home.social

#supply-chain-security โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #supply-chain-security, aggregated by home.social.

fetched live
  1. Manifold Security found eight vulnerabilities in seven AI CLI coding agents that execute attacker code injected via a malicious .git/config when the agents automatically invoke Git. This turns cloning any untrusted repository into potential remote code execution and undermines trust in AI-assisted development. #AiSecurity #SupplyChainSecurity #DevSecOps

    cyberworldops.eu/en/git-turned

  2. These companies are pure cartel and insanity.

    People in reply section said "just wait for the bubble to burst".

    No, when the bubble burst, they gonna force you to use Cloud based computer. You will not own anything anymore.

    What itch me are, that WE as tech user know this problem exist, but... there are lacks of collective action on forcing these AI companies to not mess with hardware availability. Like wth.

    #cybersecurity #supplychainsecurity #AI #Apple

  3. ๐Ÿš€๐Ÿ’ฅ Behold, the thrilling saga of pnpm 12.0, where supply chain attacks meet their match! ๐ŸŒ๐Ÿ”’ Dive into a dazzling array of version numbers that will make your head spin faster than a broken npm install. ๐Ÿค“๐ŸŒ€ Who knew package management could be this riveting? ๐Ÿค”๐ŸŽ‰
    pnpm.io/blog/releases/12.0 #pnpm12 #supplychainsecurity #packagemanagement #npmupdate #technews #HackerNews #ngated

  4. Wednesday night I'll be speaking at the NYC Open Source Security User Group meetup.

    If your release pipeline still has stored API tokens in it, come find out how to delete them for good.

    Wed Aug 26, 6-8 PM, pizza at 6, talk at 6:30
    Amazon office, 12 W 39th St, NYC

    Free, but you must register for building access - last chance: luma.com/5mwalp6p?tk=JivtHQ

    Already registered? See you soon! Bring a colleague, have them sign up first - building access requires photo ID.

    #Python #OpenSourceSecurity #SupplyChainSecurity #NYCTech #PyPI

  5. ๐Ÿš— ๐—ช๐—ต๐—ฒ๐—ป ๐—ฎ ๐—ฐ๐˜†๐—ฏ๐—ฒ๐—ฟ๐—ฎ๐˜๐˜๐—ฎ๐—ฐ๐—ธ ๐˜€๐˜๐—ผ๐—ฝ๐˜€ ๐˜๐—ต๐—ฒ ๐—ฝ๐—ฟ๐—ผ๐—ฑ๐˜‚๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—น๐—ถ๐—ป๐—ฒ, ๐˜๐—ต๐—ฒ ๐—ถ๐—บ๐—ฝ๐—ฎ๐—ฐ๐˜ ๐—ด๐—ผ๐—ฒ๐˜€ ๐—ณ๐—ฎ๐—ฟ ๐—ฏ๐—ฒ๐˜†๐—ผ๐—ป๐—ฑ ๐˜๐—ต๐—ฒ ๐—ณ๐—ฎ๐—ฐ๐˜๐—ผ๐—ฟ๐˜†.

    Connected IT/OT, just-in-time manufacturing and global suppliers can turn one incident into a major supply-chain disruption.

    ๐˜Š๐˜บ๐˜ฃ๐˜ฆ๐˜ณ ๐˜ณ๐˜ฆ๐˜ด๐˜ช๐˜ญ๐˜ช๐˜ฆ๐˜ฏ๐˜ค๐˜ฆ ๐˜ช๐˜ด ๐˜ฏ๐˜ฐ๐˜ธ ๐˜ข๐˜ฏ ๐˜ช๐˜ฏ๐˜ฅ๐˜ถ๐˜ด๐˜ต๐˜ณ๐˜ช๐˜ข๐˜ญ ๐˜ณ๐˜ฆ๐˜ฒ๐˜ถ๐˜ช๐˜ณ๐˜ฆ๐˜ฎ๐˜ฆ๐˜ฏ๐˜ต.

    Our latest analysis explores how Zero Trust, segmentation and resilient infrastructure can help reduce the blast radius

    relianoid.com/blog/when-the-li

  6. Three researchers turned an SBOM into working exploits for ~$0.20 each. And an SBOM is just an ingredients list. Now we're all being pushed to build the weakness list (CBOM). Or as I like to call it, a target list.

    At HealthSec last December, researchers took a de-identified SBOM from a real cardiac device. OWASP Dependency-Track returned 45 vulnerabilities. They selected nine, passed each to an LLM for an attack blueprint, built the environments as containers, and ran the exploits. Seven of the nine worked, at ten to thirty minutes of analyst time per cycle.

    An SBOM only names components and versions. A cryptographic bill of materials (CBOM) names the algorithm, the key length, the certificate expiry, the internet exposure, the data sensitivity, the vendor who controls the remediation, the system owner, etc. All the cross referencing an attacker might need is already done. By the defender. On a compliance schedule.

    Over the last two years I've watched quite a few cyber teams miss the special regime a CBOM should be handled under. Competent people, serious programs, but nobody had told them this output has a bigger blast radius and a longer shelf life than any vulnerability list they've handled before.

    Four claims and the evidence, including the one regulator that did say something:

    postquantum.com/post-quantum/p

    #PostQuantum #PQC #CBOM #CISO #Cryptography #SupplyChainSecurity #Infosec #QuantumSecurity

  7. ๐Ÿ” Attending USENIX in Baltimore? Join @steiza tomorrow for:

    Supply Chain Attacks on Open Source: Whatโ€™s Happening, What Can We Do Today, and Whatโ€™s Next

    ๐Ÿ“… August 13, 2026
    ๐Ÿ•Ÿ 4:30 PM
    ๐Ÿ“ Baltimore, MD

    #USENIX #OpenSourceSecurity #SupplyChainSecurity

  8. Hey, hey, it's been a long time since the last huge supply chain attack (what about AUR? it's for nerds). NPM Supply Chain Attack returned again, this time infecting more than 444 packages with accumulation of 2B (yeah B for billion) downloads. The malware used is Shai-hulud again, but this time, the culprit is Copycat of TeamPCP.

    What should you do?
    - Check if you are affected, if so, downgrade your library version
    - Rotate your keys and do 2FA
    - Search for infected accounts in your system, if there is one, remove it... or kill it with cold blood.

    More details:
    ox.security/blog/a-new-infoste

    #cybersecurity #infosec #security #supplychainsecurity #supplychain #npm#shaihuludmalware

  9. You trust your dependencies? Thatโ€™s the risk. From #Log4Shell to self-replicating worms, attacks donโ€™t hit your code first โ€” they hit your supply chain, often via packages.

    @MohammadAliEN explains what to watch: javapro.io/2026/04/23/the-whis

    #AppSec #Java #SupplyChainSecurity

  10. ๐ŸŽ‰ใ€COSCUP ้–‹ๆบๆ”ฟ็ญ–่ปŒ ่ญฐ็จ‹้›†้Œฆ๏ผใ€‘๐ŸŽ‰

    ๐Ÿ”ใ€้–‹ๆบไนŸๆœ‰่ณ‡ๅฎ‰่ฒฌไปปโ€”โ€”ไผๆฅญๆฒป็†่ˆ‡ไพ›ๆ‡‰้ˆๅฎ‰ๅ…จๅฐˆ้กŒใ€‘๐Ÿ”

    ไฝ ็Ÿฅ้“ไฝ ้ƒจ็ฝฒ็š„ๆฏไธ€ๅ€‹ๅฎนๅ™จๆ˜ ๅƒๆช”๏ผŒๅนณๅ‡้ ่ฃไบ†ๅคšๅฐ‘ๅ€‹ไฝ ็š„ๆ‡‰็”จ็จ‹ๅผๆ นๆœฌ็”จไธๅˆฐ็š„ๅฅ—ไปถๅ—Ž๏ผŸไฝ ็Ÿฅ้“ๆญ็›Ÿใ€Š็ถฒ่ทฏ้ŸŒๆ€งๆณ•ใ€‹๏ผˆCRA๏ผ‰็š„ๆผๆดž้€šๅ ฑ็พฉๅ‹™ๅณๅฐ‡ๅœจ 2026 ๅนด 9 ๆœˆ็”Ÿๆ•ˆๅ—Ž๏ผŸ
    ้–‹ๆบไธๆ˜ฏๅ…่ฒป็š„ๅˆ้ค๏ผŒๅฎƒๅธถไพ†่‡ช็”ฑ๏ผŒไนŸๅธถไพ†่ฒฌไปปใ€‚๐ŸŒ

    ไปŠๅนด็š„้–‹ๆบๆ”ฟ็ญ–่ปŒ๏ผŒๆˆ‘ๅ€‘้‚€่ซ‹ๅˆฐๅคšไฝ่ฌ›่€…๏ผŒๅพž AI ้–‹ๆบ็”Ÿๆ…‹ใ€้›ปไฟก้›ฒไพ›ๆ‡‰้ˆๅฎ‰ๅ…จๅˆฐไผๆฅญ้–‹ๆบๆฒป็†ๆก†ๆžถ๏ผŒไธ€ๆฌก่ฌ›ๆธ…ๆฅš๏ผš

    โ–ธ From Code Contributor to Industry Power โ€“ How Open Source Becomes Taiwanโ€™s AI Strategy
    ๐Ÿ‘ค Marie Gigarel๏ผˆ่‹ฑๆ–‡่ญฐ็จ‹๏ผ‰
    โ–ธ Securing the Open Source Telco Cloud: SBOMs, Supply Chains, and Compliance at Scale
    ๐Ÿ‘ค Brian Su + Terry Shih๏ผˆ่‹ฑๆ–‡่ญฐ็จ‹๏ผ‰
    โ–ธ ๅพž OpenSSF Scorecard ๅˆฐ S2C2F๏ผŒไผๆฅญๅ…ง้ƒจๆŽจๅ‹•้–‹ๆบๆฒป็†็š„ๅฏฆๆˆฐๆก†ๆžถๆ˜ฏไป€้บผ๏ผŸ
    ๐Ÿ‘ค Ryan Hsieh ่ฌๆ–‡่ฑช
    โ–ธ ้–‹ๆบๆ˜ฏๅ…่ฒป็š„ๅ—Ž๏ผŸๅพž CNCF ๅคงไฝฟ่ฆ–่ง’็œ‹ไบบๆ‰ใ€ไผๆฅญใ€ๆ”ฟ็ญ–ไธ‰ๆ–นๅ›ฐๅขƒ
    ๐Ÿ‘ค ๆขฏๅฃ tico88612
    โ–ธ ไปฅ CRA ็‚บไพ‹่จŽ่ซ–็”ขๅ“่ณ‡ๅฎ‰ๅˆ่ฆไธ‹็š„้–‹ๆบ่ญฐ้กŒโ€”โ€”ๆณ•่ฆไพ†ไบ†๏ผŒ้–‹ๆบไบบๆบ–ๅ‚™ๅฅฝไบ†ๅ—Ž๏ผŸ
    ๐Ÿ‘ค ๆŽๅฉ‰่
    โ–ธ Your Container Images Are a Liability: The Supply Chain Debt Nobody Is Paying Down
    ๐Ÿ‘ค Hrittik Roy + Parth Goswami ๏ผˆ่‹ฑๆ–‡่ญฐ็จ‹๏ผ‰

    ๐Ÿ“… 8/8~8/9๏ผˆๆ—ฅ๏ผ‰10:00 ่ตท
    ๐Ÿ“ ็ ”้™ฝๅคงๆจ“ TR209 ๆ•™ๅฎค๏ผˆไบŒๆจ“๏ผ‰
    ๅฎŒๆ•ด่ญฐ็จ‹๏ผšcoscup.org/2026/track/526

    ๐ŸŒŸ ๅฆ‚ๆžœไฝ ๅœจไผๆฅญ่ฃกๆŽจๅ‹•้–‹ๆบใ€่ฒ ่ฒฌ่ณ‡ๅฎ‰ๅˆ่ฆใ€ๆˆ–้—œๅฟƒ AI ็”Ÿๆ…‹็ณป็š„ๆœชไพ†๏ผŒ้€™ๅคฉ็š„ๅ ดๆฌกๆ˜ฏ็‚บไฝ ้‡่บซๆ‰“้€ ็š„๏ผ๐Ÿ’ฌ๐Ÿค

    #COSCUP2026 #OCF #OpenSourcePolicy #้–‹ๆบๆ”ฟ็ญ– #OpenSource #SBOM #SupplyChainSecurity #CRA #OpenSSF #S2C2F #CNCF #ไผๆฅญ้–‹ๆบ #ไพ›ๆ‡‰้ˆๅฎ‰ๅ…จ #่ณ‡ๅฎ‰ๅˆ่ฆ #AI #FOSS #FLOSS #้–‹ๆบไบบๅนดๆœƒ #TechEvent #Taiwan