supply chain9 articles
Chinese Router Maker Says Its Firmware Backdoor Is Fine, Actually, Then Quietly Pulls Firmware
Chinese router vendor Zbtlink has denied that its firmware contains backdoors, claiming a suspicious remote-control feature found by security firm VulnCheck was intended solely for after-sales maintenance on sample units. However, the company simultaneously paused firmware downloads and acknowledged unspecified security vulnerabilities, contradicting its denial. VulnCheck's CTO described the code as a persistent, boot-loaded implant across more than 20 router models that phones home to external servers with no authentication, allowing anyone controlling those endpoints to issue commands to affected devices.
Oligo Security Pulls In $60M to Guard Apps at Runtime
Oligo Security has raised $60 million in a new funding round, bringing its total funding to $140 million, with participation from several venture capital firms including Ballistic Ventures and Lightspeed Venture Partners. The Tel Aviv-based company, founded in 2022, offers a runtime security platform that provides real-time protection for application code, cloud workloads, and AI systems, helping organizations detect and block exploits, prioritize vulnerabilities, and prevent supply chain attacks. Oligo plans to use the new funding to accelerate product development and expand its global operations.
US Slams the Door on Foreign Robots Over Security and Supply Chain Fears
The US government has effectively banned the import of advanced foreign-made robots, citing national security and supply chain risks, including vulnerabilities to data theft, remote disruption, and dependency on potentially hostile foreign entities. The FCC has added such devices to its Covered List of prohibited imports, with exceptions for devices approved by the Department of War and foreign-owned companies that manufacture their robots within the United States. Existing approved devices can continue to be imported and used, but the policy signals a clear shift toward requiring robots sold in America to be made in America.
Ransomware Knocks Out Fairlife Milk Production Across the US
Coca-Cola has suspended US production at its dairy subsidiary Fairlife following a ransomware attack that compromised portions of the company's systems, including production-related infrastructure. The company has activated incident response protocols, notified law enforcement, and is working with cybersecurity experts to assess the full impact, though it states that product quality and safety have not been affected. Key details such as the attackers' identity, how the breach occurred, and whether any ransom demands have been made remain undisclosed.
Nichirei Cyberattack Leaves Japan's Frozen Food Chain on Ice
Japanese frozen food giant Nichirei was hit by a cyberattack on July 13, forcing it to disconnect its systems and disrupting operations at its refrigerated warehouses and shipping divisions, with knock-on effects for restaurants, retailers, and delivery services. The company confirmed that hackers targeted its servers and that some affected systems contained personal information, prompting an initial report to Japan's Personal Information Protection Commission over a potential data leak. Nichirei announced it would begin gradually restoring operations but has withheld details of the attack, leaving it unclear whether a ransomware group was involved.
Citrix Bleed 2, Rogue Drivers, and Poisoned Packages: Ransomware Groups Are Getting Creative
Ransomware groups including Anubis, The Gentlemen, and the VECT/TeamPCP alliance are employing increasingly sophisticated tactics, such as exploiting the critical Citrix Bleed 2 vulnerability (CVE-2025-5777), using legitimate remote management tools to blend in with normal IT activity, and leveraging a BYOVD zero-day to disable enterprise security solutions. The VECT/TeamPCP partnership represents a notable evolution in the threat landscape, combining supply chain credential theft with ransomware deployment at scale, though implementation flaws in VECT's encryptor have undermined its effectiveness. The FBI has issued a flash alert warning that credentials and data stolen in these campaigns pose a persistent long-term risk, as affiliated actors are likely to continue weaponizing them well after the initial breach.
North Korean Hackers Are Quietly Poisoning Open Source Repositories
North Korean hackers are conducting a supply chain campaign called PolinRider, active since December 2025, targeting open source developers across NPM, Packagist, Go modules, and Chrome extensions. The attackers compromise maintainer accounts to inject obfuscated JavaScript loaders into legitimate repositories, which deliver the DEV#POPPER RAT and OmniStealer malware, with 162 malicious artifacts identified across 108 packages so far. Security firm Socket warns that any developers who installed affected packages should treat their environment as potentially compromised and conduct remediation from a clean machine, as credentials for package registries, cloud services, and CI/CD pipelines may have been exposed.
Iran's MOIS-Linked Hackers Deploy Modular C2 Framework Against Israeli Targets
An Iranian hacking group called Cavern Manticore, linked to Iran's Ministry of Intelligence and Security, has been targeting Israeli IT providers and government organisations using a newly discovered modular command-and-control framework called Cavern. The framework exploits SysAid's software update feature to deploy a trojanised DLL, enabling capabilities such as file theft, database access, Active Directory reconnaissance, network scanning, and tunnelling, while using multiple .NET compilation formats to deliberately complicate reverse engineering and forensic analysis. The group has also been observed moving laterally through trusted IT supply chain relationships and abusing remote monitoring tools, with related Iranian threat actors simultaneously conducting broader reconnaissance and data exfiltration campaigns across the Middle East.

Apple Hikes Prices Across the Board, Points Finger at Memory Costs
Apple has raised prices across most of its product lineup, with increases ranging from $100 to over $1,000 depending on the model, while iPhone prices remain unchanged for now. CEO Tim Cook attributes the hikes to soaring memory costs, stating that shielding customers from the increases has become "unsustainable." The root cause is a memory supply shortage driven by chipmakers prioritising more profitable data centre memory over consumer products amid surging AI investment.