Critical Minerals & the G2β¦
thinktankcalendar.com/event/f41681...
#Commodities #Global #SupplyChainSecurity

Critical Minerals & the G2β¦
thinktankcalendar.com/event/f41681...
#Commodities #Global #SupplyChainSecurity
π In the last day: 1 malicious package caught across npm, ahead of the public advisory. We were first on 33%.
AI agent skills deserve code-review energy. If a skill can browse, install packages, read files, or touch production workflows, treat it like executable supply chain risk - not a cute plugin. Scan before you trust. #AIAgents #SupplyChainSecurity
Banks must modernize their software supply chain nowβnot wait for full app rewrites to boost security. #SupplyChainSecurity #FinancialServices #DevSecOps #AIThreats https://thedailytechfeed.com/why-banks-must-secure-their-software-supply-chain-first-not-rewrite-everything/
β± Before the advisory: our scan flagged npm @bottino/[email protected] 50 days ahead of MAL-2026-17351.
Two compromised #GitHub Actions 'actions-cool' were re-enabled with malicious tags intact, silently restarting Mini Shai-Hulud worm across downstream workflows. One action has about 15,000 dependent repos!
π
#SupplyChainSecurity
π‘οΈ Krait Critical Minerals is focused on advancing high-value antimony assets in stable North American jurisdictions.
Find out more with MiningIR β‘οΈ miningir.com/featured-compa...
#Antimony #CriticalMinerals #KRIT #DefenseTech #SupplyChainSecurity #MiningIR #MiningNews
A CVSS 10 GeoServer Cloud vulnerability in a GitHub Actions workflow could have leaked repository secrets. No abuse found, and the workflow is gone.
#GeoServer #GeoServerCloud #GitHubActions #SupplyChainSecurity #CICD #DevSecOps #OpenSource #SecretsLeak
β± 3 days of lead time on npm [email protected]: we flagged it, then MAL-2026-17228 confirmed it.
π In the last day: 10 malicious packages caught across npm, ahead of the public advisory. We were first on 52%.
TUE | 29 SEPT 2026 | Cybersecurity Report #Cybersecurity #CyberFM #AriasThomas #ThreatIntel #SupplyChainSecurity #MobileSecurity #CloudSecurity #InfoSec #EnterpriseSecurity #RSSHDelivery #NewYorkTech #TechTok #CyberTok
OpenAIβs GPT-6 Astra ran supply chain attacks despite being told not to
π Read more: www.helpnetsecurity.com/2026/09/29/o...
figlet-chalk-render v1.2.1 (npm) contains CRITICAL malicious code: on import, it downloads & runs a Windows executable, evading CI/sandbox. Remove & audit dependencies now. https://radar.offseq.com/threat/malicious-code-in-figlet-chalk-render-npm-e2cae6cc542e670e #OffSeq #npm #SupplyChainSecurity
π Our week: 67 malicious packages flagged across the ecosystems, npm the hottest, typically 0 days before the advisory landed.
β± 2 days of lead time on npm [email protected]: we flagged it, then MAL-2026-17215 confirmed it.
π In the last day: 5 malicious packages caught across pypi, ahead of the public advisory. We were first on 21%.
SUN | 27 SEPT 2026 | Cybersecurity Report #Cybersecurity #CyberFM #AriasThomas #PowerGrid #LegalTech #SupplyChainSecurity #InfoSec #EnterpriseSecurity #RSSHDelivery #NewYorkTech #TechTok #CyberTok
π Canada Launches Critical Minerals Strategy Targeting Chinese Market Dependence
π Read the full update:
β‘οΈhttps://miningir.com/canada-launches-critical-minerals-strategy-targeting-chinese-market-dependence/
#Canada #CriticalMinerals #CriticalMineralsStrategy #SupplyChainSecurity #Diversi
β± We flagged npm [email protected] 7 hours before the public advisory landed (MAL-2026-17190).
π In the last day: 7 malicious packages caught across npm and pypi, ahead of the public advisory. We were first on 12%.