supply chain
6 stories
Cl0p Targets 40+ Organizations Through PTC Windchill Flaw
The Cl0p ransomware group has claimed responsibility for exploiting a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM software, impacting over 40 organizations. The group is using a custom implant for data theft and extortion, demanding payment from victims. Several major companies, including Shell and Philips, are reportedly among the targeted entities, though most have only acknowledged awareness and are investigating.

Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports
The U.S. Coast Guard is investigating a cyberattack that disrupted operations at North Carolina's three major port facilities. The breach caused delays in gate openings and necessitated a shift to manual processing as the ports authority worked to contain the intrusion. While normal operations have resumed, the nature of the attack and its full impact remain undisclosed.

Cyberattack Disrupts Operations at Japanese Food Giant Nichirei
Nichirei, a major Japanese food company, has confirmed that a cyberattack on July 13th caused system outages, disrupting logistics and shipments. The company has established an emergency response team and is gradually restoring operations while withholding specific details to prevent further damage. The incident has impacted various businesses that rely on Nichirei's services, including restaurant chains and retailers.

Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks
An Iran-linked threat actor is using an adaptable modular command-and-control framework in cyberattacks. It compromised IT service providers to reach high-value targets primarily in Israel.

AI Hallucinations Create Phantom Domains for Supply Chain Attacks
Artificial intelligence models can generate domain names that do not actually exist, a phenomenon known as "phantom squatting." Attackers are leveraging this AI hallucination to create malicious domains that mimic legitimate ones, thereby posing a significant threat to software supply chains. This tactic allows them to potentially intercept or manipulate software development processes.

OpenClaw Skill Marketplace Faces AI Supply Chain Threat
Researchers have identified malicious skills within OpenClaw's ClawHub marketplace that evade automated detection. These skills are designed to deploy information-stealing malware and conduct automated financial fraud.