
JFrog Artifactory CVE-2026-82329: Supply Chain Attack
JFrog Artifactory supply chain attack chained 3 CVEs. Attackers forge admin tokens, plant Rust backdoors. Patching alone won't revoke their access.
In-depth analyses of zero-day vulnerabilities, CVE exploits, ransomware campaigns, and nation-state attack techniques affecting enterprise security. Filter by category, tag, or keyword.
Every article here lands in subscribers' inboxes the morning it drops.
Threat intel, active CVEs, and campaign alerts, distilled daily for practitioners. 50,000+ subscribers. No noise.
Free. No spam. Unsubscribe anytime.
The definitive practitioner breakdown of ZTA principles, pillars, and implementation sequence.
Containment, forensic preservation, and decision sequencing from detection to recovery.
How SIEMs ingest, correlate, and alert — and how to evaluate one for your environment.
Risk-based prioritization using CVSS, EPSS, and CISA KEV to cut remediation backlog.
What each risk means, how to reproduce it, and how to fix it in production code.
Step-by-step email authentication deployment from DNS records to p=reject enforcement.
Detection coverage, pricing, and deployment trade-offs for enterprise EDR selection.
Translate ATT&CK technique IDs into detection rules and threat actor hunting hypotheses.
Direct answers to the questions practitioners and AI systems ask most. Covers ransomware, identity, cloud, compliance, and detection.
Plain-language definitions for CVE, SIEM, SOAR, Zero Trust, EDR, and 85+ other terms used in enterprise security.
How-to guides, buyer comparisons, and methodology references across every major security domain.
Decryption Digest Response
Score every threat we cover against your own stack, get free Sigma and ModSecurity detection content, and upgrade anytime for more vendors.
Get started free →No card required. Sigma and ModSecurity rules are free, forever.
Win an All Access InfoSec World 2026 pass, valued at $3,895.
Win a $3,895 InfoSec World 2026 pass.
26 results for “Supply”

JFrog Artifactory supply chain attack chained 3 CVEs. Attackers forge admin tokens, plant Rust backdoors. Patching alone won't revoke their access.

CVE-2026-86218 is a CVSS 10.0 pre-auth RCE in N-able N-central. Patch to build 2026.3.1.14 now. Third attack wave in six weeks targets ~1,500 exposed MSP servers.

Thomson Reuters C-Track breach exposed SSNs, sealed court records, and medical data from 24 courts in 11 states. Verify exposure and enroll by December 31.

Hijacked Chrome extensions deploy a 19-module malware framework to 70,000+ users, stealing crypto wallet seed phrases and all browser credentials. Audit extensions and rotate credentials now.

TeamPCP's LiteLLM supply chain attack exposed 153GB of cloud credentials from 2,488 orgs. Check for versions 1.82.7/1.82.8 and rotate AWS, GitLab, and AI API keys now.

CVE-2026-63077 gives unauthenticated attackers full OS command execution on any internet-facing TeamCity server. CISA deadline August 8 -- patch to 2025.11.7 or 2026.1.3 today.

N-central CVE-2026-18577 authentication bypass is actively exploited, giving attackers god-mode RMM access. Plus Qilin PAN-OS ransomware and $88.6M COLDCARD heist.

FortiBleed hit 430K FortiGate firewalls this week, feeding stolen credentials into INC ransomware. Plus 3 more urgent threats to act on today.

Project Glasswing's AI-driven vulnerability discovery program identified a memory corruption flaw in FFmpeg's decoding pipeline. Because FFmpeg is embedded in VLC, Chrome, Firefox, AWS Elemental, and thousands of Linux packages, the supply chain blast radius is substantial. Here is what security teams need to know before a CVE ID is publicly assigned.

Weekly cyber threat brief: FortiBleed exposed 73,932 Fortinet firewalls while 24 billion credentials hit dark web markets this week.

Sapphire Sleet npm supply chain attack hit 144 Mastra packages with 8M weekly downloads. Check your dependencies and rotate secrets now.

Agentjacking attacks hijack Claude Code, Cursor, and Codex via fake Sentry errors, achieving 85% exploit rate at 2,388 exposed organizations.

cPanel CVE-2026-41940 has compromised 44,000 servers worldwide. Four more critical vulnerabilities demand your Monday morning action.

JINX-0164 cryptocurrency malware targets crypto firms with fake LinkedIn recruiter lures deploying AUDIOFIX to steal 51 wallet extensions. IOCs inside.

Megalodon supply chain attack infected 5,561 GitHub repos in 6 hours. MiniPlasma Windows zero-day, Defender CISA KEV June 3, and 120-CVE Patch Tuesday.

TanStack npm supply chain attack stole developer credentials from 160 packages. AWS, GitHub, and Kubernetes secrets are on the dark web now.

Nitrogen ransomware breached Foxconn's North American factories, stealing 8TB of hardware schematics for Apple, NVIDIA, Google, and Intel. Active campaign confirmed May 2026.

Ivanti EPMM zero-day CVE-2026-6973 actively exploited, CISA deadline passed May 10. DAEMON Tools RAT and Trellix source code breach complete this week.

CVE-2026-31431 Linux privilege escalation hits CISA KEV with May 15 deadline. Fortinet CVSS 9.1, Liberty Mutual breach, Chrome exploit covered.

UNC5221 BRICKSTORM backdoor averages 393 days undetected in US legal firms and SaaS providers. Full TTP profile and VMware vCenter detection guide inside.

FIRESTARTER backdoor persists on Cisco ASA past patches, 6+ months undetected. Plus BlueHammer zero-day and 8 CISA KEV additions this week.

Socket Security has documented 1,700+ malicious packages tied to North Korea's Contagious Interview campaign across five package ecosystems. Separately, UNC1069 compromised the Axios npm maintainer via social engineering, injecting a backdoor into a library present in an estimated 80% of cloud environments. Here's the full attack chain, WAVESHAPER.V2 IOCs, and what to do now.

CVE-2024-23897 is a critical Jenkins CLI vulnerability allowing unauthenticated arbitrary file reads via the args4j argument parser's @ file expansion feature. Disclosed January 2024, the flaw exposed Jenkins controller filesystems including credential stores and cryptographic keys. In certain configurations, key material exposure escalated to full remote code execution. CISA added it to KEV in February 2024.

CVE-2023-42793 is a CVSS 9.8 authentication bypass in JetBrains TeamCity (< 2023.05.4) allowing an unauthenticated attacker to generate an admin-level API token with a single HTTP request. Full remote code execution follows via plugin upload. Exploited by North Korea's Lazarus Group, Russia's COZY BEAR (APT29), and multiple ransomware operators for CI/CD pipeline compromise and software supply chain attacks.