home.social

#supply-chain — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #supply-chain, aggregated by home.social.

fetched live
  1. This afternoon a couple of my CI/CD pipelines broke because a user deleted all their their public repositories from #Github .

    I suppose many people are starting to be fed up with all what's going on with big companies stealing our code to train their #LLMs, or maybe it's something else... who knows. It's not like we have a single reason to be discontent with Github / Microsoft.

    Anyway... I started reviewing all my projects to ensure that I mirror all my critical dependencies so I don't suffer the same problem again.

    #CICD #AI #GenerativeAI #SupplyChain

  2. 🖥️ 🇨🇳

    The AI boom’s tungsten problem

    "Two Japanese producers, Kanto Denka and Central Glass, made about a quarter of the world’s supply between them. Past tense. As of the first of July, they stopped. Not an accident on the factory floor – they ran out of the pure tungsten powder they need, the powder comes from China, and China stopped letting it leave the country in 2025."

    🔗 almonty.com/the-ai-booms-tungs

    #AI #Artificialintelligence #Technology #Tech #China #Trade #Business #SupplyChain

  3. AI Coding Tools Exacerbate Open-Source Remediation Debt

    AI coding tools are speeding up development, but at a hidden cost: they can quickly introduce a flood of new open-source components that security teams struggle to keep up with, multiplying remediation debt. This creates a downstream cycle of vulnerability assessments, licensing checks, and ownership questions that can…

    osintsights.com/ai-coding-tool

    #AiCodingTools #OpensourceSecurity #SoftwareDevelopment #SupplyChain #VulnerabilityManagement

  4. xpl0itrs colpisce il Gruppo Spaggiari: 6,1 TB rivendicati da 3.000 scuole italiane, l’azienda ridimensiona

    Il gruppo di cybercrime xpl0itrs rivendica l'esfiltrazione di 6,1 terabyte di dati dall'infrastruttura di Spaggiari, storico fornitore del registro elettronico ClasseViva usato da 4,5 milioni di utenti al giorno. L'azienda ridimensiona l'incidente a un solo modulo, ma il profilo del gruppo — già dietro rivendicazioni contro Spotify, Treasury e OpenAI — invita alla cautela.

    insicurezzadigitale.com/xpl0it

  5. Thousands of Leaked AWS Keys Remain Active

    A recent scan by Truffle Security uncovered a staggering 9,300+ active AWS keys that were leaked online, including hundreds with full administrative rights, putting sensitive data at risk. These compromised keys were found across various public platforms, with a shocking 88% still authentic and vulnerable to exploitation.

    osintsights.com/thousands-of-l

    #CloudSecurity #Aws #LeakedCredentials #SupplyChain #EmergingThreats

  6. Memory constraints may force tradeoffs in system design. Vera Rubin configurations could see CPU capacity cut roughly in half due to memory availability, suggesting buyers may need to choose between capacity and cost. implicator.ai/nvidia-ai-server #ai #hardware #supplychain

  7. Mainland #Chinese #enterprises are increasingly adopting comprehensive #global #business #strategies, targeting both advanced #economies and #emerging #markets, according to new research from the #HongKong #Trade Development Council (HKTDC). The #survey highlights #HK’s pivotal role in helping these #China #firms navigate challenges such as shifting trade #policies, #protectionism, and #SupplyChain reconfigurations. cnbusinessforum.com/hong-kong-

  8. 🚨 about Studio Boldrin & Aurore Development: two #Qilin victims, one narrow geographic cluster

    Studio Boldrin operates in Bibione, while Aurore Development manages #hospitality properties across Cavallino-Treporti and Bibione. Both were recently listed by the Qilin #ransomware group.

    No direct technical or corporate link has been confirmed. However, the geographic proximity raises a legitimate question: coincidence, shared IT supplier, common remote-access infrastructure, or the same Qilin affiliate exploiting a local #supplychain?

    A leak-site listing alone cannot establish a shared campaign. Confirmation would require matching initial-access vectors, overlapping infrastructure, common MSP/RMM tooling, shared credentials, or cross-victim data found in the leaked material.

    For now, this is a correlation worth monitoring, not an attribution.

    #ransomNews

  9. Currently investigating a bug blocking the build of the Arch Linux code package for several releases now. The problem comes from a mismatch between open-vsx.org and an extension who updated a release artifact on GitHub after open-vsx.org picked it and made it available on their website.

    Developers from around the world, please, PLEASE use immutable releases on GitHub or anywhere else! The whole software ecosystem thanks you.

    #archlinux #supplychain #packaging

  10. Mainland #Chinese #enterprises are increasingly adopting comprehensive #global #business #strategies, targeting both advanced #economies and #emerging #markets, according to new research from the #HongKong #Trade Development Council (HKTDC). The #survey highlights #HK’s pivotal role in helping these #China #firms navigate challenges such as shifting trade #policies, #protectionism, and #SupplyChain reconfigurations. cnbusinessforum.com/hong-kong-

  11. Mozilla revoked an exposed GPG signing subkey and issued a replacement after the private key was accidentally committed to a GitHub repository. 🔐
    Mozilla found no evidence of unauthorized access, while users who manually verify signatures must import the new key and revoke the old one. 🦊

    @mozilla

    🔗 securityweek.com/mozilla-issue

    #TechNews #Firefox #Mozilla #GPG #SupplyChain #Cybersecurity #OpenSource #Security #Privacy #FOSS #Linux #Software #Technology

  12. Samsung now holds roughly 40% of the DRAM market in H1 2026 — a record high, up 5.4 points year over year, and its fastest-growing product line.

    What's driving it: AI data centers are pulling memory capacity toward HBM. With Micron and SK hynix shifting the same way, consumer DRAM and NAND stay tight and prices keep climbing.

    The squeeze is expected to run toward 2030.

    androidheadlines.com/2026/08/s

    #Samsung #DRAM #Memory #HBM #Semiconductors #SupplyChain

  13. Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns

    On August 20, 2026, malicious versions of three Rust crates were published to crates.io: [email protected], [email protected], and [email protected]. The malicious crates added a typosquatted dependency (proc-macro1) whose build script downloads and executes a remote binary at compile time. The payload is a featureful backdoor that beacons to C2 via HTTPS, exfiltrates host information, enumerates installed applications, reads browser profiles for saved logins, and persists via Registry Run key, LaunchAgent, or systemd user service. The campaign's infrastructure substantially overlaps with operations attributed to North Korean actors, including shared C2 endpoint patterns with the Mastra campaign and IP addresses used in the axios npm attack.

    Pulse ID: 6a8775e93b9ffe6d9c526c90
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #DPRK #Endpoint #HTTP #HTTPS #InfoSec #Korea #Mac #NPM #NorthKorea #OTX #OpenThreatExchange #RAT #Rust #SupplyChain #bot #iOS #AlienVault

  14. Popular Rust Crates Compromised in Build-Time Supply Chain Attack

    A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

    Pulse ID: 6a8775e8885af9073b89474a
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault

  15. Videosorveglianza: il 2026 sara’ l’anno dei rincari spinti dall’AI: Novaira Insights ha rilasciato il suo nuovo report sul mercato globale della videosorveglianza: ripresa nel 2025, segnali di stabilizzazione in Cina e un 2026 caratterizzato...
    #Videosorveglianza #AI #NovairaInsights #intelligenzaartificiale #supplychain dlvr.it/TV684x

  16. Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

    Indicators extracted from public reporting. Source: wiz.io/blog/rust-supply-chain-

    Pulse ID: 6a877807939f52dc55e5712e
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: CyberHunter_NL
    Created: 2026-08-20 21:56:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DPRK #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #Rust #SupplyChain #bot #CyberHunter_NL