltrating developer environments and cloud infrastructure by exploiti… Palo Alto Unit 42 · Aug 21, 2026 High CVE-2024-3094supply chainnpmci/cd
supply-chain Trivy, Not LiteLLM Behind the 2,500 Org Compromise A sophisticated supply chain attack, initially linked to the LiteLLM malware, has impacted over 2,500 organizations, primarily through a compromise of the Trivy scanner. The attack, orchestrated by TeamPCP, exploited vul… SecurityWeek · Aug 14, 2026 High GEBRFRsupply-chainvulnerabilitycredential-theft
supply-chain Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack Over 2,500 organizations and 434,000 CI/CD pipelines were impacted by a supply chain attack involving the LiteLLM AI library. The attack stemmed from a compromised version of Aqua Security’s Trivy vulnerability scanner,… SecurityWeek · Aug 12, 2026 High supply chainaicredentials
vulnerability Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets Two vulnerabilities – one in Gemini CLI and another in Claude Code – have been discovered that allowed unprivileged attackers to execute code on CI runners, potentially exposing sensitive information. Gemini CLI allowed… The Hacker News · Aug 7, 2026 High CVE-2026-12537CVE-2026-54316ci/cdinput validationcommand injection
vulnerability Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability JetBrains TeamCity, a popular CI/CD platform, is experiencing a critical vulnerability (CVE-2026-63077) that allows unauthenticated attackers to execute commands on the server. CISA has added the vulnerability to its lis… SecurityWeek · Aug 6, 2026 Critical CVE-2026-63077vulnerabilityrcedeserialization
vulnerability Critical Code Execution Vulnerability Patched in TeamCity JetBrains has released patches to address a critical vulnerability (CVE-2026-63077) in TeamCity On-Premises, allowing unauthenticated attackers to execute code on the server. This flaw can lead to data breaches, configur… SecurityWeek · Jul 31, 2026 Critical CVE-2026-63077rcevulnerabilitypatch
threat-intel Attackers Are Learning to Live Off the AI Toolchain Attackers are increasingly leveraging AI coding assistants and CI/CD pipelines to hide malicious activity, a trend exemplified by the Sandworm_Mode worm. This ‘living off the AI toolchain’ approach makes detection incred… Dark Reading · Jul 22, 2026 High aimalwaresupply-chain
supply-chain Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking A new vulnerability, dubbed ‘Cordyceps,’ has been identified within CI/CD workflows across numerous open-source projects, allowing unauthorized access and control over developer repositories. The flaws, primarily found i… SecurityWeek · Jun 24, 2026 High ci/cdsupply chaingithub actions
vulnerability Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS Six vulnerabilities, dubbed Proto6, have been identified in protobuf.js, a JavaScript implementation of Protocol Buffers. These flaws could lead to remote code execution (RCE) and denial-of-service (DoS) attacks, primari… The Hacker News · Jun 10, 2026 High CVE-2026-44289CVE-2026-44290CVE-2026-44291node.jsprotobufrce
supply-chain Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories A sophisticated supply chain attack, orchestrated by the Miasma worm (a variant of Shai-Hulud), targeted 73 Microsoft GitHub repositories, primarily within the Azure organization. The attack, initially discovered through… Dark Reading · Jun 9, 2026 High supply chaingithubazure
threat-intel OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds This article discusses the launch of CVE Lite CLI, an open-source command-line security scanner developed by Sonu Kapoor to address the challenges of managing vulnerabilities within JavaScript and Typescript projects usi… SecurityWeek · Jun 5, 2026 Medium dependency-scanningvulnerabilityjavascript
supply-chain Supply Chain Compromises Impact Nx Console and GitHub Repositories CISA is responding to multiple supply chain attacks targeting developer ecosystems, specifically CI/CD pipelines. A malicious Nx Console VS Code extension compromised a GitHub employee, leading to data exfiltration, and… CISA Advisories · May 28, 2026 High CVE-2026-48027supply chainci/cdgithub
supply-chain ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems The ‘SymJack’ attack leverages AI coding agents as a supply chain delivery mechanism, exploiting developer trust in automation to inject malicious code into CI pipelines. Attackers gain control by compromising coding age… SecurityWeek · May 27, 2026 High USaicoding agentssupply chain
threat-intel Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images This article reports on the development of DockSec, an open-source tool designed to address the challenge of vulnerability detection in Docker images. The tool utilizes an LLM to correlate findings from multiple vulnerab… SecurityWeek · May 26, 2026 Medium dockervulnerabilityai
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th) TeamPCP, a threat actor, launched a sophisticated supply chain campaign involving the malicious publication of compromised code extensions and SDKs across multiple platforms, including GitHub, npm, and PyPI. This campaig… SANS Internet Storm Center · May 25, 2026 High CVE-2026-45321supply chaincredential theftdeveloper tools
supply-chain Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows A sophisticated cyberattack, dubbed Megalodon, has targeted over 5,500 GitHub repositories using malicious CI/CD workflows. The attacker leveraged throwaway accounts and forged author identities to exfiltrate sensitive d… The Hacker News · May 22, 2026 Critical IRILci/cdgithubsupply chain
supply-chain Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials A GitHub Actions workflow, actions-cool/issues-helper, was compromised through an imposter commit attack, allowing threat actors to steal CI/CD credentials from running workflows. The attack leveraged malicious code inje… The Hacker News · May 19, 2026 High USgithubci/cdsupply-chain
threat-intel Shai-Hulud Worm Clones Spread After Code Release The release of Shai-Hulud source code by TeamPCP, a financially motivated threat actor, has triggered the spread of clones targeting software developers and the open-source ecosystem. This incident highlights a new attac… Dark Reading · May 18, 2026 High supply-chainopen-sourcedeveloper
threat-intel Developer Workstations Are Now Part of the Software Supply Chain Recent attacks, including those mimicking the "mini Shai Hulud" and "Shai-Hulud 2.0" campaigns, have highlighted a growing threat: attackers targeting developer workstations to steal credentials and secrets from CI/CD pi… The Hacker News · May 18, 2026 High USdeveloper workstationssecretssupply chain
threat-intel Smashing Security podcast #463: This AI company leaked its own code. It’s also built something terrifying This article discusses a concerning trend where AI companies are inadvertently leaking their own code and becoming targets for malicious actors. Tanya Janca highlights the vulnerability of software developers, particular… Graham Cluley · Apr 15, 2026 High CAsupply chaindeveloper securitycredential theft