25 Sep, 2026

BigCommerce alerts merchants of data breach linked to Ribon apps

Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. The cloud-based Software-as-a-Service (SaaS) ecommerce platform confirmed the credential compromise on September 17 and immediately removed the apps to protect its customers. UK-based online spirits vendor Master […]

3 mins read

Brevo supply-chain attack injected ClickFix scripts on customer sites

Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. The customer relationship management and digital marketing company says the attackers used the API key to create a malicious Cloudflare Worker that modified content at […]

4 mins read

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account. Developer Janis Elsts says an unauthorized party accessed the adminmenueditor.com website on Monday and uploaded version 2.35 as an […]

3 mins read

Coder’s registry infrastructure compromised to push malicious modules

Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. The Coder platform enables organizations to provide developers with secure, self-hosted cloud development environments for building and deploying software, including AI applications. The project is used by prominent private and government organizations, including Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW, […]

2 mins read

Hackers push malicious Virtualizor update in BGP hijacking attack

Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. Virtualizor is a legacy web control panel from Softaculous that hosting providers use to create, sell, and manage virtual private servers (VPS). An urgent notice from the vendor warns that […]

2 mins read

Australia arrests alleged TeamPCP hackers behind supply-chain attacks

Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching developer supply chain attacks. TeamPCP is a hacking group known for widespread supply-chain attacks over the past year that targeted open-source software and developer platforms to steal credentials, authentication secrets, and […]

2 mins read

Hackers poison arrayref Rust crate to push infostealer malware

Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers’ systems during compilation. Within a 23-minute window, the attacker also poisoned two other crates, append-only-vec and internment, in the same supply-chain attack. The arrayref crate is a popular Rust library with more than 53 million downloads […]

3 mins read

BdThemes plugins supply-chain hack creates rogue WordPress admins

A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators’ browsers to create rogue admin accounts. Starting Saturday, the affected BdThemes products were no longer available for download after the WordPress Plugins team closed all of them pending a full […]

3 mins read

Massive ChainDrop npm supply-chain attack infects hundreds of packages

Self-propagating malware named ‘ChainDrop’ has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. Infected packages include very popular ones such as Keyv and Cacheable, flat-cache and file-entry-cache, all caching utilities from the same maintainer.  The supply-chain attack started after the threat actor compromised the GitHub account of Keyv’s maintainer, and […]

4 mins read

Online ad firm Adform’s script compromised to steal cryptocurrency

Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors’ clipboards with ones controlled by an attacker. Adform is one of Europe’s largest adtech firms, providing a full-stack platform that includes Demand-Side Platform (DSP), Supply-Side Platform (SSP), ad servers, and management […]

3 mins read