Výsledky hledání

téma: dodavatelský řetězec× typ: varování× v celém archivu zrušit filtry

15 karet z 15 položek CZ · EN/orig

1

Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties

Executive Summary Following disclosure of the TraderTraitor attack against LayerZero in April 2026, SentinelOne identified an additional victim with the same macOS backdoors. Our analysis explores the mechanics of these backdoors and the expanded targeting against a victim in the IT services sector with no relationship to cryptocurrency trading. We also identified more weaponized GitHub repositories from the social engineering schemes used to target job seekers in these campaigns. This report…

Apple Terraform GitHub US

tg: incident tg: varování tg: rozbor tp: malware tp: phishing tp: dodavatelský řetězec tp: špionáž

· SentinelLabs · Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties

2

Crypto customers targeted by scammers after email marketing provider breach

An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields. The incident was a supply-chain phishing campaign carried out through Brevo, an email marketing provider used by several cryptocurrency companies and other firms. Brevo initially said an attacker had gained access to 120 customer accounts, some of which were used to send phishing emails to the…

Brevo Trezor CoinTracking BitBox finance US

tg: incident tg: varování tg: zneužíváno tp: phishing tp: podvod tp: únik dat tp: dodavatelský řetězec

· Malwarebytes Labs · Crypto customers targeted by scammers after email marketing provider breach

2

1

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan,…

PyPI npm Docker GitHub zdravotnictví veřejná správa média US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: AI tp: identita

· Mandiant / Google TI · GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

1

@7nohe/openapi-react-query-codegen Compromised in Supply Chain Attack (Campaign)

On August 28, starting at approximately 2000 UTC eight malicious versions of the @7nohe/openapi-react-query-codegen package were published on npm and were available for approximately three hours. These malicious versions were trojanized with an updated version of the miasma ma...

@7nohe/openapi-react-query-codegen US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec

· Wiz Research · @7nohe/openapi-react-query-codegen Compromised in Supply Chain Attack (Campaign)

1

arrayref and Other Rust Crates Hijacked in Supply Chain Attack (Campaign)

On August 20, 2026, malicious versions of three Rust crates were published to crates.io from the account of their maintainer, droundy: arrayref@0.3.10, internment@0.8.7 and append-only-vec@0.1.9. The Rust Security Response Team does not believe the maintainer published them, a...

arrayref internment append-only-vec US

tg: incident tg: varování tp: malware tp: dodavatelský řetězec

· Wiz Research · arrayref and Other Rust Crates Hijacked in Supply Chain Attack (Campaign)

2

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

On August 4, 2026, Elastic Security Labs identified a new Shai-Hulud campaign targeting the maintainer of keyv, a widely used key-value storage library. The attackers trojanized the monorepo and embedded a self-propagating worm called CHAINDROP that uses stolen npm credentials to automatically backdoor every other package the maintainer had publish rights to. The reach of this compromise is significant: keyv alone received over 600 million downloads last month, with related packages compounding…

keyv flat-cache cacheable-request cacheable US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Elastic Security · Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

On August 4, 2026, Elastic Security Labs identified a new Shai-Hulud campaign targeting the maintainer of keyv, a widely used key-value storage library. The attackers trojanized the monorepo and embedded a self-propagating worm called CHAINDROP that uses stolen npm credentials to automatically backdoor every other package the maintainer had publish rights to. The reach of this compromise is significant: keyv alone received over 600 million downloads last month, with related packages compounding…

keyv flat-cache cacheable-request cacheable US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Elastic Security · Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

1

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

In this article Attack chain overviewMitigation and protection guidanceIndicators of compromise (IOC)Microsoft Defender XDR detectionsAdvanced hunting queriesLearn more Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including packages associated with major enterprise software ecosystems such as keyv, flat-cache, cache-manager, and others. The malicious releases contain a Mini Shai-Hulud…

npm US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Microsoft Security Blog · ChainDrop supply chain compromise: Anatomy of a self-propagating worm

1

New North Korean campaign uses fake coding interviews to steal developer credentials

Elastic Security Labs found a new Contagious Interview campaign, tracked as REF9403, hiding malware inside SVG image files using steganography. To our knowledge, this specific infection chain has not been previously documented. We found it after the DPRK-aligned group targeted our own community Slack workspace with a fake job posting and a "coding challenge" project. Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto wallet…

US

tg: varování tg: rozbor tp: malware tp: phishing tp: dodavatelský řetězec tp: špionáž

· Elastic Security · New North Korean campaign uses fake coding interviews to steal developer credentials

1

Supply Chain Attack: rilevata nuova ondata di compromissione pacchetti NPM

Rilevata una campagna su larga scala di compromissione della supply chain nell'ecosistema npm, denominata "Mini Shai-Hulud". L'attacco sfrutta un malware di tipo worm per infiltrarsi negli ambienti di sviluppo e nelle pipeline di Continuous Integration/Continuous Deployment (CI/CD). L'obiettivo primario è l'esfiltrazione di credenziali sensibili e la successiva propagazione automatizzata attraverso la pubblicazione di versioni malevole di pacchetti legittimi.

npm IT

tg: varování tp: malware tp: dodavatelský řetězec tp: identita

· CSIRT Itálie (ACN) · Supply Chain Attack: rilevata nuova ondata di compromissione pacchetti NPM

1

1

Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities

This blog discusses the steganography, cloud abuse, and email-based backdoors used against the Ukrainian defense supply chain in the latest Pawn Storm campaign that TrendAI™ Research observed and analyzed.

obrana veřejná správa JP

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: špionáž

· Trend Micro · Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities