Saturday, June 7, 2025

Supply Chain Attacks Are Still the Weakest Link

 


Third-party breaches strike again—this time it’s LexisNexis and Adidas. This past week, data broker LexisNexis confirmed a major supply chain attack via GitHub, compromising the personal information of 364,000 people—including names, contact info, SSNs, and driver's licenses. Fortunately, financial data was spared… but your personal details? Gone. And they’re not alone—Adidas also reported a breach through a third-party customer service partner, affecting customer names, emails, phone numbers, and more. ⚠️ Phishing emails and spam calls are likely on the rise—stay alert. On a brighter note: a vulnerability researcher using OpenAI’s O3 model accidentally discovered a zero-day RCE flaw in the Linux Kernel’s SMB service. AI + cybersecurity = progress? https://www.databreachtoday.com/linux-zero-day-vulnerability-discovered-using-frontier-ai-a-28559 If you’re a Plixer customer, check out Section 4 of our Field Guide to learn how Plixer One helps detect and respond to threats like these—before they spiral into major breaches. https://www.plixer.com/plixer-field-guide/ Stay safe, stay informed, and don’t forget to like and subscribe for weekly updates on security, observability, and AI in action. https://www.darkreading.com/cyberattacks-data-breaches/lexisnexis-360k-customers-third-party-data-leak https://www.darkreading.com/vulnerabilities-threats/adidas-victim-third-party-data-breach

No comments:

Post a Comment