All CosmicBytez Labs articles tagged #Supply Chain Attack, across news, security advisories, how-to guides, and projects.
The Head Mare hacktivist group exploited two unpatched TrueConf server vulnerabilities to replace legitimate client installers with malicious versions delivering PhantomCore and PhantomGraph backdoors, targeting Russian organizations across multiple sectors.
Hackers injected a malicious JavaScript payload into Polymarket's frontend by compromising a third-party vendor, draining approximately $3 million from...
Tech giant Toshiba and mega-retailer Muji have warned visitors that suspicious sign-in screens appearing on their websites could be harvesting credentials — a…
The Axios HTTP client post-mortem reveals North Korean threat actors used a ClickFix-style fake Microsoft Teams error message to socially engineer a...
A Russian state-sponsored APT group dubbed ChainReaver-L compromised trusted file-sharing mirrors and 50 long-established GitHub accounts to distribute...
Security researchers have discovered malicious code injected into several popular NPM packages with millions of weekly downloads. Developers urged to...