FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

Poisoned Python and PHP packages purloin passwords for AWS access

By Paul Ducklin β€” May 24th 2022 at 23:04
More supply chain trouble - this time with clear examples so you can learn how to spot this stuff yourself.

☐ β˜† βœ‡ Naked Security

RubyGems supply chain rip-and-replace bug fixed – check your logs!

By Paul Ducklin β€” May 9th 2022 at 15:41
Imagine if you could assume the identity of, say, Franklin Delano Roosevelt simply by showing up and calling yourself "Frank".

ruby-1200

☐ β˜† βœ‡ Naked Security

GitHub issues final report on supply-chain source code intrusions

By Paul Ducklin β€” April 29th 2022 at 16:15
Learn how to find out which apps you've given access rights to, and how to revoke those rights immediately in an emergency.

☐ β˜† βœ‡ Naked Security

Beanstalk cryptocurrency heist: scammer votes himself all the money

By Paul Ducklin β€” April 19th 2022 at 16:00
Voting safeguards based on commuity collateral don't work if one person can use a momentary loan to "become" 75% of the community.

☐ β˜† βœ‡ Naked Security

Wormhole cryptotrading company turns over $340,000,000 to criminals

By Paul Ducklin β€” February 4th 2022 at 17:38
It was the best of blockchains, it was the worst of blockchains... as Charles Dickens might have said.

☐ β˜† βœ‡ Naked Security

S3 Ep65: Supply chain conniption, NetUSB hole, Honda flashback, FTC muscle [Podcast + Transcript]

By Paul Ducklin β€” January 13th 2022 at 15:26
Latest episode -listen to it or read it now!

☐ β˜† βœ‡ Naked Security

JavaScript developer destroys own projects in supply chain β€œlesson”

By Paul Ducklin β€” January 11th 2022 at 00:54
Two popular open source JavaScript packages recently got "hacked" in a symbolic gesture by the original project creator.

☐ β˜† βœ‡ Naked Security

Listen up 2 – CYBERSECURITY FIRST! How to protect yourself from supply chain attacks

By Paul Ducklin β€” October 25th 2021 at 16:38
Everyone remembers this year's big-news supply chain attacks on Kaseya and SolarWinds. Sophos expert Chester Wisniewski explains how to control the risk.

❌