Tag Archives: dependency confusion

Backdoor in public repository used new form of attack to target big firms

reader comments 19 with 17 posters participating Share this story A backdoor that researchers found hiding inside open source code targeting four German companies was the work of a professional penetration tester. The tester was checking clients’ resilience against a new class of attacks that exploits public repositories used by millions of software projects worldwide.… Read More »

A new type of supply-chain attack with serious consequences is flourishing

reader comments 50 with 37 posters participating Share this story A new type of supply chain attack unveiled last month is targeting more and more companies, with new rounds this week taking aim at Microsoft, Amazon, Slack, Lyft, Zillow, and an unknown number of others. In weeks past, Apple, Microsoft, Tesla, and 32 other companies… Read More »