» Tag
supply-chain
19 postsUnisoc T606/T616 Backdoors Enable Zero-Click Root on Budget Androids
Chained BootROM, modem RCE, and backdoored OEM apps let attackers silently root Unisoc-based budget Android phones with zero user interaction.
RubyGems CDN Caching Bug Could Leak Legacy API Keys to Other Users
A RubyGems.org CDN caching flaw could leak legacy API keys between users for up to an hour; CVSS 7.2, all legacy keys have been revoked.
Report Alleges Unisoc/Longcheer Supply Chain Compromise via System Apps
A forensic report claims signed system apps on Unisoc/Longcheer devices enable covert C2 tunnels and anti-forensic kernel panic attacks.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comRust crate arrayref 0.3.10 pulls in malware via proc-macro1 dependency
crates.io package arrayref 0.3.10 pulls in malicious proc-macro1, executing remote payloads and affecting Rust GUI projects like egui and iced.
Popular ModHeader Chrome Extension Exfiltrates User Data
Reverse engineering reveals ModHeader, a 1.6M-install Chrome extension, secretly exfiltrates encrypted browsing data via a hidden AES-GCM pipeline.
NixOS Study Extends Trusting-Trust Backdoor Attack Beyond Compilers
New research shows Thompson's trusting-trust attack works via GNU strip, not just compilers, silently backdooring NixOS package builds.
Jailbox: Hardened, Network-Isolated KVM VMs for AI Coding Agents
Jailbox creates hardened, network-isolated KVM VMs to contain AI coding agents and untrusted code, with no route back to your host or LAN.
Shai-Hulud npm Worm Infects Over 1,280 Packages
Shai-Hulud npm worm spread credential-stealing malware across over 1,280 packages.
Cargo Symlink Flaw Disclosed as CVE-2026-5223
CVE-2026-5223: Cargo mishandled symlinks in third-party registry tarballs, risking cache overwrites; fixed in Rust 1.96.0.
AI Escape Room: Docker CTF Rebuilds the 2026 Hugging Face Breach
A Docker Compose CTF lab recreates the 2026 Hugging Face agent breach, covering SSRF, SSTI, HDF5 exfiltration, and Kubernetes pivoting for security training.