#dprk
2 cases
3CX Supply Chain Attack (CVE-2023-29059): The First Cascading Software CompromiseSupply Chain AttackState-Sponsored
A North Korean-linked actor compromised Trading Technologies' X_TRADER, used it to breach 3CX, and shipped signed, trojanised VoIP clients to its customers — the first documented case of one software supply chain attack causing another.
Supply Chain AttackState-Sponsored
Rust Ecosystem Supply-Chain Attack Targeting arrayrefSupply Chain Attack
On August 20, 2026, attackers hijacked a prominent Rust ecosystem crate and pushed a malicious update to `arrayref@0.3.10`, a small array-conversion utility with approximately 245 million lifetime...
Supply Chain Attack