|
You are here |
staex.io | ||
| | | | |
www.evasec.io
|
|
| | | | | Multiple vulnerabilities affecting the CocoaPods ecosystem, have been discovered, posing a major risk of supply chain attacks. | |
| | | | |
adnanthekhan.com
|
|
| | | | | I successfully exploited a critical misconfiguration vulnerability in GitHub's actions/runner images repository. I gained control over build agents used by the repository, accessed secrets, and showed how an attacker could insert malicious code into the runner base images and carry out an attack which could have affected all GitHub customers using hosted runners. Following the... | |
| | | | |
www.haukeluebbers.de
|
|
| | | | | Motivation Since the summer of 2019 I have been looking into package dependency compromises, a subset of software supply chain attacks. Today a number of popular programming languages make heavy use of more or less centralized package repositories and come with tools that make it easy to rely on third-party packages, which often come with lots of dependencies of their own. But with each dependency the attack surface for package dependency compromises increases - and malicious actors have already used different vectors to inject their payloads into software applications. | |
| | | | |
socket.dev
|
|
| | | A supply chain attack has been detected in versions 1.95.6 and 1.95.7 of the popular @solana/web3.js library. | ||