Over 35 Tech Companies Compromised in Novel Software Supply Chain Attack | HackerNoon

  • 📰 hackernoon
  • ⏱ Reading Time:
  • 42 sec. here
  • 2 min. at publisher
  • 📊 Quality Score:
  • News: 20%
  • Publisher: 51%

대한민국 뉴스 뉴스

대한민국 최근 뉴스,대한민국 헤드 라인

'Over 35 Tech Companies Compromised in Novel Software Supply Chain Attack' by sonatype sonatype vulnerabilities

foobarIn this case, that would mean, the attacker’s counterfeitmake its way into your software build.

He wondered what would happen if he squatted the private package names listed in the manifest on the npm open-source registry, open to everyone. All other 200+ packages published by Birsan in npm, RubyGems, and PyPI ecosystems contain identical code and perform the same actions. “At this point, I feel that it is important to make it clear that every single organization targeted during this research has provided permission to have its security tested, either through public bug bounty programs or through private agreements. Please do not attempt this kind of test without authorization,” Birsan has warned in his blog post.

And the biggest leverage the researcher had in this attack, it triggered automatically without requiring human error as we have seen with typosquatting and brandjacking attacks.

 

귀하의 의견에 감사드립니다. 귀하의 의견은 검토 후 게시됩니다.
이 소식을 빠르게 읽을 수 있도록 요약했습니다. 뉴스에 관심이 있으시면 여기에서 전문을 읽으실 수 있습니다. 더 많은 것을 읽으십시오:

 /  🏆 532. in KR

대한민국 최근 뉴스, 대한민국 헤드 라인

Similar News:다른 뉴스 소스에서 수집한 이와 유사한 뉴스 기사를 읽을 수도 있습니다.

Shipping, manufacturing delays upset board game industryBoard game publishers say supply chain and manufacturing issues have forced them to raise prices.
출처: fox7austin - 🏆 594. / 51 더 많은 것을 읽으십시오 »