/explore

Click through on any links that interest you or select the planets on the right to continue exploring the Outer Web.
You are here

staex.io
| | www.evasec.io
2.6 parsecs away

Travel
| | Multiple vulnerabilities affecting the CocoaPods ecosystem, have been discovered, posing a major risk of supply chain attacks.
| | adnanthekhan.com
4.4 parsecs away

Travel
| | I successfully exploited a critical misconfiguration vulnerability in GitHub's actions/runner images repository. I gained control over build agents used by the repository, accessed secrets, and showed how an attacker could insert malicious code into the runner base images and carry out an attack which could have affected all GitHub customers using hosted runners. Following the...
| | www.haukeluebbers.de
3.1 parsecs away

Travel
| | Motivation Since the summer of 2019 I have been looking into package dependency compromises, a subset of software supply chain attacks. Today a number of popular programming languages make heavy use of more or less centralized package repositories and come with tools that make it easy to rely on third-party packages, which often come with lots of dependencies of their own. But with each dependency the attack surface for package dependency compromises increases - and malicious actors have already used different vectors to inject their payloads into software applications.
| | socket.dev
9.7 parsecs away

Travel
| A supply chain attack has been detected in versions 1.95.6 and 1.95.7 of the popular @solana/web3.js library.