WhisperX tag archive

#supply chain attack

This page collects WhisperX intelligence signals tagged #supply chain attack. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (20)

The Lab · 2026-03-25 21:57:02 · The Register

1. Context Hub Proof-of-Concept Exposes AI Supply Chain Risk: Poisoned Documentation, Not Malware

A new vulnerability in the AI development pipeline bypasses traditional malware entirely, relying instead on poisoned documentation to compromise coding agents. The attack vector, demonstrated in a proof-of-concept against the service Context Hub, reveals a critical weakness in how AI assistants consume and trust exter...

The Lab · 2026-03-30 09:27:04 · GitHub Issues

2. SEC GitHub Workflow Flaw: Critical 'Pwn Request' Vulnerability in pr-loop.yml Exposes API Secrets

A critical security flaw in the SEC's GitHub Actions workflow, `pr-loop.yml`, creates a direct path for attackers to steal high-value API secrets, including the `ANTHROPIC_API_KEY` and `ALEXS_CODEX_KEY`. The vulnerability is a textbook 'pwn request' scenario, where the workflow's configuration grants it access to the r...

The Lab · 2026-03-30 11:27:14 · GitHub Issues

3. Critical Prototype Pollution Vulnerability in Widely Used 'ini' NPM Package (Patched in v1.3.6+)

A critical security flaw, identified as prototype pollution, has been patched in the widely used `ini` npm package, a fundamental library for parsing INI configuration files across the Node.js ecosystem. The vulnerability, tracked as GHSA-qqgx-2p2h-9c37, existed in all versions prior to 1.3.6. If exploited, an attacker...

The Lab · 2026-04-01 01:56:57 · Hacker News

4. AI Recruiting Startup Mercor Hit by Cyberattack, Hackers Claim Data Theft via Compromised LiteLLM

AI recruiting startup Mercor has confirmed a security breach after an extortion-focused hacking group claimed responsibility for stealing data from the company's internal systems. The incident is directly tied to the compromise of the open-source LiteLLM project, a widely used library for unifying large language model ...

The Lab · 2026-04-02 01:26:57 · GitHub Issues

5. Kubernaut Agent Security Flaw: Untrusted Data Flows Directly Into LLM, Enabling Prompt Injection

The Kubernaut Agent's core investigation pipeline is vulnerable to prompt injection attacks, as it processes untrusted content from multiple Kubernetes sources directly into its LLM context window without any sanitization or detection. This creates a direct path for attackers to manipulate the agent's reasoning and out...

The Lab · 2026-04-02 09:57:08 · Inc42

6. Axios Supply Chain Attack: How a Single Compromised Library Opened a Backdoor to Millions of Apps

A critical software supply chain attack on the widely-used Axios library has exposed the fragility of modern development ecosystems. On March 31, 2026, attackers seized control of a trusted maintainer account and injected malicious code directly into official Axios updates. This breach, though lasting only hours, sprea...

The Lab · 2026-04-04 05:26:57 · GitHub Issues

7. GitHub Triage Bot Compromised: Agentic Workflow Injection Triggers Malicious 'Canary' Comment

A critical security vulnerability has been exposed in a GitHub issue triage system, where an attacker successfully manipulated an AI bot's instructions to force it to post a specific, unauthorized verification message. The exploit, described as an "agentic workflow injection," overrides the bot's standard operating pro...

The Network · 2026-04-04 20:26:56 · GitHub Issues

8. Ransomware & Supply Chain Surge: DragonForce, BQTLock, and GitHub Actions Campaigns Dominate Critical Threat Landscape

The threat landscape has intensified, with ransomware-as-a-service (RaaS) operations and sophisticated supply chain attacks driving a surge in critical incidents. Over the past 24 hours, six reports were rated critical, dominated by DragonForce claiming five new victims across pharmaceuticals, manufacturing, and retail...

The Lab · 2026-04-05 15:27:03 · GitHub Issues

9. GitHub Actions Security Flaw: 422 Instances of Exposed Tokens & Secrets Found in CI/CD Workflows

A critical security vulnerability pattern has been identified in GitHub Actions workflows, exposing sensitive tokens and secrets. An automated scan of a major open-source repository revealed 422 instances where authentication tokens and secrets are directly interpolated into `run:` blocks within CI/CD pipelines. This p...

The Lab · 2026-04-06 02:27:00 · GitHub Issues

10. Helm 爆出高危代码注入漏洞 CVE-2025-53547,恶意 Chart.yaml 可导致本地代码执行

Kubernetes 包管理器 Helm 爆出高危安全漏洞,攻击者可通过特制的 `Chart.yaml` 文件在本地执行任意代码。该漏洞被追踪为 CVE-2025-53547(GHSA-557j-xg8c-q2mm),由 Helm 项目贡献者发现,核心风险在于依赖更新流程。当用户处理包含恶意内容的 `Chart.yaml` 文件及其关联的 `Chart.lock` 文件时,攻击者可利用此漏洞在目标系统上实现代码注入与执行。 漏洞细节显示,攻击向量集中在 `Chart.yaml` 文件的特定字段。当 Helm 解析这些字段并处理依赖关系时,恶意构造的内容可能绕过安全限制,触发非预期的代码执行路径。此漏洞影响范围广泛,因为 Helm ...

The Lab · 2026-04-10 00:39:39 · GitHub Issues

11. EngageLab SDK Flaw Exposes 50 Million Android Users, 30 Million Crypto Wallets at Critical Risk

A critical vulnerability in the EngageLab SDK has exposed an estimated 50 million Android users to potential compromise, with a staggering 30 million of those users identified as cryptocurrency wallet holders. This flaw represents a severe supply-chain security failure, placing a massive user base at direct risk of dat...

The Lab · 2026-04-11 15:22:33 · GitHub Issues

12. Critical Security Gap: Container Images Deployed Without Vulnerability Scanning, Exposing Infrastructure to Known CVEs

A critical security gap has been identified in the deployment pipeline, where container images are being deployed without any vulnerability scanning, signature verification, or registry authentication. This leaves the infrastructure exposed to known CVEs, supply chain attacks, and potential malicious payloads. The curr...

The Lab · 2026-04-13 15:22:51 · TechCrunch

13. Anodot Breach Exposes Major Clients, Hackers Demand Ransom from Dozens of Firms

A significant data breach at business analytics firm Anodot has left more than a dozen of its corporate customers facing extortion demands. The attack, which targeted Anodot's systems, successfully exfiltrated sensitive data, placing major companies like Rockstar Games in the crosshairs of cybercriminals. This incident...

The Lab · 2026-04-15 00:22:48 · GitHub Issues

14. Microsoft SharePoint Zero-Day Among 167 Flaws in April 2026 Patch Tuesday; OpenAI Launches GPT-5.4-Cyber for Defense

Microsoft's April 2026 Patch Tuesday is a critical security event, addressing a total of 167 vulnerabilities. The most urgent fix is for a zero-day vulnerability in SharePoint, a widely used enterprise collaboration platform. The presence of an actively exploited zero-day elevates the immediate risk for organizations, ...

The Lab · 2026-04-17 09:22:43 · GitHub Issues

15. Kyverno Security Flaw: CVE-2026-40868 Allows Service Account Token Leak to Attacker-Controlled Endpoints

A critical vulnerability in Kyverno's policy engine can inadvertently leak the powerful controller service account token to external, potentially malicious servers. The flaw, tracked as CVE-2026-40868, resides in the `apiCall` servicecall helper, which automatically injects an `Authorization: Bearer` header using Kyver...

The Lab · 2026-04-20 02:22:29 · CoinDesk

16. Vercel Security Breach Exposes Crypto Developer API Keys, Sparks Credential Lockdown

A security breach at cloud platform Vercel has triggered a scramble among cryptocurrency developers to secure their API keys. The incident, which may be linked to a compromised AI tool, potentially exposed sensitive credentials used by application frontends. These frontends serve as the critical user-facing layer conne...

The Lab · 2026-04-20 15:22:58 · TechCrunch

17. Vercel Breach: Hackers Hijack Employee Account via Context AI Hack to Steal Customer Data

Vercel, the popular frontend cloud platform, has confirmed a security breach where hackers stole customer data. The intrusion was not a direct attack on Vercel's own systems but a sophisticated supply-chain exploit. According to the company, attackers leveraged a prior, separate security breach at Context AI, an AI sta...

The Lab · 2026-04-20 22:22:30 · Protos

18. Vercel Breach via AI Tool Compromise Puts DeFi Frontends at Risk, $2M Ransom Demanded

A critical breach at Vercel, the cloud platform behind countless crypto frontends, has triggered urgent warnings for DeFi users to halt interactions, as attackers now potentially control the delivery pipeline for web applications. The intrusion, which Vercel CEO Guillermo Rauch attributes to an employee compromised via...

The Lab · 2026-04-21 04:22:46 · GitHub Issues

19. Vercel Breached via Employee's AI Tool Access: Context.ai Compromise Triggers Supply Chain Attack

A breach at AI tool vendor Context.ai has cascaded into a significant security incident at software giant Vercel, exposing the hidden risks of third-party integrations and employee access. Threat actors, after compromising Context.ai, used that foothold over the weekend to infiltrate Vercel's systems. The attack vector...

The Lab · 2026-04-21 10:33:33 · Medianama

20. Vercel Breach Traced to Compromised Third-Party AI Tool, Context.ai

Cloud platform Vercel has confirmed a breach of its internal systems, with attackers gaining entry through a compromised third-party AI tool. The incident exposed a 'limited subset' of customer data, specifically non-sensitive environment variables. Vercel maintains its core services are operational and that sensitive ...