Supply Chain Attack

AI Advances in Hacking as Defenders Deploy Counter-Agents
Google and security researchers revealed this week that attackers are using AI to find and exploit vulnerabilities, while defenders deploy AI agents to identify critical flaws faster than human teams.

Shai-Hulud npm Worm Targets TanStack Ecosystem With Destructive Payload
A new Shai-Hulud npm worm variant targeted 42 TanStack packages with a payload that steals credentials and threatens to wipe user home directories if stolen tokens are revoked.

Bitwarden CLI npm Package Compromised to Steal Developer Credentials
Bitwarden CLI compromised in a major security incident affecting developer credentials. The attack affected developers relying on the command-line tool for password vault operations.

Kaspersky Uncovers Hidden Attack Chains in Notepad++ Supply Chain Compromise
Kaspersky uncovers sophisticated Notepad++ supply chain attack with multiple hidden infection chains targeting organizations across Asia and Latin America, revealing critical security risks for global enterprises.
