software supply chain attack - Tagged - Security Boulevard The Home of the Security Bloggers Network Fri, 29 Mar 2024 17:19:26 +0000 en-US hourly 1 https://wordpress.org/?v=6.4.3 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png software supply chain attack - Tagged - Security Boulevard 32 32 133346385 PyPI Goes Quiet After Huge Malware Attack: 500+ Typosquat Fakes Found https://securityboulevard.com/2024/03/pypi-suspended-500-fakes-richixbw/ Fri, 29 Mar 2024 17:19:26 +0000 https://securityboulevard.com/?p=2013426 Closeup of person going “Shhh!”

Emergency stop button: The Python Package Index was drowning in malicious code again, so they had to shut down registration for cleanup.

The post PyPI Goes Quiet After Huge Malware Attack: 500+ Typosquat Fakes Found appeared first on Security Boulevard.

]]>
2013426
Complex Supply Chain Attack Targets GitHub Developers https://securityboulevard.com/2024/03/complex-supply-chain-attack-targets-github-developers/ Tue, 26 Mar 2024 18:42:46 +0000 https://securityboulevard.com/?p=2013043 supply chain, SBOM, cybersecurity, SLSA organizations third party attacks supply chain supply chain ransomware The Kill Chain Model

Unidentified threat actors used multiple tactics to launch a sophisticated software supply-chain campaign targeting developers on the GitHub platform, including members of the popular Top.gg community that includes more than 170,000 members. The attackers used a range of tactics and techniques, from leveraging stolen browser cookies to take over accounts to contributing malicious code with..

The post Complex Supply Chain Attack Targets GitHub Developers appeared first on Security Boulevard.

]]>
2013043
GitHub Fights Forks — Millions of Them — Huge Software Supply Chain Security FAIL https://securityboulevard.com/2024/02/github-repo-confusion-supply-chain-richixbw/ Thu, 29 Feb 2024 16:37:11 +0000 https://securityboulevard.com/?p=2010508 A fork, wrapped in delicious pasta

Forking hell: Scrotebots clone thousands of projects, injecting malware millions of times.

The post GitHub Fights Forks — Millions of Them — Huge Software Supply Chain Security FAIL appeared first on Security Boulevard.

]]>
2010508
Malicious Packages in npm, PyPI Highlight Supply Chain Threat https://securityboulevard.com/2024/02/malicious-packages-in-npm-pypi-highlight-supply-chain-threat/ Mon, 26 Feb 2024 22:06:07 +0000 https://securityboulevard.com/?p=2010143 supply chain software

Software developers are being targeted with malicious packages in npm and PyPI as threat groups launch software supply-chain attacks.

The post Malicious Packages in npm, PyPI Highlight Supply Chain Threat appeared first on Security Boulevard.

]]>
2010143
Attackers Finding Novel Ways to Abuse GitHub: ReversingLabs https://securityboulevard.com/2023/12/attackers-finding-novel-ways-to-abuse-github-reversinglabs/ Wed, 20 Dec 2023 21:57:26 +0000 https://securityboulevard.com/?p=2002687 AI code fixing

Threat actors are finding new ways to take advantage of GitHub in hopes of tricking developers into putting malicious code into their software and sending to users downstream, according to researchers with ReversingLabs. Code repositories like GitHub and Python Package Index (PyPI) are popular targets for hackers who want to abuse the software supply chain..

The post Attackers Finding Novel Ways to Abuse GitHub: ReversingLabs appeared first on Security Boulevard.

]]>
2002687
UK, South Korea Warn of North Korea Supply-Chain Attacks https://securityboulevard.com/2023/11/uk-south-korea-warn-of-north-korea-supply-chain-attacks/ Mon, 27 Nov 2023 16:00:56 +0000 https://securityboulevard.com/?p=2000168 North Korea software supply chain Microsoft

The cybersecurity agencies in the UK and South Korea are warning of the growing threat of North Korea-linked threat groups using zero-day and third-party exploits to launch software supply-chain attacks. The hackers are targeting products that are widely used by government organizations, financial institutions, and defense industry companies around the world, the UK’s National Cyber..

The post UK, South Korea Warn of North Korea Supply-Chain Attacks appeared first on Security Boulevard.

]]>
2000168
Supply Chain Attacks and Cyberinsurance https://securityboulevard.com/2021/12/supply-chain-attacks-and-cyberinsurance/ Tue, 14 Dec 2021 08:30:08 +0000 https://securityboulevard.com/?p=1904228 Protect AI Chainguard supply chain Early in the Kill Chain

The rise in sophisticated supply chain cyberattacks doesn’t just affect enterprises; there are also impacts on the insurance industry and on enterprises’ cyberinsurance costs. What is a software supply chain attack? Software supply chain attacks are cyberattacks against an organization’s software supply chain infrastructure and process. In such attacks, the attacker gains access to a..

The post Supply Chain Attacks and Cyberinsurance appeared first on Security Boulevard.

]]>
1904228
Russia’s Nobelium Supply Chain Attacks Force U.S. Government’s Hand https://securityboulevard.com/2021/10/russias-nobelium-supply-chain-attacks-force-u-s-governments-hand/ Tue, 26 Oct 2021 11:01:24 +0000 https://securityboulevard.com/?p=1898603 Russian APT28 botnet FBI

Threats from the U.S. government apparently weren’t enough to keep Nobelium, the group behind the SolarWinds campaign, away from the vulnerable global IT supply chain—Microsoft said the threat actors, affiliated with Russian intelligence unit SVR, have attacked at least 140 managed service providers (MSPs) and cloud service providers, with 14 known breaches since May 2021...

The post Russia’s Nobelium Supply Chain Attacks Force U.S. Government’s Hand appeared first on Security Boulevard.

]]>
1898603
Accellion Data Breach Highlights Third-Party Risk https://securityboulevard.com/2021/05/accellion-data-breach-highlights-third-party-risk/ Tue, 18 May 2021 08:00:51 +0000 https://securityboulevard.com/?p=1877231 supply chain GrammaTech third-party Hamas

Two mega-breaches caused by third parties earlier this year, following the SolarWinds supply chain hack created a growing tsunami of third-party risk for enterprises and government organizations. Security software provider Accellion also suffered a breach in their FTA tool which caused many of their clients to have their data exposed to hackers. A number of..

The post Accellion Data Breach Highlights Third-Party Risk appeared first on Security Boulevard.

]]>
1877231
Over 2K Publicly Accessible Etcd Servers Leak Sensitive Credentials https://securityboulevard.com/2018/03/over-2k-publicly-accessible-etcd-servers-leak-sensitive-credentials/ https://securityboulevard.com/2018/03/over-2k-publicly-accessible-etcd-servers-leak-sensitive-credentials/#comments Fri, 23 Mar 2018 11:37:09 +0000 https://securityboulevard.com/?p=1765137

After publicly exposed MongoDB databases, Amazon AWS S3 buckets and Redis instances, researchers now warn that a considerable number of etcd servers are also publicly accessible and contain sensitive credentials that could provide access to additional systems. The warning came late last week from security researcher Giovanni Collazo, who found 2,284 etcd servers reachable from..

The post Over 2K Publicly Accessible Etcd Servers Leak Sensitive Credentials appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2018/03/over-2k-publicly-accessible-etcd-servers-leak-sensitive-credentials/feed/ 1 1765137