Software developmentfromSecuritymagazine3 months agoTyposquatted packages delivering malware to Linux and macOS systemsA malicious campaign using typosquatted Go packages is targeting Linux and macOS systems to deliver malware.
Growth hackingfromThe Hacker News4 months agoSeven Malicious Go Packages Found Deploying Malware on Linux and macOS SystemsOngoing campaign targets Go ecosystem with typosquatted modules deploying malware on Linux and macOS.
Software developmentfromInfoQ2 months agoGoogle Go Module Mirror Served Backdoor for 3+ YearsResearch uncovered a major supply chain attack in the Go ecosystem involving a backdoored package.The attack exploited caching in the Go Module Proxy, emphasizing security vulnerabilities in module management.
DevOpsfromTheregister3 months agoSeparate supply chain attack tied to 23K pwned GitHub reposThe GitHub supply chain attack was likely initiated through a compromised GitHub Action, reviewdog/action-setup, leading to extensive data breaches.
Information securityfromThe Hacker News1 month agoDragonForce Exploits SimpleHelp Flaws to Deploy Ransomware Across Customer EndpointsDragonForce ransomware exploited vulnerabilities in a Managed Service Provider's SimpleHelp tool for data exfiltration and ransomware deployment.
E-CommercefromArs Technica2 months agoHundreds of e-commerce sites hacked in supply-chain attackA supply-chain attack compromised hundreds of e-commerce sites, allowing malware to steal payment information from visitors.Malware that had been dormant for six years is now actively stealing sensitive data from e-commerce customers.
Software developmentfromSecuritymagazine3 months agoTyposquatted packages delivering malware to Linux and macOS systemsA malicious campaign using typosquatted Go packages is targeting Linux and macOS systems to deliver malware.
Growth hackingfromThe Hacker News4 months agoSeven Malicious Go Packages Found Deploying Malware on Linux and macOS SystemsOngoing campaign targets Go ecosystem with typosquatted modules deploying malware on Linux and macOS.
Software developmentfromInfoQ2 months agoGoogle Go Module Mirror Served Backdoor for 3+ YearsResearch uncovered a major supply chain attack in the Go ecosystem involving a backdoored package.The attack exploited caching in the Go Module Proxy, emphasizing security vulnerabilities in module management.
DevOpsfromTheregister3 months agoSeparate supply chain attack tied to 23K pwned GitHub reposThe GitHub supply chain attack was likely initiated through a compromised GitHub Action, reviewdog/action-setup, leading to extensive data breaches.
Information securityfromThe Hacker News1 month agoDragonForce Exploits SimpleHelp Flaws to Deploy Ransomware Across Customer EndpointsDragonForce ransomware exploited vulnerabilities in a Managed Service Provider's SimpleHelp tool for data exfiltration and ransomware deployment.
E-CommercefromArs Technica2 months agoHundreds of e-commerce sites hacked in supply-chain attackA supply-chain attack compromised hundreds of e-commerce sites, allowing malware to steal payment information from visitors.Malware that had been dormant for six years is now actively stealing sensitive data from e-commerce customers.
Node JSfromThe Hacker News2 months agoRipple's xrpl.js npm Package Backdoored to Steal Private Keys in Major Supply Chain AttackXRPL.js, a popular JavaScript library, was compromised in a supply chain attack aimed at harvesting users' private keys.
fromTheregister6 months agoInformation securityOpenWrt supply chain attack scare prompts urgent upgrades
Node JSfromThe Hacker News2 months agoRipple's xrpl.js npm Package Backdoored to Steal Private Keys in Major Supply Chain AttackXRPL.js, a popular JavaScript library, was compromised in a supply chain attack aimed at harvesting users' private keys.
fromTheregister6 months agoInformation securityOpenWrt supply chain attack scare prompts urgent upgrades