Cybersecurity News
Filters
Filtered by tag: supply chain attack × Clear
North Korean Hackers Tied to Rust Supply Chain Attack
North Korean hackers have been linked to a supply chain attack targeting the Rust programming ecosystem. Researchers identified malicious backdoors embedded in compromised Rust packages, connecting the campaign to previously documented North Korean threat actors. The attack follows a pattern of supply chain intrusions attributed to the group, raising fresh concerns about open-source package repository security.
Faulty towers: Quest hotel chain discloses third-party customer data breach
Matched: Australia
Australian hotel apartment chain Quest has disclosed a data breach affecting customer information, including names, email addresses, and dates of birth. The breach originated from a third-party supplier rather than Quest's own systems. Affected customers have been notified and warned to remain vigilant against potential phishing attempts and scams that may exploit the compromised data.
Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center has disclosed a data breach affecting customer information, stemming from a cyberattack on logistics partner CEVA Logistics. As a result, some orders have been cancelled or delayed. The incident is part of a broader supply chain attack targeting CEVA Logistics, with Pokémon Center among several companies affected. Customers are advised to monitor their accounts for suspicious activity.
Malicious Solidity Pro VS Code Extension Steals Crypto Wallets, API Keys and SSH Keys via Telegram
Matched: cryptocurrency
A malicious VS Code extension called Solidity Pro has been discovered stealing cryptocurrency wallet data, API keys, and SSH keys from developers. Disguised as a legitimate Solidity development tool with polished documentation, the extension exfiltrates stolen data via Telegram. The attack highlights how convincing branding and familiar tooling can lower developers' guard against supply chain threats.
Hackers Turned a Trusted Advertising Platform Into a Crypto-Stealer Delivery Network
Matched: cryptocurrency
Adform, an ad tech firm serving ~14,000 businesses, suffered a supply chain attack where hackers hijacked a widely used JavaScript file within its infrastructure to distribute cryptocurrency-stealing malware. Researcher Kevin Beaumont uncovered the breach, which exploited the platform's trusted ad-serving network to reach victims. Adform holds nearly 30% of the demand-side platform market, amplifying the attack's potential reach.
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Matched: cryptocurrency
Attackers modified a JavaScript file from ad tech firm Adform to silently replace cryptocurrency wallet addresses in users' browsers. The malicious script, active on July 27, 2026, targeted Bitcoin and other crypto addresses copied by visitors to affected sites. Adform detected and removed the code the same day, notified clients, and reported the incident to authorities. Users who transacted on July 27 should verify their wallet addresses.
