In a fresh development, such language generally doesn’t apply to our lives. But one concept has begun affecting us everyday users more—supply chain attacks. Cybersecurity for businesses involves a lot of jargon unfamiliar to us consumers, and for good reason.

According to the latest update, the bad actors focus on a weaker link in the chain, then use that opening to steal information from the main target. (Or at least, see what kind of dirt they can get on other organizations.). A supply chain attack is when hackers go after a vendor or partner that a publisher works with, rather than attacking the business directly.

The report highlights that now consumers often end up at risk after business-to-business attacks, too. It’s a fresh way of thinking about supply chain attacks—where they’re not just a problem for IT departments. Before AI, this kind of hack mostly stayed confined in the corporate realm.

According to the latest update, the hack of a Valve partner ended up affecting Steam Machine buyers in Europe.

As part of the ongoing story, but now with AI in the mix, they’re happening more often, and with bigger consequences. Just a few years ago, supply chain attacks were more rare—and quieter.

According to the latest update, (Think Nvidia, Samsung, Amazon, Microsoft, Airbus, FedEx, MediaTek, X/Twitter, Epic Product rollouts—and that’s just part of the list.) The attack focused on an open-source AI tool called LiteLLM, which pulls together large-language model use into a single interface. Through that breach, hackers stole credentials, secrets, tokens, and keys belonging to those major businesses. This summer alone, multiple supply chain attacks made the news, including a major one involving terabytes of data and the global stage’s largest corporations.

In a fresh development, meanwhile, modular PC maker Framework lost personal information on all customers after an exploit of Metabase, the partner who hosted the data. Meanwhile, closer to home for us consumers, Valve sent out a warning to Steam Machine buyers in Europe about the hack of a distributor.

Industry observers note that the danger: Use of the stolen data could end up in scam texts, email, or phone calls.

In a fresh development, (For example, we don’t know what will happen with the LiteLLM breach—if ripple effects will include further compromise of those major corporations.). Unfortunately, you can’t do much about cyberattacks on businesses, much less the fallout.

The report highlights that be suspicious of messages about package delays, problems with your accounts, or dangers lurking on your PC. But you can change how you interact with text, email, and phone call notifications.

In a fresh development, either call on a number you looked up on the website, go to the website in a tab you opened yourself, or open your app. If you think you may actually have an account issue, contact the website or service directly.

The report highlights that in the old days, people assumed having their basic details out on the web wasn’t a problem. But AI now allows bad actors to easily create personalized scams, with ever-increasing convincing detail, faster speed, and bigger target groups. Seeing them for what they are is becoming harder. So cut them off at the source. Bypass questionable messages and you shouldn’t get snared in their net. Why?

According to the latest update, since joining the team in 2016, she’s written about CPUs, Windows, PC building, Chrome, Raspberry Pi, and much more—while also serving as PCWorld’s resident bargain hunter (#slickdeals). Currently her focus is on security, helping people understand how best to protect themselves online. Her work has previously appeared in PC Gamer, IGN, Maximum PC, and Official Xbox Magazine. A 15-year veteran of technology and video platform releases journalism, Alaina Yee covers a variety of topics for PCWorld.