← Back
Supply ChainWired Security·4 hours ago

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

A security researcher has identified nine vulnerabilities in ATM encryption and authentication software that expose critical weaknesses in the broader software supply chain. The flaws suggest that security issues affecting ATMs have implications reaching well beyond individual machines to impact interconnected systems and dependencies across the financial technology ecosystem.

Read full article at Wired Security

Related Articles

Supply ChainThe Hacker News·3 days ago

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

VulnCheck has discovered two pre-installed firmware implants in ZBT routers that enable unauthenticated attackers to achieve root-level command execution on affected devices. The implants, designated CVE-2026-74232 and CVE-2026-74233 and named SPEAKINGSTONE and DARKLANTERN respectively, represent a significant supply-chain risk for organizations deploying these Shenzhen Zhibotong Electronics devices.

Supply ChainGraham Cluley·3 days ago

Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more

Two individuals have been charged in connection with TeamPCP's extensive global supply chain attack campaign that compromised over 1,000 organizations and resulted in the theft of approximately 500,000 credentials, with OpenAI among the affected victims. The attackers deployed a self-propagating worm dubbed Shai-Hulud in their operation, demonstrating the sophisticated nature of their coordinated hacking spree. This case highlights the significant reach and impact of organized cyber threats targeting critical infrastructure and technology companies worldwide.

Supply ChainThe Register·3 days ago

Australian cops cuff alleged TeamPCP masterminds

Australian authorities have arrested alleged masterminds behind TeamPCP, a group responsible for developing the Shai-Hulud worm and conducting supply chain attacks. The operation was conducted in collaboration with the FBI, marking a significant enforcement action against the threat actor group.