Researchers have identified security vulnerabilities in Amazon Bedrock, LangSmith, and SGLang that could enable data exfiltration, account takeover, and remote code execution in AI environments.
A compromised npm publish token was used to release Cline CLI version 2.3.0, triggering unauthorized installation of OpenClaw on developer systems during an eight hour supply chain attack window.
Cybersecurity researchers uncover the first known malicious Microsoft Outlook add in used to steal more than 4,000 Microsoft credentials through an abandoned domain takeover supply chain attack.
Cybersecurity researchers uncover a supply chain attack where compromised dYdX npm and PyPI packages distributed wallet-stealing malware and remote access trojans, exposing developers and crypto users to major risks.
A misconfiguration in AWS CodeBuild allowed potential takeover of GitHub repositories including aws-sdk-js-v3, exposing cloud environments to supply chain risks. AWS has since remediated the issue.
Trust Wallet reveals Shai-Hulud supply chain attack compromised Chrome extension, stealing $8.5 million in crypto assets from 2,520 wallets. Users urged to update to version 2.69.