Practical Guidance For Securing Your Software Supply ChainThe Hacker News·Jun 26, 09:52 UTC · Jun 26, 2024Exploit / PoC60
3CX supply chain attack was the result of a previous supply chain attack, Mandiant saysCyberScoop·Apr 20, 13:10 UTC · Apr 20, 2023Exploit / PoC in the wild60
Benefits of blockchain pilot programs for risk management planningHelp Net Security·Jan 28, 00:00 UTC · Jan 28, 2020Exploit / PoC57
Eclypsium raises $25 million to protect businesses from breaches through supply chainsHelp Net Security·Jan 11, 11:58 UTC · Jan 11, 2024Exploit / PoC in the wild60
The Unknown Risks of The Software Supply Chain: A DeepThe Hacker News·Feb 17, 07:04 UTC · Feb 17, 2024Exploit / PoC60
Proactive software supply chain security becoming critical as threats riseHelp Net Security·Jan 26, 00:00 UTC · Jan 26, 2022Exploit / PoC60
Developer account body snatchers pose risks to the software supply chainCisco Talos·Oct 4, 12:51 UTC · Oct 4, 2022Exploit / PoC57
Supply chain challenges loom large in quantum race, White House official saysCyberScoop·Jul 29, 20:22 UTC · Jul 29, 2026Exploit / PoC in the wild60
Aqua Security strengthens software supply chain security with pipeline integrity scanningHelp Net Security·May 10, 00:00 UTC · May 10, 2023Exploit / PoC60
North Korean Supply Chain Threat is Booming, UK and South Korea WarnInfosecurity Magazine·Nov 23, 12:30 UTC · Nov 23, 2023Exploit / PoC60
White House floats law to shore up agencies’ digital supply chainCyberScoop·Jul 13, 23:34 UTC · Jul 13, 2018Exploit / PoC in the wild60
Hands-on Review: Myrror Security Code-Aware and AttackThe Hacker News·Feb 17, 07:01 UTC · Feb 17, 2024Exploit / PoC60
Securing open-source code supply chains may help prevent the next big cyberattackHelp Net Security·Nov 24, 00:00 UTC · Nov 24, 2021Exploit / PoC57
GUAC - A Google Open Source Project to secure software supply chainSecurity Affairs·Oct 21, 10:15 UTC · Oct 21, 2022Exploit / PoC57
Federal cyber chief: Supply chain security against foreign influence needs workCyberScoop·Dec 3, 21:34 UTC · Dec 3, 2019Exploit / PoC in the wild60
GrammaTech CodeSentry 3.0 improves software supply chain securityHelp Net Security·Jan 20, 00:00 UTC · Jan 20, 2022Exploit / PoC60
DHS, Apple push back on Bloomberg supply chain storyCyberScoop·Oct 8, 18:54 UTC · Oct 8, 2018Exploit / PoC in the wild60
U.S. officials say supply-chain threat is 'very real' regardless of Bloomberg story accuracyCyberScoop·Oct 10, 20:28 UTC · Oct 10, 2018Exploit / PoC in the wild60
Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploitedHelp Net Security·Apr 5, 00:00 UTC · Apr 5, 2026Exploit / PoC in the wildCVE-2026-35616CVE-2026-21643CVE-2026-20093+2 CVEs160
Coats: ODNI has seen 'no evidence' of supply chain hack detailed in Bloomberg storyCyberScoop·Oct 19, 12:41 UTC · Oct 19, 2018Exploit / PoC in the wild60
Google announces GUAC open source project on software supply chainsThe Record·Jan 4, 00:00 UTC · Jan 4, 2023Exploit / PoC60
NIST wants to the federal government to pay more attention to the supply chainCyberScoop·May 10, 14:00 UTC · May 10, 2018Exploit / PoC in the wild60
Open Source Supply Chain Attacks Surge 430%Infosecurity Magazine·Aug 13, 09:53 UTC · Aug 13, 2020Exploit / PoC in the wild60
DHS supply chain and CDM bills pass the HouseCyberScoop·Sep 5, 00:28 UTC · Sep 5, 2018Exploit / PoC in the wild60
Codecov dev tool hit in another supply chain hackCyberScoop·Apr 16, 16:21 UTC · Apr 16, 2021Exploit / PoC in the wild60
AI-generated code could be a disaster for the software supply chain. Here’s why.Ars Technica · Security·Apr 29, 11:15 UTC · Apr 29, 2025Exploit / PoC157
When ‘minimal impact’ isn’t reassuring: lessons from the largest npm supply chain compromiseCyberScoop·Sep 15, 13:21 UTC · Sep 15, 2025Exploit / PoC in the wild60
Downloads of known vulnerable open source components increase 120%Help Net Security·Sep 27, 00:00 UTC · Sep 27, 2018Exploit / PoC60
Surge in cyber attacks targeting open source software projectsHelp Net Security·Aug 13, 00:00 UTC · Aug 13, 2020Exploit / PoC in the wild60
Tj-actions Supply Chain Attack Traced Back to GitHub Token CompromiseInfosecurity Magazine·Apr 4, 12:00 UTC · Apr 4, 2025Exploit / PoC in the wildCVE-2025-3006660
Flaw in the Packagist PHP repository could have allowed a supply chain attackSecurity Affairs·Oct 4, 20:19 UTC · Oct 4, 2022Exploit / PoC in the wildCVE-2022-24828CVE-2021-2947260
Google Unveils Open Source Project to Improve Software Supply Chain SecurityInfosecurity Magazine·Oct 21, 17:00 UTC · Oct 21, 2022Exploit / PoC57
Phylum integrates with Sumo Logic to identify software supply chain attacksHelp Net Security·Dec 7, 00:00 UTC · Dec 7, 2023Exploit / PoC60
This firmware flaw was bad enough, but then researchers looked at the supply chainCyberScoop·Jul 19, 15:15 UTC · Jul 19, 2019Exploit / PoC60
Kusari Inspector improves supply chain securityHelp Net Security·Jun 18, 00:00 UTC · Jun 18, 2025Exploit / PoC in the wild60
North American utilities drill 'GridEx' brings record turnout — except from supply chain vendorsCyberScoop·Apr 2, 12:18 UTC · Apr 2, 2020Exploit / PoC in the wild60
Hidden risks in the financial sector's supply chainHelp Net Security·Mar 4, 07:00 UTC · Mar 4, 2026Exploit / PoC in the wild60
Rapid7 says attacker accessed its source code in Codecov supply chain hackCyberScoop·May 13, 19:55 UTC · May 13, 2021Exploit / PoC in the wild60
Don't expect Huawei on DHS's supply chain task force any time soonCyberScoop·Jun 24, 19:28 UTC · Jun 24, 2020Exploit / PoC in the wild60
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain AttacksThe Hacker News·Aug 19, 04:18 UTC · Aug 19, 2025Exploit / PoC157