Shadow code may pose a serious supply chain risk. Sampling 4,300 websites and applications ranked by traffic, researchers discovered that each website had an average of 12 third-party scripts and three fourth-party scripts.
Publishing platform Substack has disclosed a data breach that leaked nearly 700,000 user records after an unauthorized third-party exploited a security flaw.
Hackers injected malicious code into nearly a dozen 20 NPM packages with billions of weekly downloads in a software supply chain attack after phishing a maintainer’s account.
A very commonly used VoIP telephony system has been compromised via trojans snuck in through an open source component, and the supply chain attack puts over half a million global businesses at risk.
Vulnerable IT service providers are becoming entry points for supply chain attacks as seen in the recent attack on Wipro. The attack follows closely after Wipro CEO declares "security cannot be a show stopper for business priorities".
Supply chain security is becoming an increasing concern in COVID-19 outbreak as new opportunities are provided to cyber criminals seeking to exploit vulnerabilities.
Supply chain vulnerability in the ThroughTek "Kalay" network, a cloud-based communications platform used by an estimated 83 million IoT devices, could allow for remote compromise and control.
Some privacy vault apps on Google Play Store are used as remote backdoor to harness devices for fake clicks in ad fraud scheme and to exfiltrate user data and files.
The CFAA case of Van Buren v. U.S. has concluded with a decision resulting in a clarification of how crimes involving "authorized access" are defined.
Meta is framing the lawsuit as an opening volley in a war against data scraping and invasive surveillance by law enforcement partners. The surveillance company has clearly gone farther than is usual given the creation of some 38,000 fake accounts.










