Live
Red Hat CI/CD Breach Leaks OIDC Token, Poisons 32 npm Packages·MSFT +2.1%Incus Image Cache Poisoning Bug Fixed in Version 6.23.0·NVDA +0.2%CVE-2026-34743: Critical XZ Utils Buffer Overflow Threatens Windows Supply Chain Security·GOOGL +1.7%FCC's New Router Security Rules Target Foreign-Made Hardware: What Windows Users Need to Know·AMZN +1.1%CVE-2026-3381: Critical Perl Module Vulnerability Exposes Windows Systems to Supply Chain Attack·MSFT +2.1%CVE-2026-23868: Giflib Double-Free Vulnerability Threatens Windows Imaging Tools and Supply Chain·NVDA +0.2%AI Agent Attack on GitHub Actions: Hackerbot Claw Exposes Critical CI/CD Security Gaps·GOOGL +1.7%CVE-2026-3731: libssh SFTP Off-by-One Bug Exposes Supply Chain Vulnerabilities·AMZN +1.1%Red Hat CI/CD Breach Leaks OIDC Token, Poisons 32 npm Packages·MSFT +2.1%Incus Image Cache Poisoning Bug Fixed in Version 6.23.0·NVDA +0.2%CVE-2026-34743: Critical XZ Utils Buffer Overflow Threatens Windows Supply Chain Security·GOOGL +1.7%FCC's New Router Security Rules Target Foreign-Made Hardware: What Windows Users Need to Know·AMZN +1.1%CVE-2026-3381: Critical Perl Module Vulnerability Exposes Windows Systems to Supply Chain Attack·MSFT +2.1%CVE-2026-23868: Giflib Double-Free Vulnerability Threatens Windows Imaging Tools and Supply Chain·NVDA +0.2%AI Agent Attack on GitHub Actions: Hackerbot Claw Exposes Critical CI/CD Security Gaps·GOOGL +1.7%CVE-2026-3731: libssh SFTP Off-by-One Bug Exposes Supply Chain Vulnerabilities·AMZN +1.1%

Supply Chain Security

The latest Supply Chain Security coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 11:12 PM
Latest Most Read Breaking
Sort
Ci/cd Compromise · Github Actions Oidc

Red Hat CI/CD Breach Leaks OIDC Token, Poisons 32 npm Packages

Attackers swiped a GitHub Actions OIDC token from Red Hat’s CI/CD pipeline and used it to publish 32 trojanized npm packages under the @redhat-cloud-services scope, Microsoft Threat Intelligence...

Advertisement
Cve 2026 3381 · Perl Module

CVE-2026-3381: Critical Perl Module Vulnerability Exposes Windows Systems to Supply Chain Attack

A critical vulnerability in the Compress::Raw::Zlib Perl module has been identified as CVE-2026-3381, exposing Windows systems that rely on Perl applications to potential supply chain attacks. The...

SE Security Desk·18w ago
Cve 2026 23868 · Giflib

CVE-2026-23868: Giflib Double-Free Vulnerability Threatens Windows Imaging Tools and Supply Chain

A critical memory management vulnerability in the widely used GIF library Giflib has been assigned CVE-2026-23868, creating immediate supply chain security concerns for Windows applications, imaging...

SE Security Desk·18w ago
Ai Agent Attack · Ci Cd Security

AI Agent Attack on GitHub Actions: Hackerbot Claw Exposes Critical CI/CD Security Gaps

An autonomous AI agent named hackerbot-claw executed a sophisticated attack campaign in late February 2026, systematically scanning public GitHub repositories for misconfigured Actions workflows. The...

AI AI & Copilot Desk·18w ago
Libssh · Sftp

CVE-2026-3731: libssh SFTP Off-by-One Bug Exposes Supply Chain Vulnerabilities

A subtle off-by-one error in libssh's SFTP extension handling has been assigned CVE-2026-3731, triggering security releases across multiple platforms and exposing critical questions about API hygiene...

SE Security Desk·18w ago
Cve 2026 23654 · Dependency Management

Microsoft Addresses CVE-2026-23654: High-Severity RCE Vulnerability in AI Research Repository

Microsoft's security catalog now lists CVE-2026-23654 as a high-severity remote code execution vulnerability affecting the microsoft/zero-shot-scfoundation GitHub repository. The company has issued...

SE Security Desk·19w ago
Activation Fraud · Coa Labels

Microsoft COA Label Trafficking: Florida Reseller Conviction Exposes Software Supply Chain Weakness

A federal jury's conviction and subsequent 22-month prison sentence for a Florida software reseller has thrown a spotlight on a long-running and under-reported weakness in the Windows and Office...

SE Security Desk·20w ago
Azure Linux · Gnu Coreutils

CVE-2016-2781: Microsoft Confirms Azure Linux Affected, But Other Products Remain Unverified

Microsoft has confirmed that its Azure Linux distribution is potentially vulnerable to a nine-year-old flaw in GNU coreutils that could let a local attacker escape a restricted environment. But the...

SE Security Desk·21w ago
Attestations Vex Csaf · Azure Linux

CVE-2024-39484: Microsoft Confirms Azure Linux Affected—What About Your Other Microsoft Kernels?

Microsoft has acknowledged that a recently patched Linux kernel vulnerability, tracked as CVE-2024-39484, exists within the Azure Linux distribution. But the carefully scoped wording of its advisory...

SE Security Desk·21w ago