home.social

#supply-chain — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #supply-chain, aggregated by home.social.

fetched live
  1. Currently investigating a bug blocking the build of the Arch Linux code package for several releases now. The problem comes from a mismatch between open-vsx.org and an extension who updated a release artifact on GitHub after open-vsx.org picked it and made it available on their website.

    Developers from around the world, please, PLEASE use immutable releases on GitHub or anywhere else! The whole software ecosystem thanks you.

    #archlinux #supplychain #packaging

  2. Mainland #Chinese #enterprises are increasingly adopting comprehensive #global #business #strategies, targeting both advanced #economies and #emerging #markets, according to new research from the #HongKong #Trade Development Council (HKTDC). The #survey highlights #HK’s pivotal role in helping these #China #firms navigate challenges such as shifting trade #policies, #protectionism, and #SupplyChain reconfigurations. cnbusinessforum.com/hong-kong-

  3. Mozilla revoked an exposed GPG signing subkey and issued a replacement after the private key was accidentally committed to a GitHub repository. 🔐
    Mozilla found no evidence of unauthorized access, while users who manually verify signatures must import the new key and revoke the old one. 🦊

    @mozilla

    🔗 securityweek.com/mozilla-issue

    #TechNews #Firefox #Mozilla #GPG #SupplyChain #Cybersecurity #OpenSource #Security #Privacy #FOSS #Linux #Software #Technology

  4. Samsung now holds roughly 40% of the DRAM market in H1 2026 — a record high, up 5.4 points year over year, and its fastest-growing product line.

    What's driving it: AI data centers are pulling memory capacity toward HBM. With Micron and SK hynix shifting the same way, consumer DRAM and NAND stay tight and prices keep climbing.

    The squeeze is expected to run toward 2030.

    androidheadlines.com/2026/08/s

    #Samsung #DRAM #Memory #HBM #Semiconductors #SupplyChain

  5. Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns

    On August 20, 2026, malicious versions of three Rust crates were published to crates.io: [email protected], [email protected], and [email protected]. The malicious crates added a typosquatted dependency (proc-macro1) whose build script downloads and executes a remote binary at compile time. The payload is a featureful backdoor that beacons to C2 via HTTPS, exfiltrates host information, enumerates installed applications, reads browser profiles for saved logins, and persists via Registry Run key, LaunchAgent, or systemd user service. The campaign's infrastructure substantially overlaps with operations attributed to North Korean actors, including shared C2 endpoint patterns with the Mastra campaign and IP addresses used in the axios npm attack.

    Pulse ID: 6a8775e93b9ffe6d9c526c90
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #DPRK #Endpoint #HTTP #HTTPS #InfoSec #Korea #Mac #NPM #NorthKorea #OTX #OpenThreatExchange #RAT #Rust #SupplyChain #bot #iOS #AlienVault

  6. Popular Rust Crates Compromised in Build-Time Supply Chain Attack

    A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

    Pulse ID: 6a8775e8885af9073b89474a
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault

  7. Videosorveglianza: il 2026 sara’ l’anno dei rincari spinti dall’AI: Novaira Insights ha rilasciato il suo nuovo report sul mercato globale della videosorveglianza: ripresa nel 2025, segnali di stabilizzazione in Cina e un 2026 caratterizzato...
    #Videosorveglianza #AI #NovairaInsights #intelligenzaartificiale #supplychain dlvr.it/TV684x

  8. Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

    Indicators extracted from public reporting. Source: wiz.io/blog/rust-supply-chain-

    Pulse ID: 6a877807939f52dc55e5712e
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: CyberHunter_NL
    Created: 2026-08-20 21:56:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DPRK #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #Rust #SupplyChain #bot #CyberHunter_NL

  9. Mainland #Chinese #enterprises are increasingly adopting comprehensive #global #business #strategies, targeting both advanced #economies and #emerging #markets, according to new research from the #HongKong #Trade Development Council (HKTDC). The #survey highlights #HK’s pivotal role in helping these #China #firms navigate challenges such as shifting trade #policies, #protectionism, and #SupplyChain reconfigurations. cnbusinessforum.com/hong-kong-

  10. RE: hachyderm.io/@djc/117127279917

    arrayref is a really popular Rust crate and it seems like the maintainer account has been compromised. The compromised version (arrayref 0.3.10) and its malicious dependency (proc-macro1) are removed from crates.io already.

    @ifin advisory: discourse.ifin.network/t/rust-

    Rust project blog post: blog.rust-lang.org/2026/08/20/

    StepSecurity writeup: stepsecurity.io/blog/arrayref-

    Rustsec advisory-db entry: github.com/rustsec/advisory-db

    #rustlang #rust #infosec #supplychain #malware

  11. Der slowakische Geheimdienst NBÚ hat in landesweit getesteten Verkehrs-Radarkameras russ. Komponenten und einen SMS-aktivierbaren Backdoor-Mechanismus gefunden. Die Geräte sind technisch fast identisch mit einem russischen Radarsystem und wurden über ein EU-gefördertes Projekt beschafft. Das Innenministerium hatte die Herkunft zunächst bestritten. Das zeigt, wie schwer Lieferkettentransparenz bei sicherheitsrelevanter Hardware in der Praxis durchzusetzen ist. #Cybersecurity #Supplychain #KRITIS