Topic

Supply Chain & Third Party

Attacks that arrive through vendors, software packages and the third-party platforms you trust.

40 articles in this topic

Supply Chain & Third Party

Mini Shai-Hulud: SAP npm Supply Chain Attack Steals Developer Credentials and CI/CD Secrets

Four official SAP npm packages were compromised with credential-stealing malware in the Mini Shai-Hulud campaign. Here's what Saudi financial CISOs must do to protect their SAP development pipelines.

20 May 2026 5 min
Breaches & Data Leaks

Coinbase Insider Bribery Breach: Why Saudi Financial CISOs Must Rethink Third-Party Personnel Risk

Bribed overseas contractors stole data from 70,000 Coinbase customers — a $400M lesson in why insider threat programs for third-party personnel are non-negotiable under SAMA CSCC and NCA ECC.

20 May 2026 5 min
Supply Chain & Third Party

Mini Shai-Hulud Worm: How One npm Install Compromised 160+ Packages and Stole CI/CD Secrets

A self-propagating worm dubbed Mini Shai-Hulud hijacked 160+ npm and PyPI packages — including TanStack and Mistral AI — turning every compromised developer into a new infection vector. Here's what your DevSecOps team needs to act on immediately.

19 May 2026 5 min
Ransomware

Everest Ransomware Hits Two US Banks via Third-Party Vendor: A Wake-Up Call for Saudi Financial Sector Supply Chain Security

Everest ransomware breached two US banks through a single shared vendor, exposing 250K customer records. Here's what Saudi financial institutions must learn about third-party risk under SAMA CSCC.

16 May 2026 5 min
Ransomware

Nitrogen Ransomware Hits Foxconn: Supply Chain Lessons for Saudi Financial Institutions

Nitrogen ransomware breached Foxconn, exfiltrating 8TB of confidential data from Apple, Google, and Intel projects. Here's what Saudi financial institutions must learn about supply chain risk under SAMA CSCC.

16 May 2026 5 min
Software Engineering

Mini Shai-Hulud Supply Chain Worm Hits TanStack and Breaches OpenAI Through Trusted CI/CD Pipelines

A self-spreading worm hijacked TanStack's legitimate GitHub Actions pipeline, published malicious packages indistinguishable from real ones, and breached OpenAI — exposing fatal gaps in software supply chain security.

16 May 2026 5 min
Supply Chain & Third Party

Mini Shai-Hulud Worm Hits TanStack and 170+ Packages: The Largest npm Supply Chain Attack of 2026

TeamPCP weaponized GitHub Actions OIDC tokens to publish 401 malicious package versions across TanStack, Mistral AI, and UiPath — stealing credentials from cloud providers, crypto wallets, and CI systems. Here's what happened and how to respond.

13 May 2026 5 min
Software Engineering

RubyGems Shuts Down Signups After BufferZoneCorp Supply Chain Attack Hits CI/CD Pipelines

RubyGems suspended new registrations after hundreds of malicious sleeper packages drained AWS keys, SSH credentials, and GitHub tokens from CI/CD pipelines — a wake-up call for every organization running open-source dependencies.

13 May 2026 5 min
Software Engineering

Checkmarx Jenkins Plugin Backdoored by TeamPCP: CI/CD Supply Chain Under Siege

A rogue version of the Checkmarx Jenkins AST plugin was uploaded to the Jenkins Marketplace, turning trusted security tooling into an infostealer. Here's what happened and why SAMA-regulated institutions must audit their pipelines immediately.

12 May 2026 5 min
Supply Chain & Third Party

TanStack NPM Supply Chain Attack CVE-2026-45321: Trusted Packages Weaponized to Steal Developer Secrets

A self-spreading worm hijacked TanStack's trusted CI/CD pipeline, publishing 84 malicious npm packages that exfiltrated GitHub tokens, SSH keys, and cloud credentials. CVSS 9.6 — here's what SAMA-regulated institutions need to check immediately.

12 May 2026 5 min
Breaches & Data Leaks

Trellix Source Code Breach: Why Your Security Vendor Could Be Your Biggest Risk

Trellix's source code repository was breached by RansomHouse. For SAMA-regulated banks running Trellix products, this supply chain risk event demands immediate third-party incident response.

11 May 2026 6 min
Breaches & Data Leaks

Canvas LMS Mega-Breach: Lessons in Third-Party SaaS Risk for Saudi Institutions

ShinyHunters compromised Instructure's Canvas LMS, exposing data from 8,800+ institutions and 275 million users — the largest educational breach in history. Here's what Saudi organizations must learn about third-party SaaS risk.

11 May 2026 6 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality