The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Logistics/Procurement

Breach intelligence, attack campaigns, and threat reports targeting the Logistics/Procurement sector.

40 threat reports
Page 1 of 4

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Logistics/Procurement Threat Reports

Showing 1–12 / 40 reports
Critical Vulnerabilities Expose Botslab Dashcams to Complete Remote Takeover
Impact· MEDIUM

Critical Vulnerabilities Expose Botslab Dashcams to Complete Remote Takeover

CISA published advisory ICSA-26-267-01 detailing 13 critical vulnerabilities in Botslab G980H dashcams affecting two firmware versions worldwide. The vulnerabilities include authentication bypass, session hijacking, predictable session identifiers, hard-coded credentials, unencrypted communications, and path traversal flaws with CVSS scores up to 8.8. Attackers with adjacent network access can gain unauthorized device control, access sensitive recordings and location data, intercept WiFi credentials, and potentially install malicious firmware. Botslab has not responded to CISA's coordination efforts, leaving users without official patches or remediation guidance. This incident highlights the growing security risks in IoT devices within transportation infrastructure, as dashcams increasingly capture sensitive location data and connect to corporate networks through fleet management systems.

7 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Corp MDM Android Spyware Campaign Exposes Critical Mobile Security Gaps in Logistics Sector
Impact· HIGH

Corp MDM Android Spyware Campaign Exposes Critical Mobile Security Gaps in Logistics Sector

In September 2026, a sophisticated Android spyware campaign dubbed Corp MDM targeted logistics firms including CEVA and TKW Logistics through fake Google Play Store pages. The malware, distributed via fraudulent APK files disguised as system services, enabled attackers to intercept SMS messages, redirect calls, and maintain persistent device access. The campaign utilized cleartext HTTP communications to exfiltrate sensitive data including one-time passwords, transaction notifications, and delivery updates, with command-and-control infrastructure hosted at IP address 69.55.61.82. The operation appears to be orchestrated by Russian-Armenian threat actors and represents part of a broader multi-platform assault on the logistics sector involving credential phishing and Windows-based malware. This incident highlights the escalating sophistication of mobile-targeted supply chain attacks as threat actors increasingly weaponize AI-assisted development and exploit the logistics sector's heavy reliance on mobile communications for operational coordination.

7 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Bransys ELD Vulnerabilities Expose Transportation Fleet Data Through Hardcoded Credentials
Impact· HIGH

Critical Bransys ELD Vulnerabilities Expose Transportation Fleet Data Through Hardcoded Credentials

In September 2026, CISA disclosed critical vulnerabilities in Bransys Electronic Logging Device (ELD) systems affecting both Android and iOS versions. The vulnerabilities included hardcoded MQTT and FTP credentials (CVE-2026-86520, CVE-2026-77960) and cleartext transmission of sensitive information (CVE-2026-86689). These flaws could allow unauthorized attackers to access real-time telemetry data from active devices across multiple transportation carriers, potentially compromising driver location data, vehicle diagnostics, and compliance records. The vendor has released patches requiring users to update to Android version 11.00.00 or iOS version 1.1.54. This incident highlights the growing security risks in critical transportation infrastructure as IoT devices become more interconnected. With increasing regulatory scrutiny on supply chain security and the recent focus on transportation system vulnerabilities following nation-state attacks on critical infrastructure, organizations must prioritize secure development practices and regular security assessments of embedded systems.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Trezor Supply Chain Attack: When Legitimate Email Infrastructure Becomes a Weapon
Impact· CRITICAL

Trezor Supply Chain Attack: When Legitimate Email Infrastructure Becomes a Weapon

In September 2026, cryptocurrency hardware wallet maker Trezor warned customers that threat actors had breached its third-party email provider and were conducting sophisticated phishing attacks. The attackers sent fake "critical security alert" emails from help@trezor.io, claiming a hardware microcontroller vulnerability in STM32 chips could expose wallet seeds to brute-force attacks. This incident followed a previous breach of Trezor's shipping provider ShipMonk in August 2026, which compromised data from 81,000 customers across multiple countries. The ShipMonk breach exploited a critical SQL injection zero-day vulnerability in the Metabase analytics platform, with the ShinyHunters extortion gang subsequently targeting the company. This incident highlights the growing trend of supply chain attacks targeting cryptocurrency platforms and the increasing sophistication of phishing campaigns that leverage compromised legitimate infrastructure to bypass security controls and user awareness training.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Trezor Breach Exposes 81,000 Customers: Third-Party Risk Management Failures
Impact· CRITICAL

Trezor Breach Exposes 81,000 Customers: Third-Party Risk Management Failures

In August 2026, cryptocurrency hardware wallet maker Trezor disclosed a significant data breach at its third-party shipping provider ShipMonk, initially affecting 14,000 customers across multiple countries. The breach expanded dramatically when it was revealed that ShipMonk had failed to delete historical customer data as contractually required, ultimately exposing personal information of 81,000 customers including names, addresses, email addresses, and phone numbers. The attack exploited a critical SQL injection zero-day vulnerability in the Metabase analytics platform, with the ShinyHunters extortion gang later claiming responsibility and sending extortion demands to ShipMonk. This incident highlights the persistent vulnerability of third-party supply chains and the critical importance of data retention policies in an era where cryptocurrency adoption is accelerating and regulatory scrutiny is intensifying. The breach demonstrates how a single compromised analytics platform can cascade across multiple organizations, affecting everything from hardware manufacturers to online service providers.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
ShineyHunters Exploit Zero-Day to Breach Trezor's Shipping Partner
Impact· CRITICAL

ShineyHunters Exploit Zero-Day to Breach Trezor's Shipping Partner

In August 2026, hardware wallet manufacturer Trezor disclosed that 67,000 U.S. customers had their personal data exposed through a breach at shipping provider ShipMonk. The ShineyHunters extortion gang exploited CVE-2026-72898, a critical SQL injection vulnerability in Metabase with a CVSS score of 10.0, to gain unauthorized access to ShipMonk's systems. The exposed data included customer names, email addresses, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021, despite Trezor's repeated requests for data deletion per their 90-day retention policy. This supply chain attack highlights how third-party vulnerabilities can impact customer data even when primary security measures are robust. This incident demonstrates the growing threat of supply chain compromises targeting logistics and fulfillment providers, with attackers increasingly exploiting zero-day vulnerabilities in business intelligence platforms to access customer databases across multiple organizations simultaneously.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
ClickFix Attackers Exploit Polygon Blockchain in Campaign Against 31 Organizations
Impact· HIGH

ClickFix Attackers Exploit Polygon Blockchain in Campaign Against 31 Organizations

In September 2026, a sophisticated ClickFix campaign compromised at least 31 organizations across e-commerce, professional services, and retail logistics sectors. The attackers employed EtherHiding techniques, abusing the Polygon blockchain as a dynamic command-and-control infrastructure to evade traditional detection methods. Unlike typical ClickFix campaigns that deploy infostealers, this operation functioned as an initial access broker (IAB), installing persistent backdoors that survive reboots and communicate with C2 servers updated via blockchain transactions costing fractions of cents. This incident represents a concerning evolution in cybercriminal tactics, demonstrating how threat actors are weaponizing blockchain technology for resilient C2 infrastructure. The campaign's dual-victim approach, targeting both website owners through mass exploitation and end-users through social engineering, highlights the growing sophistication of modern cyber attacks and the need for comprehensive defense strategies addressing both technical vulnerabilities and human factors.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Critical Password Hash Vulnerability Exposes Rockwell Automation Fleet Management Systems
Impact· MEDIUM

Critical Password Hash Vulnerability Exposes Rockwell Automation Fleet Management Systems

Rockwell Automation's OTTO Fleet Manager versions 2.36.2 and earlier contain a critical vulnerability (CVE-2026-75112) involving insufficient computational effort in bcrypt password hashing implementation. This weakness reduces the computational cost for attackers to perform offline brute-force attacks against stored password hashes if they gain access to unencrypted system backups. The vulnerability affects industrial fleet management systems used worldwide in critical manufacturing and transportation sectors, with Rockwell Automation releasing version 2.36.3 to address the issue. This incident highlights the growing threat to industrial control systems and the critical importance of proper cryptographic implementations in operational technology environments, particularly as threat actors increasingly target industrial infrastructure with sophisticated attack techniques.

3 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Bendix EC80 Brake ECU Vulnerabilities Threaten Vehicle Safety Systems
Impact· HIGH

Critical Bendix EC80 Brake ECU Vulnerabilities Threaten Vehicle Safety Systems

In August 2026, CISA disclosed critical vulnerabilities in Bendix EC80 Brake ECU systems used across transportation infrastructure in the United States and Canada. The vulnerabilities include a stack-based buffer overflow (CVE-2026-67560), an out-of-bounds write (CVE-2026-68967), and hard-coded credentials (CVE-2026-71396). Successful exploitation could allow attackers to disable critical safety systems including ABS functions, steering assist, speedometer, automatic traction control, and shifting capabilities, potentially causing catastrophic vehicle safety failures. The vulnerabilities were discovered by Ben Gardiner of NMFTA and affect multiple EC80ESP+ and EC80ESP variants across different firmware versions. This incident highlights the growing threat landscape targeting industrial control systems and critical transportation infrastructure, as nation-state actors and cybercriminals increasingly focus on operational technology vulnerabilities that can cause physical harm and disrupt essential services.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Maritime Security Alert: FURUNO FA-50 AIS Transponder Vulnerabilities Expose Global Fleet
Impact· CRITICAL

Critical Maritime Security Alert: FURUNO FA-50 AIS Transponder Vulnerabilities Expose Global Fleet

Critical vulnerabilities CVE-2026-59769 and CVE-2026-67578 were discovered in FURUNO FA-50 Class B AIS Transponder devices used worldwide in maritime transportation systems. The flaws include hardcoded credentials and missing authentication for critical functions, allowing attackers with network access to alter device settings and configurations. With CVSS scores of 9.1 and 7.5 respectively, these vulnerabilities affect all versions of the discontinued product, leaving thousands of vessels potentially exposed to navigation system manipulation. FURUNO ended production in October 2020 and will not provide security updates, recommending only physical security measures and network isolation as mitigations. This incident highlights the growing risks of legacy IoT/OT devices in critical infrastructure, where end-of-life products continue operating without security support, creating persistent attack vectors that threaten maritime safety and operational integrity.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Valve Alerts Steam Hardware Customers to Data Breach via CEVA Logistics
Impact· MEDIUM

Valve Alerts Steam Hardware Customers to Data Breach via CEVA Logistics

Between July 29 and August 1, 2026, CEVA Logistics, the shipping partner for Valve's Steam hardware in Europe, experienced a cyberattack that compromised customer data. The attackers accessed names, addresses, phone numbers, email addresses, and details of purchased products. Valve confirmed that sensitive information such as payment details and Steam account credentials remained secure, as CEVA does not have access to this data. Affected customers have been notified and advised to be vigilant against potential phishing attempts. This incident underscores the vulnerabilities in supply chain partnerships and the importance of robust security measures across all entities handling customer data. As cyberattacks targeting third-party service providers become more prevalent, organizations must ensure comprehensive security protocols are in place to protect end-user information.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Cyberattack Disrupts North Carolina Ports Operations in August 2026
Impact· MEDIUM

Cyberattack Disrupts North Carolina Ports Operations in August 2026

In early August 2026, the North Carolina Ports Authority experienced a cyberattack that disrupted IT systems across the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. The incident, detected on August 4, led to a system-wide outage, causing operational delays and affecting cargo handling. The authority activated its cybersecurity contingency plan, initiating recovery efforts on August 5. While operations began returning to normal by August 7, residual delays persisted as system restoration continued. The specific nature of the attack, the threat actor involved, and whether sensitive data was compromised remain undisclosed. This incident underscores the escalating cyber threats targeting critical infrastructure, particularly in the maritime sector. Ports are increasingly becoming focal points for cyberattacks, highlighting the need for robust cybersecurity measures and contingency planning to mitigate operational disruptions and safeguard sensitive data.

1 month ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports