Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
7 résultats taggé Supply-chain-security  ✕
An Ongoing Open Source Attack Reveals Roots Dating Back To 2021 https://checkmarx.com/blog/an-ongoing-open-source-attack-reveals-roots-dating-back-to-2021/
01/09/2023 09:01:02
QRCode
archive.org
thumbnail

Developers in the cryptocurrency sphere are being targeted once again, as yet another threat actor has been exposed. This user has been publishing malicious NPM packages with the purpose of exfiltrating sensitive data such as source code and configuration files from the victim’s machines. The threat actor behind this campaign has been linked to malicious activity dating back to 2021. Since then, they have continuously published malicious code.

checkmarx EN 2023 malicious NPM Supply-chain-security
Compromised PyTorch-nightly dependency chain between December 25th and December 30th, 2022. https://pytorch.org/blog/compromised-nightly-dependency/
02/01/2023 11:38:36
QRCode
archive.org
thumbnail

If you installed PyTorch-nightly on Linux via pip between December 25, 2022 and December 30, 2022, please uninstall it and torchtriton immediately, and use the latest nightly binaries (newer than Dec 30th 2022).

$ pip3 uninstall -y torch torchvision torchaudio torchtriton
$ pip3 cache purge
PyTorch-nightly Linux packages installed via pip during that time installed a dependency, torchtriton, which was compromised on the Python Package Index (PyPI) code repository and ran a malicious binary. This is what is known as a supply chain attack and directly affects dependencies for packages that are hosted on public package indices.

PyTorch EN 2022 Linux pip Compromised dependency Supply-chain-security
SentinelSneak: Malicious PyPI module poses as security software development kit https://blog.reversinglabs.com/blog/sentinelsneak-malicious-pypi-module-poses-as-security-sdk
21/12/2022 00:05:00
QRCode
archive.org
thumbnail

A malicious Python file found on the PyPI repo adds backdoor and data exfiltration features to what appears to be a legitimate SDK client from SentinelOne.

reversinglabs EN 2022 PyPI Supply-chain-security Python exfiltration module kit
Phylum Detects Ongoing Typosquat/Ransomware Campaign in PyPI and NPM https://blog.phylum.io/phylum-detects-active-typosquatting-campaign-in-pypi
12/12/2022 15:55:58
QRCode
archive.org
thumbnail

Malicious packages that download ransomware binaries written in Golang published today, with more expected in the coming hours.

phylum EN 2022 Typosquat Ransomware PyPI NPM Supply-chain-security
PyPI package 'ctx' and PHP library 'phpass' compromised to steal environment variables https://blog.sonatype.com/pypi-package-ctx-compromised-are-you-at-risk
25/05/2022 06:59:04
QRCode
archive.org
thumbnail

This week, immensely popular PyPI package 'ctx' has been compromised and altered to steal environment variables from its users. Additionally, a forked PHP project 'phpass' also suffered a repo-hijacking attack with the project tained with identical malicious payload.

PyPI ctx PHP supplychain attack sonatype EN 2022 exfiltration steal Supply-chain-security
CrateDepression | Rust Supply-Chain Attack Infects Cloud CI Pipelines with Go Malware https://www.sentinelone.com/labs/cratedepression-rust-supply-chain-attack-infects-cloud-ci-pipelines-with-go-malware/
23/05/2022 09:03:56
QRCode
archive.org
thumbnail

Software developers using GitLab CI are being targeted with malware through a typosquatting attack, putting downstream users at risk.

sentinelone EN 2022 supply-chain Supply-chain-security Rust CrateDepression malicious dependency
EU lands new law to fight off hackers in critical sectors https://www.politico.eu/article/eu-lands-new-law-to-fight-off-hackers-in-critical-sectors/
14/05/2022 09:38:51
QRCode
archive.org
thumbnail

Rules for industries and governments aim to prevent all-out cyber breakdown.

Politico EN 2022 EU directive 5G Bart-Groothuis Communications Critical-infrastructure Cyber-Espionage Cybercrime Cybersecurity Data-flows Digital-Industry Eva-Maydell Hackers Internet-of-Things Network-security Privacy Supply-chain-security Telecoms Telecoms-Infrastructure
4460 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio