d4 · decrypted · topic

Supply chain

Compromised packages, vendor breaches and trust in what you install. 6 posts so far.

The npm maintainer account North Korea phished, and the four packages it unlocked Amazon has linked four npm supply chain compromises, including debug, chalk and axios, to a North Korea-linked group that phished a single trusted maintainer. Plus: an actively exploited hardcoded credential in Cisco's firewall manager, ShinyHunters' extortion claim against EY, and new NCSC guidance on surviving a disruptive cyber-attack. The SD-WAN orchestrator that needed no login, and the one before it Arista's VeloCloud SD-WAN orchestrator carried a maximum-severity command injection bug that needed no credentials to reach, the second such flaw in a network orchestration console in a fortnight. Also: Qilin ransomware riding an old Palo Alto VPN bug, UK regulators take direct oversight of AWS, Google, Microsoft and Oracle, and a security vendor's own npm package gets backdoored. A capacity limit in Frankfurt, and the National Lottery it took offline A single capacity limit in one AWS availability zone in Frankfurt took the UK National Lottery, Hugging Face and university coursework platforms offline for three and a half hours, without a single attacker involved. Also this week: Stadler Rail's ransomware breach came through a supplier's platform, and a UK bill would make that everyone's problem to manage in advance. Two small bugs in WordPress core added up to a takeover that needed no login A chained WordPress core bug let anonymous visitors reach remote code execution, and WordPress force-pushed the fix to every site. Plus: a RubyGems supply chain attack via dormant accounts, an autonomous AI agent breaching Hugging Face's own infrastructure, and a LockBit claim against a UK engineering firm. A trusted GitHub workflow, and the three million downloads it poisoned A GitHub Actions misconfiguration let an attacker backdoor npm packages downloaded three million times a week, no zero-day required. Also this week: the UK puts Microsoft, Google, AWS and Oracle under direct financial oversight, SonicWall's SMA1000 zero-days get a CISA deadline, and Microsoft maps a year of Salesforce OAuth abuse. The ShareFile shutdown, and the bypass that made it necessary Progress told ShareFile customers to physically power down servers after a 'credible' threat, months after a public authentication-bypass and RCE chain went unpatched. Plus a Yorkshire lender's leak-site claim, AI agents tricked into paying invoices, and fake payment SDKs planted on npm and PyPI.