#supply-chain — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #supply-chain, aggregated by home.social.
-
Currently investigating a bug blocking the build of the Arch Linux code package for several releases now. The problem comes from a mismatch between open-vsx.org and an extension who updated a release artifact on GitHub after open-vsx.org picked it and made it available on their website.
Developers from around the world, please, PLEASE use immutable releases on GitHub or anywhere else! The whole software ecosystem thanks you.
-
Iran Reports Doubling Defense Output
#Taco #Nacho #News #Politics #Nato #War #ww3 #Military #Russia #USA #Escalation #Europe #EU #Oil #UN #China #Iran #Pentagon #Yemen #Iraq #Asia #Security #Incompetence #SupplyChain
https://en.mehrnews.com/news/247144/Iran-defence-output-doubled-in-a-year-Ministry-Spox
-
" There’s no shortcut to replenish US munitions stockpiles
Firms are pitching low-cost munitions and the Pentagon is making weapons deals. It won’t immediately fix the Iran stockpile problem, experts say."#Taco #Nacho #News #Politics #Nato #War #ww3 #Military #Russia #USA #Escalation #Europe #EU #Oil #UN #China #Iran #Pentagon #Yemen #Iraq #Asia #Security #Incompetence #SupplyChain
-
Mainland #Chinese #enterprises are increasingly adopting comprehensive #global #business #strategies, targeting both advanced #economies and #emerging #markets, according to new research from the #HongKong #Trade Development Council (HKTDC). The #survey highlights #HK’s pivotal role in helping these #China #firms navigate challenges such as shifting trade #policies, #protectionism, and #SupplyChain reconfigurations. https://cnbusinessforum.com/hong-kong-remains-top-services-hub-for-chinese-firms-expanding-overseas/
-
Mozilla revoked an exposed GPG signing subkey and issued a replacement after the private key was accidentally committed to a GitHub repository. 🔐
Mozilla found no evidence of unauthorized access, while users who manually verify signatures must import the new key and revoke the old one. 🦊🔗 https://www.securityweek.com/mozilla-issues-new-firefox-gpg-key-following-exposure/
#TechNews #Firefox #Mozilla #GPG #SupplyChain #Cybersecurity #OpenSource #Security #Privacy #FOSS #Linux #Software #Technology
-
Samsung now holds roughly 40% of the DRAM market in H1 2026 — a record high, up 5.4 points year over year, and its fastest-growing product line.
What's driving it: AI data centers are pulling memory capacity toward HBM. With Micron and SK hynix shifting the same way, consumer DRAM and NAND stay tight and prices keep climbing.
The squeeze is expected to run toward 2030.
-
Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
On August 20, 2026, malicious versions of three Rust crates were published to crates.io: [email protected], [email protected], and [email protected]. The malicious crates added a typosquatted dependency (proc-macro1) whose build script downloads and executes a remote binary at compile time. The payload is a featureful backdoor that beacons to C2 via HTTPS, exfiltrates host information, enumerates installed applications, reads browser profiles for saved logins, and persists via Registry Run key, LaunchAgent, or systemd user service. The campaign's infrastructure substantially overlaps with operations attributed to North Korean actors, including shared C2 endpoint patterns with the Mastra campaign and IP addresses used in the axios npm attack.
Pulse ID: 6a8775e93b9ffe6d9c526c90
Pulse Link: https://otx.alienvault.com/pulse/6a8775e93b9ffe6d9c526c90
Pulse Author: AlienVault
Created: 2026-08-20 21:47:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CyberSecurity #DPRK #Endpoint #HTTP #HTTPS #InfoSec #Korea #Mac #NPM #NorthKorea #OTX #OpenThreatExchange #RAT #Rust #SupplyChain #bot #iOS #AlienVault
-
When the shortage is the strategy
https://nooneshappy.com/article/when-the-shortage-is-the-strategy/
Comments: https://news.ycombinator.com/item?id=49391358
#HackerNews #shortages #strategy #innovation #business #insights #supplychain
-
[#TRADESHOW] #Fenestration #BAU #China 2026 will be held from October 28 to 30, 2026, at China #International #Exhibition #Center Shunyi Hall in #Beijing. As the #Asia-#Pacific’s premier #trade #expo for #windows, #doors, #facades, and #building envelope technologies, the #business #event serves as a major #B2B #platform for #innovation, #sourcing, and #industry exchange across the full fenestration #SupplyChain. https://cnbusinessforum.com/event/fenestration-bau-china-2026/
-
[#TRADESHOW] 2026 #China (#Guzhen) #International #Lighting #Fair will be held from October 22 to 25, 2026, at Guzhen #Convention and #Exhibition #Centre in #Zhongshan. As a leading lighting #trade #show in #China, the #business #event serves as a major #B2B #platform for lighting #products, #LED technologies, #smart #home solutions, and related #furnishings across the #global lighting #SupplyChain. https://cnbusinessforum.com/event/2026-china-guzhen-international-lighting-fair/
-
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...
Pulse ID: 6a8775e8885af9073b89474a
Pulse Link: https://otx.alienvault.com/pulse/6a8775e8885af9073b89474a
Pulse Author: AlienVault
Created: 2026-08-20 21:47:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault
-
Videosorveglianza: il 2026 sara’ l’anno dei rincari spinti dall’AI: Novaira Insights ha rilasciato il suo nuovo report sul mercato globale della videosorveglianza: ripresa nel 2025, segnali di stabilizzazione in Cina e un 2026 caratterizzato...
#Videosorveglianza #AI #NovairaInsights #intelligenzaartificiale #supplychain http://dlvr.it/TV684x -
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
Indicators extracted from public reporting. Source: https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns
Pulse ID: 6a877807939f52dc55e5712e
Pulse Link: https://otx.alienvault.com/pulse/6a877807939f52dc55e5712e
Pulse Author: CyberHunter_NL
Created: 2026-08-20 21:56:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DPRK #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #Rust #SupplyChain #bot #CyberHunter_NL
-
RE: https://fosstodon.org/@rust/117129454116706734
Check your local cache registry whether you haven’t been affected as well #rust #supplychain
-
New.
Socket: Popular Rust Crates Compromised in Build-Time Supply Chain Attack https://socket.dev/blog/popular-rust-crates-compromised @SocketSecurity #infosec #threatresearch #Rust #supplychain #cyberattack
-
If you are developing in #Rustlang then you should check this post: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
-
Mainland #Chinese #enterprises are increasingly adopting comprehensive #global #business #strategies, targeting both advanced #economies and #emerging #markets, according to new research from the #HongKong #Trade Development Council (HKTDC). The #survey highlights #HK’s pivotal role in helping these #China #firms navigate challenges such as shifting trade #policies, #protectionism, and #SupplyChain reconfigurations. https://cnbusinessforum.com/hong-kong-remains-top-services-hub-for-chinese-firms-expanding-overseas/
-
RE: https://hachyderm.io/@djc/117127279917454362
arrayref is a really popular Rust crate and it seems like the maintainer account has been compromised. The compromised version (arrayref 0.3.10) and its malicious dependency (proc-macro1) are removed from crates.io already.
@ifin advisory: https://discourse.ifin.network/t/rust-packages-compromised-in-typosquat-account-takeover-attack/765
Rust project blog post: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
StepSecurity writeup: https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack
Rustsec advisory-db entry: https://github.com/rustsec/advisory-db/issues/3161
-
Der slowakische Geheimdienst NBÚ hat in landesweit getesteten Verkehrs-Radarkameras russ. Komponenten und einen SMS-aktivierbaren Backdoor-Mechanismus gefunden. Die Geräte sind technisch fast identisch mit einem russischen Radarsystem und wurden über ein EU-gefördertes Projekt beschafft. Das Innenministerium hatte die Herkunft zunächst bestritten. Das zeigt, wie schwer Lieferkettentransparenz bei sicherheitsrelevanter Hardware in der Praxis durchzusetzen ist. #Cybersecurity #Supplychain #KRITIS
-
[#TRADESHOW] #Fenestration #BAU #China 2026 will be held from October 28 to 30, 2026, at China #International #Exhibition #Center Shunyi Hall in #Beijing. As the #Asia-#Pacific’s premier #trade #expo for #windows, #doors, #facades, and #building envelope technologies, the #business #event serves as a major #B2B #platform for #innovation, #sourcing, and #industry exchange across the full fenestration #SupplyChain. https://cnbusinessforum.com/event/fenestration-bau-china-2026/
-
[#TRADESHOW] 2026 #China (#Guzhen) #International #Lighting #Fair will be held from October 22 to 25, 2026, at Guzhen #Convention and #Exhibition #Centre in #Zhongshan. As a leading lighting #trade #show in #China, the #business #event serves as a major #B2B #platform for lighting #products, #LED technologies, #smart #home solutions, and related #furnishings across the #global lighting #SupplyChain. https://cnbusinessforum.com/event/2026-china-guzhen-international-lighting-fair/
-
The space industry’s next challenge: supply chain resilience