Tuesday 22 September 2026 05:35:11 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItaliano

#Supply Chain


A Package That Looked Clean Until It Ran

Published: 22 September 2026 02:04Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A malicious npm package called indexed-btree illustrates a sharper supply-chain trick: hiding bad behavior in normal runtime code, beyond the reach of install-script checks.

The Package That Waited Until You Ran It

Published: 21 September 2026 16:20Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A counterfeit npm dependency shows how a supply-chain lure can slip past install-time defenses and still wake up inside a live application.

Victim Listing, Real Exposure: Why a Single Ransomware Claim Can Shake a Supply Chain

Published: 21 September 2026 16:14Category: Ransomware & ExtortionGeo: North America / USAAuthor: LOGICFALCON

Metaencryptor has publicly named Flex Ltd., but the allegation is not proof of breach - it is a reminder that manufacturing and logistics firms can face outsized risk even before any technical details are confirmed.

Stolen Code, Bigger Questions: What CrowdSec’s Disclosure Reveals About Trust in the Build Chain

Published: 21 September 2026 14:29Category: Breaches & Data LeaksGeo: Europe / FranceAuthor: BYTEHERMIT

A source-code theft can be more than an IP loss when the same release machinery that protects software may also become the attack surface.

When a Package Looks Clean and Still Turns Risky at Runtime

Published: 21 September 2026 14:19Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A lookalike npm package named indexed-btree is described as hiding malicious behavior in ordinary JavaScript code, a pattern that can slip past install-time checks and surface only when the package is actually used.

Video Calls Become a Trust Trap for Rust Maintainers

Published: 21 September 2026 14:05Category: Cyber Warfare & Nation-State OperationsAuthor: AGONY

Rust team members and popular crate owners were approached through video calls, a reminder that supply-chain risk often begins with identity, not code.

The Quiet Risk Behind Critical Infrastructure Is Not Always a Hack

Published: 21 September 2026 12:09Category: Cyber Intelligence & Threat TrendsGeo: North America / USAAuthor: GHOSTCOMPLY

Idaho National Laboratory’s TOPGEAR effort points to a harder security problem: mapping influence, ownership, and dependency before they become operational weaknesses.

Inside the Vendor Squeeze: Why a Small IT Provider Became a Bigger Target

Published: 21 September 2026 10:34Category: Cyber Warfare & Nation-State OperationsGeo: Asia / IndiaAuthor: AGONY

A SentinelOne disclosure links Jade Sleet to an India-based IT services provider and two macOS backdoors, showing how developer-facing environments can matter far beyond one workstation.

The Hidden Risk in Enterprise AI Is Not the Model - It Is the Control Boundary

Published: 21 September 2026 10:21Category: AI Security & Agentic SystemsAuthor: INTEGRITYFOX

When companies choose between cloud AI and internally installed models, the real security question is who owns the data, identities, logs, and risk.

A Factory Wind-Down Can Become a Resilience Test

Published: 21 September 2026 06:01Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

Sherline’s announced manufacturing wind-down after 52 years is a reminder that the end of production can create long-tail operational risk, even when no cyber incident is involved.

npm’s Quietest Payloads Are Getting Harder to Spot

Published: 20 September 2026 18:09Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A malicious package in the npm ecosystem highlights a simple but stubborn truth: blocking install scripts does not stop code that waits until normal runtime to execute.

The Pin That Wasn't: How a Trusted AI Plugin Can Turn into a Silent Rewrite

Published: 18 September 2026 16:42Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

Plugin4Shell spotlights a brittle trust boundary in AI coding agents: if the final checkout is not verified, a reviewed plugin can still be replaced after approval.

When the Registry Becomes the Gatekeeper, Security Stops Being Optional

Published: 18 September 2026 12:28Category: Technology, Innovation & Digital InfrastructureAuthor: SECPULSE

A 2026 roundup of container registry security tools points to a deeper shift: image scanning is moving from a visibility feature to a release decision, and that changes how teams should think about trust in the software supply chain.

PhantomRaven Turns npm Installs Into a Secret-Hunting Trap

Published: 18 September 2026 12:12Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A JavaScript stealer moving through the npm ecosystem shows how package trust, install-time code, and AI-shaped tradecraft can collide inside ordinary developer workflows.

When AI Assistants Start Trusting the Wrong Plugin

Published: 18 September 2026 12:09Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A reported flaw in a plugin pipeline puts a hard spotlight on how coding agents handle extension provenance, update logic, and the boundary between convenience and code execution.

One Stolen Key, One Edge Worker, and 100,000 Websites in the Blast Radius

Published: 18 September 2026 12:03Category: CybercrimeGeo: Europe / FranceAuthor: VULNCRUSADER

A reported credential abuse case shows how a single compromised API key can turn trusted edge infrastructure into a large-scale script injection path.

When a Trusted Widget Turns Hostile: The Hidden Risk Behind Brevo’s Browser Path

Published: 18 September 2026 10:37Category: Cloud, SaaS & Identity SecurityGeo: Europe / FranceAuthor: SHADOWFIREWALL

A reported JavaScript injection against Brevo-linked delivery paths shows how a single embedded script can become a high-trust attack surface for every site that loads it.

When an AI Agent Gets a Publish Button, Security Stops Being Optional

Published: 17 September 2026 18:14Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

RubyGems and Hugging Face are being used as cautionary precedents for a larger problem: agentic AI is only as safe as the permissions, secrets, and approval gates wrapped around it.

Ransomware Is Finding a Pressure Point in Manufacturing

Published: 17 September 2026 16:30Category: Ransomware & ExtortionAuthor: LOGICFALCON

A reported 40 percent jump in early 2026 points to a simple criminal calculation: when production slows, extortion leverage grows.

Why a Defense Robotics Firm’s CMMC Milestone Matters More Than It Looks

Published: 17 September 2026 12:28Category: Privacy, Regulation & ComplianceGeo: North America / USAAuthor: SAFEHEXER

A self-assessment is not a certification victory, but in the defense supply chain it can still signal how seriously a supplier is preparing for CUI-heavy contracts and tightening cyber rules.