Tuesday 28 July 2026 13:14:11 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#Supply chain


When a Build Workflow Turns Hostile: The AsyncAPI npm Incident

Published: 21 July 2026 10:15Category: Malware & BotnetsAuthor: IRONQUERY

A malicious release surfaced in a trusted package path, showing how compromised automation can turn software delivery into a malware channel.

Inside the AI Trapdoor: Malicious Skills, Fake Registries, and the New Malware Supply Chain

Published: 21 July 2026 10:11Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A reported campaign abused AI tool listings, GitHub-style trust cues, and MCP workflows to move SmartLoader first and StealC second, turning documentation into part of the attack path.

Stolen Hospital Customer Data Exposes the Quiet Weak Point in Healthcare Security

Published: 20 July 2026 18:33Category: Breaches & Data LeaksGeo: Europe / United KingdomAuthor: BYTEHERMIT

A breach at a hospital software vendor is a reminder that the most sensitive part of healthcare defense may sit outside the hospital walls.

The Monitor That Tried to Install Its Own Agenda

Published: 20 July 2026 14:38Category: Technology, Innovation & Digital InfrastructureGeo: Asia / South KoreaAuthor: SECPULSE

Testing of an LG UltraGear setup suggests a simple display connection can trigger a quiet Windows install, raising uncomfortable questions about peripheral software and user consent.

EY-Linked Breach Shows How One Vendor Portal Can Turn PII Into a Fraud Cache

Published: 20 July 2026 14:15Category: Breaches & Data LeaksGeo: Europe / United KingdomAuthor: BYTEHERMIT

A third-party management platform tied to Ernst & Young was used to steal names, addresses, Social Security numbers, and payment card data, underscoring the security cost of concentrating sensitive records in supplier systems.

When the IDE Becomes the Attack Surface: Why Agentic Security Is Rewriting Endpoint Defense

Published: 20 July 2026 12:26Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

The emerging push toward agentic endpoint security reflects a simple problem: in modern developer environments, trust is no longer confined to files and processes, and AI-aware controls are being asked to watch the runtime itself.

Ruby’s Quiet Trust Chain Becomes a Loud Risk

Published: 20 July 2026 08:14Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A malicious package cluster in the Ruby ecosystem shows how ordinary gem installs can become a staging point for payload delivery on developer machines.

Image Files as Bait: How Interview Lures Are Being Used to Slip Malware Past Developer Trust

Published: 20 July 2026 08:07Category: Malware & BotnetsGeo: Asia / North KoreaAuthor: NEXUSGUARDIAN

A resurfaced recruitment-themed campaign is using SVG files as a delivery container, while a separate Ruby ecosystem intrusion underlines how quickly software trust can be turned against developers.

Two Trust Boundaries, One Trap: Active Images and Package Registries Turned Against Developers

Published: 20 July 2026 08:03Category: Malware & BotnetsGeo: Asia / North KoreaAuthor: IRONQUERY

A malware campaign linked to SVG files and a separate RubyGems supply-chain incident show how developers can be targeted through the tools they use most.

Trusted Updates, Untrusted Payloads: ViPNet Becomes the Delivery Path

Published: 19 July 2026 18:05Category: Cyber Warfare & Nation-State OperationsGeo: Europe / RussiaAuthor: AGONY

A reported abuse of ViPNet's update mechanism shows how a normal maintenance channel can turn into a high-value target when trust is the thing under attack.

When the Help Desk Becomes the Heist Route: EY’s Tax Files and the Vendor Trust Problem

Published: 18 July 2026 10:13Category: Breaches & Data LeaksGeo: North America / USAAuthor: SECURERECLAIMER

A breach involving a vendor-managed IT support platform shows how sensitive client tax data can travel through a trust boundary that many organizations do not fully see.

Nichirei’s Cyberattack Exposes the Fragility Behind Cold-Chain Logistics

Published: 17 July 2026 14:11Category: Industrial Cybersecurity & Critical InfrastructureGeo: Asia / JapanAuthor: NETAEGIS

A confirmed cyberattack at Nichirei Corp. caused system failures and disrupted food and cold-chain logistics operations, underscoring how quickly digital disruption can ripple through temperature-sensitive supply networks.

Supplier Risk Gets Bankable as Security Teams Push Past Static Questionnaires

Risk Ledger’s $32 million Series B puts a spotlight on a growing idea in cyber defense: that supplier risk data works better when it is shared, updated, and tied to live dependency maps.

The Hidden Risk in Retail AI: When Forecasts Start Steering the Business

Published: 17 July 2026 12:18Category: Technology, Innovation & Digital InfrastructureAuthor: TRUSTBREAKER

Retail and logistics are moving from retrospective reporting to predictive decision support, but the real security story is the data pipeline behind the forecast.

When Trusted Admin Access Becomes the Attack Surface

Published: 17 July 2026 10:06Category: CybercrimeGeo: North America / USAAuthor: VULNCRUSADER

Managed service providers can turn one compromised management plane into a multi-customer security event, which is why cybercrime keeps circling the same trusted chokepoints.

Printer Supply Chains Are Not Just a Pricing Fight Anymore

Published: 17 July 2026 02:08Category: CybercrimeGeo: North America / USAAuthor: CIPHERWARDEN

A major rupee penalty over cartridges and PCs shows how reseller incentives, counterfeit risk, and product trust can become part of the security story.

Governments Are Rewiring Vulnerability Disclosure Before the Next Bug Goes Public

Published: 16 July 2026 17:22Category: Legal, Policy & Government CybersecurityGeo: North America / USAAuthor: ROOTBEACON

A new cross-border disclosure framework puts structure around how suppliers receive, triage, and fix security flaws, with coordination now treated as part of the job.

Victim Listing Alone Can Still Put Industrial Suppliers on Alert

Published: 16 July 2026 16:43Category: Ransomware & ExtortionGeo: Asia / JapanAuthor: LOGICFALCON

A ransomware-style victim claim tied to Dink Co Ltd remains unverified, but it is enough to sharpen concern around suppliers embedded in manufacturing chains.

Japan's Food Pipeline Took the Hit, Not Just the Trucks

Published: 16 July 2026 13:07Category: Industrial Cybersecurity & Critical InfrastructureGeo: Asia / JapanAuthor: NETAEGIS

A disruption at a temperature-controlled logistics operator shows how quickly a cyber incident can turn into missing ingredients, late deliveries, and a fragile supply chain under pressure.

When Supply Chains Start Thinking for Themselves

Published: 16 July 2026 12:57Category: Technology, Innovation & Digital InfrastructureAuthor: SECPULSE

Process Intelligence is moving from a niche analytics tool to a practical way to cut waste, shorten decisions, and expose where fragmented operations really slow down.