ctipilot.ch
← Back to Weekly 2026-W26
NOTABLEsynthesis

Technology & SaaS supply chain — the week's busiest victim class

discovered 2026-06-22 00:14 UTCrun 2026-W25-0aacfe652 sourcesmulti-source

The most active victim class was technology and SaaS, reflecting the week's supply-chain theme (§ 6). Klue/Icarus (§ 2) cascaded through a SaaS integrator's customer base; Nintendo employee data was stolen from third-party HR-survey SaaS TinyPulse, not Nintendo's own systems (BleepingComputer, 2026-06-20; daily 06-20); a WordPress supply-chain compromise via Awesome Motive's CDN backdoored ~1.2M sites (Sansec, 2026-06-16; daily 06-16); and the Mastra npm scope compromise was attributed to North Korea (§ 6). The cross-cutting lesson: the breach increasingly enters through a vendor's plumbing, not the victim's perimeter.

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.