Supply Chain Attacks

Login required for search functionality | Get a free-level account with Google/Microsoft single-sign-on.

5 reports

Recent Supply Chain Attacks Compromise LastPass, Mastra AI, Several Organizations

Recent supply chain attacks have compromised multiple organizations, including LastPass and the Mastra Artificial Intelligence framework. By exploiting vendor vulnerabilities and developer accounts, threat actors leverage initial breaches to target downstream networks, amplifying third-party risks.

Fake Business and Financial Documents Used in WhatsApp Malware Distribution Campaign

Threat actors use compromised WhatsApp accounts to distribute malicious files disguised as business documents. These scripts install management tools, granting remote access to devices. Organizations are advised to avoid unmanaged communication platforms.

Recent Updates on Supply Chain Attacks

Recent cascading supply chain attacks are targeting software ecosystems. By exploiting developer credentials, automated workflows, and open source repositories, threat actors achieve a massive downstream impact, compromising major artificial intelligence firms.

The Domino Effect of Recent Supply Chain Attacks

Recent supply chain attacks demonstrate a cascading effect, where threat actors like TeamPCP exploit compromised credentials and CI/CD vulnerabilities to infect downstream targets. Organizations must assume a breach if affected software was used and prioritize securing developer access.

Cloud Platform Vercel Confirmed Data Breach via Supply Chain Attack

Cloud platform Vercel confirmed a data breach after a supply chain attack on a third-party AI tool, Context.ai. Threat actors used stolen OAuth tokens to access internal systems. Enterprises are advised to revoke the Context.ai OAuth app and restrict broad third-party permission grants.