Topic
Supply Chain
8 reports tagged Supply Chain, spanning vulnerability, campaign, threat actor and malware coverage.
Articles tagged Supply Chain
-
VulnerabilityJFrog Artifactory Path Traversal (CVE-2026-66384)
CVE-2026-66384 is a CVSS 5.3 path traversal in JFrog Artifactory affecting the Docker cache, confirmed exploited per CISA KEV.
-
VulnerabilityJFrog Artifactory Authentication Bypass (CVE-2026-82329)
CVE-2026-82329 is a CVSS 9.8 authentication flaw letting an unauthenticated attacker gain JFrog Artifactory admin rights. Added to CISA KEV Sept. 2, 2026.
-
VulnerabilityJFrog Artifactory Self-Hosted Authentication Bypass (CVE-2026-42018)
CVE-2026-42018 can leak an internal anonymous-user token to unauthenticated callers in JFrog Artifactory even when anonymous access is disabled. Added to CISA KEV Sept. 11, 2026.
-
VulnerabilityJFrog Artifactory Self-Hosted Privilege Escalation (CVE-2026-42016)
CVE-2026-42016 lets attackers escalate privileges in JFrog Artifactory via a token-scope validation gap. CISA added it to KEV Sept. 11, 2026; Wiz reports in-the-wild exploitation.
-
CampaignSolarWinds Compromise
Sophisticated supply-chain cyber operation conducted by APT29, discovered mid-December 2020, that injected malicious code into the SolarWinds Orion software build process and was formally attributed to Russia's SVR in April 2021.
-
Threat ActorOilRig
Suspected Iranian threat group, per MITRE ATT&CK, targeting Middle Eastern and international victims since at least 2014 via supply-chain trust relationships.
-
MalwareMini Shai-Hulud
Self-replicating supply-chain worm and credential stealer, per MITRE ATT&CK, derived from Shai-Hulud and used by TeamPCP to target CI/CD workflows since at least 2026 via stolen npm and GitHub OIDC tokens.
-
Vulnerabilitybrowserslist Prototype Pollution (CVE-2026-73088)
CVE-2026-73088 lets an untrusted browserslist-stats.json file crash or pollute the prototype of any Node.js process calling Browserslist, fixed in 4.28.7.