Bitwarden NPM Package Hit in Supply Chain Attack
Bitwarden NPM package compromised in a supply chain attack attributed to TeamPCP. Malicious code was injected into dependencies, posing risks to any developers who installed it.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
Bitwarden NPM package compromised in a supply chain attack attributed to TeamPCP. Malicious code was injected into dependencies, posing risks to any developers who installed it.
Tropic Trooper exploits home routers as backdoors targeting Japanese organizations. Their weak security and network position enable infiltration and lateral movement into higher-value targets.
Chinese state-sponsored hackers are industrializing botnets for cost-effective, deniable attacks. Reusing compromised devices instead of custom malware provides scalability and complicates attribution.
Critical file upload vulnerability in Breeze Cache plugin (100k+ installations) allows unauthenticated attackers to upload and execute arbitrary files (CVSS 9.8). Active exploitation confirmed with webshells deployed to thousands of WordPress sites.
Yadea T5 e-bikes have a critical wireless flaw (CVE-2025-70994) allowing attackers to unlock bikes using signal forgery attacks with standard radio tools. A firmware update is needed to fix the weak authentication in the wireless locking system.
FIRESTARTER backdoor discovered on Cisco firewalls persists even after patches. APT actors use it to maintain access despite CVE fixes, requiring forensic investigation beyond standard patching.
Xiongmai XM530 IP cameras have a critical flaw (CVE-2025-65856, CVSS 9.8) allowing unauthenticated remote access to video feeds and device configuration through exposed ONVIF protocol endpoints. Attackers can exploit this to surveil sensitive facilities without credentials, turning security devices
GNSS receiver flaw (CVE-2026-3893) allows remote takeover of power grids and critical infrastructure without authentication. Patch available but undeployed; poses immediate cascading failure risk.
Rituals Cosmetics disclosed a data breach exposing customer names, addresses, and personal details from its loyalty program. The company has not revealed the number of affected customers or the complete scope of the breach.
Attackers have shifted from exploiting technical vulnerabilities to weaponizing trusted relationships. By compromising vendor accounts and infiltrating normal workflows, they bypass security defenses designed for external threats, turning institutional trust into the primary attack surface.
Rilian raised $17.5M for its AI-native security orchestration platform, funding expansion and talent growth in the $2.5B+ SOAR market. The platform automates incident triage and response workflows, competing against established players with machine learning-driven capabilities.
Trigona ransomware deployed a custom data exfiltration tool, shifting toward rapid data theft and extortion. The move reduces attackers' network dwell time while maximizing ransom leverage.
Attackers compromised the Bitwarden CLI npm package with malware that stole credentials and API keys from developers' environments before being removed. The incident exposes supply chain vulnerabilities in open-source ecosystems.
360 Digital Security Group claims AI discovered over 1,000 vulnerabilities including Tianfu Cup entries, but industry skepticism questions the validity and significance of such AI-driven security claims.
Cloudsmith raised $72 million in Series C funding to accelerate its software supply chain security platform as organizations prioritize DevSecOps. The investment reflects growing urgency following major supply chain attacks like SolarWinds and Log4Shell, which have made artifact security and depende
UNC6692 conducts targeted intrusions by impersonating IT helpdesk personnel on Microsoft Teams to deploy custom SNOW malware. The campaign exploits organizational trust in internal support channels, relying on social engineering rather than technical exploits.
Checkmarx's KICS tool was compromised across Docker and VSCode, with malicious variants harvesting API keys and credentials. The attack maintains legitimate functionality to evade detection.
Mandatory password resets may actually weaken security rather than strengthen it. Modern attackers use persistent access methods (phishing, malware) that bypass password changes, while forced resets drive users to create weaker passwords or reuse variants.
Cisco found a flaw in Anthropic's memory handling allowing attackers to inject malicious content. The vulnerability exploits unsafe parsing of persistent memory files in enterprise agent deployments.
A Chinese APT established C2 infrastructure across Outlook, Slack, Discord, and file.io to target Mongolia, leveraging trust in legitimate cloud services to evade detection.
A $290M DeFi hack and macOS Living-of-the-Land attacks expose recurring vulnerabilities mutating across systems. Defenders face simple exploits with difficult fixes and widening security gaps.
Bitwarden CLI v2026.4.0 was compromised with malicious code distributed via npm in a Checkmarx supply chain attack. This threatens developers relying on the tool for credential management and CI/CD integration.
Rituals' loyalty database was breached, exposing customer names, emails, addresses, and purchase history. The Dutch cosmetics company hasn't disclosed how many were affected but is offering credit monitoring.
Attackers are weaponizing electrical infrastructure by manipulating voltage to disrupt operations and damage hardware, bypassing firewalls. These attacks combine voltage surges and power instability with network infiltration for amplified impact.