Security Guard Magazine
    Thumbnail
    GitHub CodeQL supply chain vulnerability

    Critical GitHub CodeQL Vulnerability Exposes Supply Chain Attack Risk

    March 31, 2025 • 1 min read

    A security flaw in GitHub CodeQL temporarily exposed a privileged token that could enable supply chain attacks affecting thousands of repositories. The vulnerability allowed potential code execution and data theft through GitHub Actions workflows, though GitHub's swift response prevented any known compromises.

    Thumbnail
    malware cybercrime SQL supply chain

    Vietnamese Hackers Target Supply Chain with Zero-Day Exploits in VeraCore Software

    February 10, 2025 • 1 min read

    XE Group, a Vietnamese cybercrime organization, has evolved from credit card theft to sophisticated supply chain attacks by exploiting critical zero-day vulnerabilities in VeraCore. The group deployed advanced web shells to maintain persistent unauthorized access to manufacturing and distribution systems since 2020.

    Thumbnail
    AWS cybersecurity malware supply chain

    Hijacked AWS Storage Buckets Expose Major Organizations to Supply Chain Attacks

    February 06, 2025 • 1 min read

    Security researchers discovered 150 abandoned AWS S3 storage buckets previously used by major organizations that could be easily re-registered and hijacked. The vulnerability allowed researchers to gain control over storage locations still receiving millions of requests from government agencies and corporations.

  • 1

Free Security Guards Resource and Information Magazine