Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise (www.theregister.com)
from cm0002@lemmings.world to cybersecurity@infosec.pub on 11 Apr 21:48
https://lemmings.world/post/44113832

#cybersecurity

threaded - newest

14th_cylon@lemmy.zip on 11 Apr 22:06 next collapse

First, attackers hit Trivy, a vulnerability scanner with more than 100,000 users and contributors that is embedded in thousands of CI/CD pipelines. Up next: Axios, an open-source JavaScript library that has about 100 million weekly downloads and runs in 80 percent of cloud and code environments.

TacoButtPlug@sh.itjust.works on 11 Apr 23:04 collapse

i know the answer is to engineer differently but im down for smashing fingers with hammers