Mr.Trunk · @mrtrunk
5 followers · 10663 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
5 followers · 10562 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
4 followers · 6989 posts · Server dromedary.seedoubleyou.me
Marcel SIneM(S)US · @simsus
205 followers · 4624 posts · Server social.tchncs.de

: Abandoned Buckets Used for Malicious Payloads
Threat actors have been taking over abandoned S3 buckets to launch malicious binaries, steal login credentials and more. hackread.com/supply-chain-atta

#supplychainattack #s3

Last updated 2 years ago

Manuel Bissey · @mbissey
30 followers · 471 posts · Server cyberplace.social

Snack giant Mondelez is warning past and present employees that their personal information may now be in the hands of hackers following a data at a third-party firm 🤖👩‍💻

bitdefender.com/blog/hotforsec

#breach #supplychainattack

Last updated 2 years ago

Marcel SIneM(S)US · @simsus
179 followers · 3286 posts · Server social.tchncs.de
GeekProjects News · @news
4 followers · 3116 posts · Server geekprojects.com
IT News · @itnewsbot
3074 followers · 255592 posts · Server schleuss.online

This Week in Security: Cookie Monster, CyberGhost, NEXX, and Dead Angles - “Operation Cookie Monster” ranks as one of the best code names in recent memory. A... - hackaday.com/2023/04/07/this-w

#vpn #nexx #news #securityhacks #hackadaycolumns #supplychainattack #thisweekinsecurity

Last updated 2 years ago

Edu Minguez 🐧 · @minWi
161 followers · 372 posts · Server tty0.social

RT @fr0gger_
🔍If you are looking for a comprehensive overview of the current supply chain attack, I created a diagram that shows the attack flow!💥I'll update as soon as the analysis progresses. Stay tuned for the MacOS edition!

#3cx #cybersecurity #infosec #supplychainattack #3cxpocalypse

Last updated 2 years ago

GeekProjects News · @news
4 followers · 3116 posts · Server geekprojects.com
IT News · @itnewsbot
3054 followers · 254754 posts · Server schleuss.online

This Week in Security: Macstealer, 3CX Carnage, and Github’s Lost Key - There’s a naming overload here, as two bits of security news this week are using t... - hackaday.com/2023/03/31/this-w

#news #macstealer #securityhacks #hackadaycolumns #supplychainattack #thisweekinsecurity

Last updated 2 years ago

Tech news from Canada · @TechNews
421 followers · 11322 posts · Server mastodon.roitsystems.ca

Ars Technica: Trojanized Windows and Mac apps rain down on 3CX users in massive supply chain attack arstechnica.com/?p=1927920 &IT

#Tech #arstechnica #it #technology #supplychainattack #biz #3cx

Last updated 2 years ago

IT News · @itnewsbot
3051 followers · 254636 posts · Server schleuss.online

Trojanized Windows and Mac apps rain down on 3CX users in massive supply chain attack - Enlarge (credit: Getty Images)

Hackers working on behalf of th... - arstechnica.com/?p=1927920

#3cx #biz #supplychainattack

Last updated 2 years ago

runejuhl · @runejuhl
4 followers · 10 posts · Server infosec.exchange

Been spending some time with , trying to package some programs.

First off: Guix is amazing. The ideas, the features, the parens. Much love since I first saw @civodul talk at some time in the past decade.

Second: packaging is absurd, holy hell! Started out trying to make a Guix package definition for Apache (jumping into the deep end straight away), and left that alone after the Java project demanded that and be installed (alright, not too bad), and continued to pull down and , along with packages. So many entry points for !

#guix #golang #fosdem #solr #perl #python #gradle #nodejs #npm #supplychainattack

Last updated 3 years ago

Manuel Bissey @DART · @mbissey
0 followers · 3 posts · Server cyberplace.social

The hack of SolarWinds' software more than two years ago pushed the threat of software supply chain attacks to the front of security conversations, but is anything being done?.… 👩‍💻🤖

go.theregister.com/feed/www.th

#supplychainattack

Last updated 3 years ago

Mab@DART · @mbissey
0 followers · 1 posts · Server cyberplace.social

98% of organizations have vendor relationships with at least one third-party that has experienced a breach in the last two years☝️🛡️

helpnetsecurity.com/2023/02/02

#supplychainattack #breach

Last updated 3 years ago

forgrindan · @forgrindan
14 followers · 104 posts · Server flokinet.social

Wieder Pakete mit in -Code-Repository entdeckt, diesmal war betroffen, Python Package Index, das offizielle - für die .
Die Pakete colorslib, httpslib, and libhttps enthielten jeweils identische Setup-Dateien, durch die Schadcode nachgeladen wird. Sie wurden alle von einem User hochgeladen.

, PyPI, ... Vorsicht ist wohl geboten



arstechnica.com/information-te

#malware #opensource #pypi #software #repository #programmiersprache #python #rubygems #npm #supplychainattack

Last updated 3 years ago

「 The author also positions each package as legitimate and clean by including a convincing project description. However, these packages download and run a malicious binary executable.

Python end users should always perform due diligence before downloading and running any packages, especially from new authors. And as can be seen, publishing more than one package in a short time period is no indication that an author is reliable 」

#pypi #python #zerodays #cybersecurity #supplychainattack

Last updated 3 years ago

「The FortiGuard Labs team has discovered a new 0-day attack embedded in three PyPI packages (Python Package Index) called ‘colorslib’, ‘httpslib’, and “libhttps”. They were found on January 10, 2023, by monitoring an open-source ecosystem. The Python packages “colorslib” and “httpslib” were published on January 7, 2023, and “libhttps” was published on January 12, 2023. All three were published by the same author」

fortinet.com/blog/threat-resea

#python #zerodays #cybersecurity #supplychainattack #pypi

Last updated 3 years ago