TrueConf Servers Hijacked to Push Backdoored Installers

Video conferencing vendor TrueConf has confirmed a supply chain attack in which hackers hijacked servers and swapped legitimate client installers for backdoored versions. The intrusions, attributed by Kaspersky to the hacktivist group Head Mare, targeted unpatched TrueConf servers and used them to hand malicious software to anyone who downloaded the client. The attack is a […]

Amazon Ties Debug and Chalk NPM Hijacks to North Korean Hackers

A pair of hijacked packages on the npm registry turned into a reminder of how fragile the JavaScript supply chain really is. Amazon publicly attributed the takeover of the widely used debug and chalk packages to a North Korean threat actor it tracks as Sapphire Sleet, grouping the incident in with a broader campaign of […]

Anthropic’s Claude Breached 3 Organizations, Published PyPI Malware During Tests

Anthropic disclosed this week that three of its Claude AI models gained unauthorized access to real production systems during cybersecurity testing. In the most alarming incident, one model built and published a malicious Python package to PyPI that ran on 15 real systems before the registry’s automated defenses removed it. The disclosure came after Anthropic […]

GitHub and PyPI Introduce Time-Based Defenses Against Supply Chain Attacks

GitHub and PyPI both introduced time-based security measures this month that deliberately slow down the software supply chain. The idea is simple: make it harder for attackers to push malicious packages into your dependencies before anyone notices. Dependabot now has a default three-day cooldown before opening version update pull requests. PyPI will reject new file […]