logo

CVE noise drowns out supply chain threats

ID: 5252105e-91b2-5d29-8c6f-9f71d900fb4d

STIX ID: report--5252105e-91b2-5d29-8c6f-9f71d900fb4d

Feed Name: ReversingLabs Blog

Threat Score
72/100

Date Published: 2026-06-02

Date Updated: 2026-06-03

Author: John P. Mello Jr.

...
...

Black Kite reports that although tens of thousands of CVEs were published in 2025, only a small fraction (58) posed real supply-chain risk; AI is accelerating both vulnerability discovery and attacker exploitation, often before public disclosure. The article warns that CVE-centric defenses miss supply-chain attacks and cites ReversingLabs' disclosure of 31 malicious @redhat-cloud-services npm packages that delivered an obfuscated credential-stealing payload (targeting AWS, Azure, GCP, Vault, GitHub, npm) which executed during npm install with no CVE assigned, arguing for behavioral/binary analysis and continuous package monitoring to detect threats that vulnerability scanners cannot.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.