Supply chain attacks continue to rise with notable cases such as Log4j, 3CX, and MOVEit in 2023. The attacks exploit vulnerabilities in open-source software, third-party apps, AI-made malware, insider threats, and lack of encryption, affecting areas like healthcare, finance, and government. Verizon has coined the term “supply chainpocalypse” for such attacks. To tackle this issue, organizations are encouraged to adopt a zero-trust security model involving multi-factor authentication and end-to-end encryption.

New Weaponized PyPI Package Attacking Developers to Steal Source Code
A malicious Python package named solana-token was discovered, designed to steal source code and sensitive data from Solana developers. Masquerading as a legitimate utility, it