Index live· 1,284 files · 148 editions
ForensicPost

Search the index

21 results
Try
Results for “Supply chain”Newest first
26-0811
File

Metabase Zero-Day Hit Five Companies Before the Flaw Was Disclosed

A CVSS 10.0 flaw in a reporting tool that stores the credentials for every warehouse behind it.

UnattributedCVE-2026-72898TechnologySupply chain
Sev 5TargetMetabase deploymentsActorUnattributedUSA
26-0717
File

AsyncAPI npm Compromise Ran Its Payload at Import, Not Install

Execution moved from install to import. The flag everyone added after the last campaign is still set, and no longer covers anything.

UnattributedImport-time payloadCloudSupply chain
Sev 4TargetAsyncAPI npm packagesActorUnattributed
26-0711
File

Malicious Jscrambler npm Versions Ran Native Binaries During Installation

Hidden native binaries executing at install, in a trusted package name. Compiled code is opaque to the review most registries actually perform.

UnattributedInstall-time binaryCloudSupply chain
Sev 4Targetjscrambler npm packageActorUnattributed
26-0606
File

A Worm in the Registry, Wearing a Vendor’s Name

A credential-stealing worm in a major vendor’s npm namespace. The namespace is the trust signal, and it delivered the reviewer’s assumption too.

UnattributedPackage compromiseCloudSupply chain
Sev 4TargetRed Hat-associated npm packagesActorUnattributed
26-0520
File

The Package That Steals the Pipeline That Builds the Package

Install-time credential theft that republishes itself using the rights it steals. Around 1,948 repositories were tied to exfiltration activity.

UnattributedInstall-time executionCloudSupply chain
Sev 4Targetnpm ecosystemActorUnattributed
26-0408
File

Enterprise Packages, Consumer Registry, No Separation

The most heavily governed system in the organisation, with a dependency path that has no governance attached to it.

UnattributedPackage compromiseCloudSupply chain
Sev 3TargetSAP-related npm packagesActorUnattributed
26-0331
File

Three Hundred Repositories, Reached With a Scanner’s Credentials

Scanner credentials reached 300+ repositories. Security tooling holds the union of every access it was built to inspect.

UnattributedStolen scanner credentialsCloudSupply chain
Sev 4TargetCiscoActorUnattributed
26-0321
File

Open-source Security Grants Cover About Four per Cent of the Maintenance Gap

Finding problems is fundable because it demonstrates capability. Fixing them is not, because it demonstrates nothing.

UnattributedFunding structureCloudSupply chain
Sev 3TargetOpen-source maintenanceActorUnattributed
26-0214
File

UFP Technologies Warned of Billing and Shipment Delays After Attack

A components maker warning of shipment delays. Qualification rules mean a medical supply chain cannot route around a supplier quickly.

Payouts KingRansomwareManufacturingManufacturing
Sev 3TargetUFP TechnologiesActorPayouts King
25-1103
File

Two Security Vendors in Two Months, by State Actors

Neither actor wanted the vendor. Both wanted what the vendor holds about everyone else — the same reach as a thousand intrusions, from one operation.

State-sponsoredSupply chain positioningCloudAnalysis
Sev 5TargetSecurity vendorsActorState-sponsored
25-1002b
File

Somebody Surveyed the Supply Chain

A breach notification records an affected count. It does not record what proportion of affected parties took which mitigating action.

ManufacturingVerification
Sev 3TargetJLR supply chainActorUnattributed
25-0928
File

UK Government Guarantee Unlocked £1.5 Billion for JLR's Supply Chain

An intrusion at one company produced a sovereign commitment in four weeks. Banks too large to fail got capital requirements in exchange; there is no equivalent here.

Scattered Lapsus$ HuntersManufacturingPolicy
Sev 5TargetJaguar Land Rover supply chainActorScattered Lapsus$ HuntersUnited Kingdom
25-0826
File

Cloudflare Says 104 API Tokens Were Exposed via Pasted Support Cases

Everyone scans repositories for committed secrets. Almost nobody scans the ticket system, which accumulates the same material indefinitely.

UNC6395OAuth token theftCloudSupply chain
Sev 4TargetCloudflare case recordsActorUNC6395USA
24-1104
File

Nokia Source Code Leaked From a Contractor’s Server With Default Logins

Nokia was right that its systems were not breached. Its code was published anyway.

IntelBrokerThird-party contractor serverTechnologySupply chain
Sev 3TargetNokiaActorIntelBrokerFinland
23-0712
File

JumpCloud Says a Nation-State Phish Reached Fewer Than Five Customers

The blast radius was tiny because the targeting was precise, not because the access was limited.

UNC4899Spear-phishingTechnologySupply chain
Sev 4TargetJumpCloudActorUNC4899
23-0420
File

Mandiant Traced the 3CX Compromise to a Trojanised X_TRADER Installer

Nobody assessing a phone-system vendor thinks to ask about its staff’s trading software.

UNC4736Trojanised X_TRADER installerTechnologySupply chain
Sev 5Target3CXActorUNC4736USA
23-0407
File

Researchers Found MSI Firmware Signing Keys in Data Leaked After a Ransom Refusal

A signing key burned into shipped hardware cannot be rotated the way a credential can.

Money MessageRansomwareManufacturingSupply chain
Sev 4TargetMicro-Star InternationalActorMoney Message
23-0329
File

Mandiant Says One Supply Chain Compromise Caused Another at 3CX

Code signing answers "did this come from the vendor". Here the answer was yes, and it was the wrong question.

UNC4736Supply chain compromiseTechnologySupply chain
Sev 5Target3CXActorUNC4736
22-1101
File

Dropbox Says Phishing Reached 130 Repositories After a Hardware Key Code Was Relayed

Cloudflare was not saved by the metal. It was saved by origin binding — and this key was not doing that.

UnattributedPhishing → OTP relayTechnologySupply chain
Sev 3TargetDropboxActorUnattributedUSA
22-0412
File

GitHub Says Stolen Heroku and Travis-CI Tokens Exposed Private Repositories at Dozens of Organisations

The security of a system is the security of everyone it has delegated to — a set nobody enumerates.

UnattributedStolen OAuth tokensTechnologySupply chain
Sev 4TargetGitHub customers, incl. npmActorUnattributedUSA
22-0301
File

One Plastic-Parts Supplier Stopped Fourteen Toyota Plants

Inventory is waste, so nothing is spare. That is the method working, and it is why one supplier stopped everything.

UnattributedManufacturingSupply chain
Sev 4TargetToyota Motor CorporationActorUnattributedJapan
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging