惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
人人都是产品经理
人人都是产品经理
爱范儿
爱范儿
WordPress大学
WordPress大学
T
Tor Project blog
Jina AI
Jina AI
美团技术团队
酷 壳 – CoolShell
酷 壳 – CoolShell
V
V2EX
雷峰网
雷峰网
博客园 - 聂微东
B
Blog RSS Feed
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 【当耐特】
Microsoft Azure Blog
Microsoft Azure Blog
S
SegmentFault 最新的问题
Recent Announcements
Recent Announcements
有赞技术团队
有赞技术团队
GbyAI
GbyAI
aimingoo的专栏
aimingoo的专栏
U
Unit 42
博客园 - Franky
Last Week in AI
Last Week in AI
阮一峰的网络日志
阮一峰的网络日志
Microsoft Security Blog
Microsoft Security Blog
F
Fortinet All Blogs
罗磊的独立博客
云风的 BLOG
云风的 BLOG
G
Google Developers Blog
大猫的无限游戏
大猫的无限游戏
Engineering at Meta
Engineering at Meta
C
Check Point Blog
Martin Fowler
Martin Fowler
The Cloudflare Blog
N
Netflix TechBlog - Medium
小众软件
小众软件
T
Tailwind CSS Blog
T
The Blog of Author Tim Ferriss
月光博客
月光博客
博客园 - 司徒正美
Stack Overflow Blog
Stack Overflow Blog
J
Java Code Geeks
Blog — PlanetScale
Blog — PlanetScale
P
Proofpoint News Feed
H
Help Net Security
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
The Exploit Database - CXSecurity.com
S
Securelist
I
Intezer
Spread Privacy
Spread Privacy

The Register - Off-Prem: SaaS

Snowflake to burn $6B on AWS Graviton CPUs and AI accelerators Google Cloud suspended major customer Railway.com without cause, causing outage Anthropic comes for the midmarket software spend ServiceNow under siege as Atlassian adds to ITSM take-outs Survey: US workers are not keen on Microsoft's AI Service change takes down Microsoft Outlook for iOS Workday, Rippling, Slack lflunk data access test: Fivetran UK tribunal sends £2B claim accusing Microsoft of overcharging for licensing to trial The spaghettified DBMS chart that shows Oracle's crown is slowly slipping Atlassian’s new data collection policy protects rich customers while AI eats the rest Atlassian to train AI on user data unless law or cash say no McGraw Hill linked to 13.5M-record data leak UK told its Big Tech habit is now a national security risk How ServiceNow gets customers to gorge at the AI trough Salesforce is taking on ServiceNow in ITSM. The winner is AI Salesforce is taking on ServiceNow in ITSM. The winner is AI Snowflake manager on 'Spider-Man' theory of AI agents Minnesota payroll problems grew after Workday, say auditors Salesforce looks to Slackbot to help solve SaaSpocalypse ServiceNow salesman sues employer in commission dispute ServiceNow salesman sues employer in commission dispute Big Tech has not enforced Australia’s social media ban 'Emphathetic 'Salesforce bots to help fired via Labor Dept Datadog bets DIY AI will mean it dodges the SaaSpocalypse Snowflake's ongoing pitch: bring AI to data, not vice versa CMA dithers as Microsoft's cloud meter runs on your dime Salesforce acquihires team behind Clockwise for Agentforce CMA cracks knuckles, eyes Adobe's cancellation fees SAP's grand cloud escape plan €2B short of the runway Microsoft 365 pauses Copilot creep after admins cry foul Salesforce buyback to saddle company with debt until 2066 India tests whether AI can stop trains hitting elephants Adobe CEO Shantanu Narayen to step down after 18 years Adobe CEO Shantanu Narayen to step down after 18 years Pentagon praises Palantir tech for battlefield strike speed Atlassian to shed ten percent of staff, because AI Atlassian's new Jira migration tool slowed down cloudy moves Oracle says AI coding is helping it dodge SaaSpocalypse Vendors building tools to clean up messes made by AI agents Iran is the first out-loud cyberwar the US has fought Microsoft postpones new Outlook migration to 2027 Okta CEO ‘paranoid’ as vibe coders stir SaaS-pocalypse fears Capita £370M Whitehall outsourcing deal challenged in court Claude having artificially intelligent hiccups and access lockouts for over two hours Claude outage hits chat, API, vibe coding SaaS-pocalypse isn't coming any time soon SaaS-pocalypse isn't coming any time soon Half of German-speaking SAP users to stay on ECC to 2030 Half of German-speaking SAP users to stay on ECC to 2030 Salesforce CEO declared victory over flagging software sales Workday CEO's AI talk can't shake off weaker sales forecast Microsoft teases ‘reimagined SharePoint’ with added AI Palantir spent $25M on CEO flights for chatty Karp Microsoft throws spox under the bus in ICC email flap ServiceNow buys Pyramid Analytics ServiceNow buys Pyramid Analytics Apple inserts ads for its premium productivity services Apple inserts ads for its premium productivity services Workday CEO steps down amid layoffs and market jitters Workday CEO steps down amid layoffs and market jitters Counting the waves of tech industry BS from blockchain to AI Atlassian swears it can deliver AI without blowing out costs Workday layoffs to hit about 400 jobs Rise of AI means companies could pass on SaaS Estonia tests Euro alternatives amid Microsoft rollout MEP: 'The EU runs on Microsoft', Uncle Sam could turn it off Azure outages ripple across multiple dependent services Europe shrugs off tariffs, plots to end tech reliance on US Microsoft ends some standalone SharePoint and OneDrive plans TikTok’s US joint venture off to a rocky start Oracle, Michael Dell, invest in JV to run TikTok USA Mandiant plugs Salesforce leaks with open source tool Data storage cloud Snowflake buys ITOM platform Observe ServiceNow snags Microsoft vet to run legal amid M&A spree ServiceNow to buy Armis in $7.7 billion security deal ServiceNow unworried by Salesforce targeting its ITSM core ServiceNow mulls Armis buy to gain IT visibility Workday project at Washington University hits $266M Here we go again: Microsoft in UK court over cloud licensing
Supply chain breaches fuel cybercrime cycle, report says
Connor Jones Connor Jones · 2026-02-12 · via The Register - Off-Prem: SaaS

Cyber-crime

Supply chain attacks now fuel a 'self-reinforcing' cybercrime economy

Researchers say breaches link identity abuse, SaaS compromise, and ransomware into a cascading cycle

Cybercriminals are turning supply chain attacks into an industrial-scale operation, linking breaches, credential theft, and ransomware into a "self-reinforcing" ecosystem, researchers say.

In its latest trends report, Group-IB reckons individual strikes that lead to broader downstream compromises of businesses are now interconnected as cyberbaddies pursue multiple methods to breach vendors and service providers.

Supply chain hacks like the recent Shai-Hulud NPM worm, Salesloft debacle, or the OpenClaw package poisoning are fast becoming the primary goals of the criminal fraternity who try to exploit the inherited access to a victim's customers.

"Open source package compromise feeds malware distribution and credential theft," the research states. "Phishing and OAuth abuse enable identity compromise that unlocks SaaS and CI/CD environments. Data breaches supply the credentials, context, and relationships needed to refine impersonation and lateral movement. Ransomware and extortion arrive later in the chain, capitalizing on access and intelligence gathered earlier. Each stage strengthens the next, creating a self-reinforcing cycle of supply chain exploitation."

Over the next year, GroupIB predicts supply chain attacks will be executed faster thanks to AI-assisted tools that can scan for vulnerabilities across vendors, CI/CD pipelines, and browser extension marketplaces at machine speed.

It also expects to see traditional malware replaced by identity attacks, whereby criminals set themselves up as genuine users and their activity blends into the normal daily business functions, evading detection for longer periods.

Platforms offering HR, CRM, and ERP, as well as MSPs, are high-priority targets, Group-IB says, as a single compromise can lead to hackers gaining access to hundreds of customers.

Evolution of data breaches

The Salesloft breach, as well as the Oracle compromise of March 2025, are examples of how data breaches are shifting from a single-reward model to one where access is used for additional compromises.

Instead of taking one big wedge of data and demanding an extortion payment, criminals took their time to collect OAuth tokens and exploit misconfigured partner connections to move laterally. They then target downstream customers, steal their data and contact lists to repeat the cycle, or, in cases involving NPM and similar ecosystems, serve malicious updates to users to carry out fraud at scale.

"Cybercrime is no longer defined by single breaches. It is defined by cascading failures of trust," said Dmitry Volkov, Group-IB CEO. 

"Attackers are industrializing supply chain compromise because it delivers scale, speed, and stealth. A single upstream breach can now ripple across entire industries. Defenders must stop thinking in terms of isolated systems and start securing trust itself, across every relationship, identity, and dependency."

Organizations should treat third parties as extensions of their own attack surface.

"Strategic investments in supply chain threat modeling, automated dependency checks, and data flow visibility are no longer optional – they are foundational to modern security architecture," said Volkov. ®