← ALL ARTICLES
// SUPPLY CHAIN

Supply Chain Intelligence

12 articles. Supply chain attack intelligence. Software supply chain compromises, dependency hijacking, and third-party vendor breaches across MENA, EU, and US.

🌍 GLOBAL CRITICAL

Axios npm Hijack: North Korea's UNC1069 Weaponized 100M Weekly Downloads via Social Engineering and WAVESHAPER.V2 RAT

North Korea's UNC1069 social-engineered the lead Axios maintainer, hijacking npm and GitHub accounts to deploy the WAVESHAPER.V2 RAT via 100M weekly downloads.

2026-03-31
🌍 GLOBAL CRITICAL

GlassWorm: 433 Compromised Components Across VSCode, GitHub, and npm - Self-Propagating Worm Spans Four Developer Ecosystems

A Russian-speaking actor deployed GlassWorm across 433 components in four developer ecosystems using invisible Unicode payloads and Solana blockchain C2.

2026-03-31
🌍 GLOBAL CRITICAL

Telnyx SDK Backdoored on PyPI: TeamPCP Hides Credential Stealer in WAV Audio Files

TeamPCP backdoored the Telnyx Python SDK using credentials stolen during the LiteLLM compromise. Payloads hidden via WAV steganography. Quarantined in 6 hours.

2026-03-29
πŸ‡¦πŸ‡ͺ MENA HIGH

NasirSecurity: Pro-Iranian Group Targets Gulf Energy Supply Chains

Pro-Iranian NasirSecurity claimed breaches of four Gulf energy firms. Resecurity traced the data to compromised supply chain vendors, not the majors.

2026-03-26
πŸ‡ΊπŸ‡Έ THREAT BRIEF HIGH

SitusAMC Supply Chain Breach Hits JPMorgan, Citi, Morgan Stanley

Hackers breached SitusAMC and exfiltrated SSNs, financial details tied to JPMorgan Chase, Citibank, Morgan Stanley. FBI investigation active.

2025-11-01
🌍 THREAT BRIEF CRITICAL

LiteLLM Backdoored on PyPI: TeamPCP Supply Chain Attack Targets AI Framework With 480M Downloads

TeamPCP backdoored LiteLLM on PyPI using credentials stolen from the Trivy compromise. 480M total downloads. .pth persistence infects all Python processes.

2026-03-24
🌍 THREAT BRIEF CRITICAL

Trivy Supply Chain Attack: Security Scanner Weaponized, 1,000+ Cloud Environments Infected

TeamPCP weaponized Aqua Security's Trivy scanner (CVE-2026-33634, CVSS 9.9), infecting 1,000+ cloud environments across five package ecosystems.

2026-03-19
🌍 THREAT BRIEF HIGH

Chrome Zero-Day CVE-2026-2441 Exploited in the Wild - Use-After-Free in CSS Engine

Google patched a high-severity Chrome zero-day after confirming active exploitation. CSSFontFeatureValuesMap use-after-free affecting all Chromium browsers.

2026-02-01
πŸ‡¦πŸ‡ͺ UAE PDPL CRITICAL

Oracle Cloud SSO Breach: 634 UAE Entities Compromised in Global Attack

A threat actor exploited CVE-2021-35587 in Oracle Cloud's SSO infrastructure, compromising 6M credentials globally including 634 UAE entities.

2025-03-01
πŸ‡΄πŸ‡² Oman PDPL

CC Energy Development: Clop/MOVEit Zero-Day Data Theft

Oman-based oil and gas operator CC Energy Development was compromised in Cl0p's mass exploitation of the MOVEit Transfer zero-day that hit 2,500+.

2023-05-01
πŸ‡ΈπŸ‡¦ Saudi PDPL

Saudi Aramco: 1TB Third-Party Data Leak

Threat actor 'ZeroX' exfiltrated 1TB via a compromised third-party contractor, exposing 14,000 employees' data and demanding a $50M ransom in cryptocurrency.

2021-06-01
πŸ‡ΆπŸ‡¦ Qatar

Qatar Airways: Privilege Club Data Exposed in SITA Supply Chain Breach

A supply chain attack on aviation IT provider SITA exposed frequent flyer data for Qatar Airways Privilege Club members. SITA serves ~90% of the world's.

2021-02-01