#supply-chain

2 posts

Jul 4, 2026

CVE-2026-48558: Critical SimpleHelp RMM Authentication Bypass — Unsigned OIDC Tokens Enable Full MSP Takeover

An in-depth technical analysis of CVE-2026-48558, a CVSS 10.0 authentication bypass in SimpleHelp RMM that lets unauthenticated attackers forge OIDC tokens, create Technician accounts, and gain administrative control over every managed endpoint. Actively exploited with TaskWeaver and Djinn Stealer payloads.

Jul 2, 2026

AI Supply Chain Security in 2026: The Hidden Link That Controls Your Model Pipeline

A comprehensive deep research analysis of AI supply chain security — from PyTorch dependency poisoning and Hugging Face model backdoors to NIST AI 600-1 provenance requirements, ML-BOM mandates, and the defense controls that actually work for production AI pipelines.