Tag Archives: dependency confusion

AI-generated code could be a disaster for the software supply chain. Here’s why.

In AI, hallucinations occur when an LLM produces outputs that are factually incorrect, nonsensical, or completely unrelated to the task it was assigned. Hallucinations have long dogged LLMs because they degrade their usefulness and trustworthiness and have proven vexingly difficult to predict and remedy. In a paper scheduled to be presented at the 2025 USENIX… Read More »

Backdoor in public repository used new form of attack to target big firms

reader comments 19 with 17 posters participating Share this story A backdoor that researchers found hiding inside open source code targeting four German companies was the work of a professional penetration tester. The tester was checking clients’ resilience against a new class of attacks that exploits public repositories used by millions of software projects worldwide.… Read More »

A new type of supply-chain attack with serious consequences is flourishing

reader comments 50 with 37 posters participating Share this story A new type of supply chain attack unveiled last month is targeting more and more companies, with new rounds this week taking aim at Microsoft, Amazon, Slack, Lyft, Zillow, and an unknown number of others. In weeks past, Apple, Microsoft, Tesla, and 32 other companies… Read More »