WhisperX tag archive

#supplychain

This page collects WhisperX intelligence signals tagged #supplychain. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-03-27 12:27:33 · GitHub Issues

1. Critical DoS Flaw in node-forge Library (CVE-2026-33891) Prompts Urgent Update to v1.4.0

A critical security vulnerability in the widely-used `node-forge` cryptography library has been disclosed, prompting an urgent update to version 1.4.0. The flaw, rated HIGH severity, is a Denial of Service (DoS) vulnerability within the `BigInteger.modInverse()` function. When called with a zero value, the function ent...

The Lab · 2026-04-07 16:27:24 · GitHub Issues

2. Node-Forge 1.4.0 Patches Critical DoS Flaw (CVE-2026-33891) in `BigInteger.modInverse()`

A critical security update for the widely-used `node-forge` cryptography library patches a high-severity Denial of Service (DoS) vulnerability. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function, which is inherited from the bundled `jsbn` library. When this function is called with a ...

The Lab · 2026-05-12 17:48:21 · The Hacker News Echo RSS

3. RubyGems Pauses Signups After Hundreds of Malicious Packages Expose Software Supply Chain Vulnerability

RubyGems, the primary package manager for the Ruby programming language, has temporarily suspended new account registrations following the upload of hundreds of malicious packages in what security researchers are describing as a coordinated supply chain attack. The platform confirmed the disruption on its official chan...