Search

Tag: #supply-chain-attack33 results

Vercel Breach via EOL AI Tool

Vercel Breach via EOL AI Tool

Vercel disclosed unauthorized access to its systems, potentially leaking some users' environment variables. The attack originated from a third-party AI tool used by an employee that had reached end-of-support. It began with a Google Workspace account hijacking.

ITmedia AI+ (日本)MediaApr 21#data-breach#supply-chain-attack#devsecops
March CI/CD Supply Chain Attacks Lessons

March CI/CD Supply Chain Attacks Lessons

In March 2026, TeamPCP compromised Trivy, Checkmarx KICS, LiteLLM, and axios via CI/CD pipelines, injecting credential-stealing malware. Attacks exploited GitHub Actions and package publishes, exfiltrating secrets from pipelines. GitLab outlines how centralized policies can detect and block such threats.

Page 2 of 4