home.social

#easyjson — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #easyjson, aggregated by home.social.

  1. Contd. [en] Software Supply Chain or Software Politics

    2/2

    "Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...

    "#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."

    justsecurity.org/142183/hiding

    #supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia

  2. Contd. [en] Software Supply Chain or Software Politics

    2/2

    "Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...

    "#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."

    justsecurity.org/142183/hiding

    #supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia

  3. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  4. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  5. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  6. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  7. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  8. #easyjson: a Golang package created by a Russian company with sanctioned CEO is found to be widely used in Helm, Istio, Kubernetes, ArgoCD, Grafana, Sigstore and across many US Government, Fortune 500 organisations:
    👇
    huntedlabs.com/the-russian-ope

  9. #easyjson: a Golang package created by a Russian company with sanctioned CEO is found to be widely used in Helm, Istio, Kubernetes, ArgoCD, Grafana, Sigstore and across many US Government, Fortune 500 organisations:
    👇
    huntedlabs.com/the-russian-ope

  10. #easyjson: a Golang package created by a Russian company with sanctioned CEO is found to be widely used in Helm, Istio, Kubernetes, ArgoCD, Grafana, Sigstore and across many US Government, Fortune 500 organisations:
    👇
    huntedlabs.com/the-russian-ope

  11. #easyjson: a Golang package created by a Russian company with sanctioned CEO is found to be widely used in Helm, Istio, Kubernetes, ArgoCD, Grafana, Sigstore and across many US Government, Fortune 500 organisations:
    👇
    huntedlabs.com/the-russian-ope

  12. #easyjson: a Golang package created by a Russian company with sanctioned CEO is found to be widely used in Helm, Istio, Kubernetes, ArgoCD, Grafana, Sigstore and across many US Government, Fortune 500 organisations:
    👇
    huntedlabs.com/the-russian-ope

  13. Researchers warn that open-source Go serialization tool #easyjson, owned by Russia’s #VKGroup and used by the US #DoD and others, poses a serious national security risk. #CyberSecurity #OpenSource #InfoSec #NationalSecurity #TechNews #DataSecurity #SupplyChainSecurity

  14. Researchers warn that open-source Go serialization tool #easyjson, owned by Russia’s #VKGroup and used by the US #DoD and others, poses a serious national security risk. #CyberSecurity #OpenSource #InfoSec #NationalSecurity #TechNews #DataSecurity #SupplyChainSecurity

  15. Researchers warn that open-source Go serialization tool #easyjson, owned by Russia’s #VKGroup and used by the US #DoD and others, poses a serious national security risk. #CyberSecurity #OpenSource #InfoSec #NationalSecurity #TechNews #DataSecurity #SupplyChainSecurity

  16. Researchers warn that open-source Go serialization tool #easyjson, owned by Russia’s #VKGroup and used by the US #DoD and others, poses a serious national security risk. #CyberSecurity #OpenSource #InfoSec #NationalSecurity #TechNews #DataSecurity #SupplyChainSecurity

  17. #Security Researchers Warn a Widely Used #OpenSource Tool Poses a 'Persistent' #Risk to the US

    The open source software #easyjson is used by the US government and American companies. But its ties to Russia’s #VK , whose CEO has been #sanctioned , have researchers sounding the alarm.
    #russia

    wired.com/story/easyjson-open-

  18. #Security Researchers Warn a Widely Used #OpenSource Tool Poses a 'Persistent' #Risk to the US

    The open source software #easyjson is used by the US government and American companies. But its ties to Russia’s #VK , whose CEO has been #sanctioned , have researchers sounding the alarm.
    #russia

    wired.com/story/easyjson-open-

  19. #Security Researchers Warn a Widely Used #OpenSource Tool Poses a 'Persistent' #Risk to the US

    The open source software #easyjson is used by the US government and American companies. But its ties to Russia’s #VK , whose CEO has been #sanctioned , have researchers sounding the alarm.
    #russia

    wired.com/story/easyjson-open-

  20. Researchers Warn a Widely Used Tool Poses a 'Persistent' to the US

    The open source software is used by the US government and American companies. But its ties to Russia’s , whose CEO has been , have researchers sounding the alarm.

    wired.com/story/easyjson-open-

  21. #Security Researchers Warn a Widely Used #OpenSource Tool Poses a 'Persistent' #Risk to the US

    The open source software #easyjson is used by the US government and American companies. But its ties to Russia’s #VK , whose CEO has been #sanctioned , have researchers sounding the alarm.
    #russia

    wired.com/story/easyjson-open-

  22. The #OpenSource software #easyjson is used by the US government and American companies. But its ties to Russia’s VK, whose CEO has been sanctioned, have researchers sounding the alarm.

    🔗 wired.com/story/easyjson-open-