#supply-chain-security โ Public Fediverse posts
Live and recent posts from across the Fediverse tagged #supply-chain-security, aggregated by home.social.
-
Manifold Security found eight vulnerabilities in seven AI CLI coding agents that execute attacker code injected via a malicious .git/config when the agents automatically invoke Git. This turns cloning any untrusted repository into potential remote code execution and undermines trust in AI-assisted development. #AiSecurity #SupplyChainSecurity #DevSecOps
https://cyberworldops.eu/en/git-turned-into-a-trap-seven-ai-agents-can-execute-code-from
-
These companies are pure cartel and insanity.
People in reply section said "just wait for the bubble to burst".
No, when the bubble burst, they gonna force you to use Cloud based computer. You will not own anything anymore.
What itch me are, that WE as tech user know this problem exist, but... there are lacks of collective action on forcing these AI companies to not mess with hardware availability. Like wth.
-
๐๐ฅ Behold, the thrilling saga of pnpm 12.0, where supply chain attacks meet their match! ๐๐ Dive into a dazzling array of version numbers that will make your head spin faster than a broken npm install. ๐ค๐ Who knew package management could be this riveting? ๐ค๐
https://pnpm.io/blog/releases/12.0 #pnpm12 #supplychainsecurity #packagemanagement #npmupdate #technews #HackerNews #ngated -
Wednesday night I'll be speaking at the NYC Open Source Security User Group meetup.
If your release pipeline still has stored API tokens in it, come find out how to delete them for good.
Wed Aug 26, 6-8 PM, pizza at 6, talk at 6:30
Amazon office, 12 W 39th St, NYCFree, but you must register for building access - last chance: https://luma.com/5mwalp6p?tk=JivtHQ
Already registered? See you soon! Bring a colleague, have them sign up first - building access requires photo ID.
#Python #OpenSourceSecurity #SupplyChainSecurity #NYCTech #PyPI
-
๐ ๐ช๐ต๐ฒ๐ป ๐ฎ ๐ฐ๐๐ฏ๐ฒ๐ฟ๐ฎ๐๐๐ฎ๐ฐ๐ธ ๐๐๐ผ๐ฝ๐ ๐๐ต๐ฒ ๐ฝ๐ฟ๐ผ๐ฑ๐๐ฐ๐๐ถ๐ผ๐ป ๐น๐ถ๐ป๐ฒ, ๐๐ต๐ฒ ๐ถ๐บ๐ฝ๐ฎ๐ฐ๐ ๐ด๐ผ๐ฒ๐ ๐ณ๐ฎ๐ฟ ๐ฏ๐ฒ๐๐ผ๐ป๐ฑ ๐๐ต๐ฒ ๐ณ๐ฎ๐ฐ๐๐ผ๐ฟ๐.
Connected IT/OT, just-in-time manufacturing and global suppliers can turn one incident into a major supply-chain disruption.
๐๐บ๐ฃ๐ฆ๐ณ ๐ณ๐ฆ๐ด๐ช๐ญ๐ช๐ฆ๐ฏ๐ค๐ฆ ๐ช๐ด ๐ฏ๐ฐ๐ธ ๐ข๐ฏ ๐ช๐ฏ๐ฅ๐ถ๐ด๐ต๐ณ๐ช๐ข๐ญ ๐ณ๐ฆ๐ฒ๐ถ๐ช๐ณ๐ฆ๐ฎ๐ฆ๐ฏ๐ต.
Our latest analysis explores how Zero Trust, segmentation and resilient infrastructure can help reduce the blast radius
#Cybersecurity #CyberResilience #Automotive #OTSecurity #SupplyChainSecurity
-
Three researchers turned an SBOM into working exploits for ~$0.20 each. And an SBOM is just an ingredients list. Now we're all being pushed to build the weakness list (CBOM). Or as I like to call it, a target list.
At HealthSec last December, researchers took a de-identified SBOM from a real cardiac device. OWASP Dependency-Track returned 45 vulnerabilities. They selected nine, passed each to an LLM for an attack blueprint, built the environments as containers, and ran the exploits. Seven of the nine worked, at ten to thirty minutes of analyst time per cycle.
An SBOM only names components and versions. A cryptographic bill of materials (CBOM) names the algorithm, the key length, the certificate expiry, the internet exposure, the data sensitivity, the vendor who controls the remediation, the system owner, etc. All the cross referencing an attacker might need is already done. By the defender. On a compliance schedule.
Over the last two years I've watched quite a few cyber teams miss the special regime a CBOM should be handled under. Competent people, serious programs, but nobody had told them this output has a bigger blast radius and a longer shelf life than any vulnerability list they've handled before.
Four claims and the evidence, including the one regulator that did say something:
https://postquantum.com/post-quantum/protecting-the-cbom/
#PostQuantum #PQC #CBOM #CISO #Cryptography #SupplyChainSecurity #Infosec #QuantumSecurity
-
Supply Chain Security in the PHP Ecosystem
-
๐ Attending USENIX in Baltimore? Join @steiza tomorrow for:
Supply Chain Attacks on Open Source: Whatโs Happening, What Can We Do Today, and Whatโs Next
๐ August 13, 2026
๐ 4:30 PM
๐ Baltimore, MD -
Hey, hey, it's been a long time since the last huge supply chain attack (what about AUR? it's for nerds). NPM Supply Chain Attack returned again, this time infecting more than 444 packages with accumulation of 2B (yeah B for billion) downloads. The malware used is Shai-hulud again, but this time, the culprit is Copycat of TeamPCP.
What should you do?
- Check if you are affected, if so, downgrade your library version
- Rotate your keys and do 2FA
- Search for infected accounts in your system, if there is one, remove it... or kill it with cold blood.More details:
https://www.ox.security/blog/a-new-infostealer-worm-hits-npm-affecting-keyv-and-cacheable/#cybersecurity #infosec #security #supplychainsecurity #supplychain #npm#shaihuludmalware
-
via @dotnet : Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime
https://ift.tt/3IOsjnU
#NuGet #NuGetTrustedPublishing #APITokenSecurity #APIAccessSecurity #APIKeyRotation #OpenIDConnect #OIDC #SecurityNews #SupplyChainSecurity #DevOps #CI/CDSeโฆ -
You trust your dependencies? Thatโs the risk. From #Log4Shell to self-replicating worms, attacks donโt hit your code first โ they hit your supply chain, often via packages.
@MohammadAliEN explains what to watch: https://javapro.io/2026/04/23/the-whispering-jar-java-security-lessons-hidden-in-a-fantasy-tale/
-
๐ใCOSCUP ้ๆบๆฟ็ญ่ป ่ญฐ็จ้้ฆ๏ผใ๐
๐ใ้ๆบไนๆ่ณๅฎ่ฒฌไปปโโไผๆฅญๆฒป็่ไพๆ้ๅฎๅ จๅฐ้กใ๐
ไฝ ็ฅ้ไฝ ้จ็ฝฒ็ๆฏไธๅๅฎนๅจๆ ๅๆช๏ผๅนณๅ้ ่ฃไบๅคๅฐๅไฝ ็ๆ็จ็จๅผๆ นๆฌ็จไธๅฐ็ๅฅไปถๅ๏ผไฝ ็ฅ้ๆญ็ใ็ถฒ่ทฏ้ๆงๆณใ๏ผCRA๏ผ็ๆผๆด้ๅ ฑ็พฉๅๅณๅฐๅจ 2026 ๅนด 9 ๆ็ๆๅ๏ผ
้ๆบไธๆฏๅ ่ฒป็ๅ้ค๏ผๅฎๅธถไพ่ช็ฑ๏ผไนๅธถไพ่ฒฌไปปใ๐ไปๅนด็้ๆบๆฟ็ญ่ป๏ผๆๅ้่ซๅฐๅคไฝ่ฌ่ ๏ผๅพ AI ้ๆบ็ๆ ใ้ปไฟก้ฒไพๆ้ๅฎๅ จๅฐไผๆฅญ้ๆบๆฒป็ๆกๆถ๏ผไธๆฌก่ฌๆธ ๆฅ๏ผ
โธ From Code Contributor to Industry Power โ How Open Source Becomes Taiwanโs AI Strategy
๐ค Marie Gigarel๏ผ่ฑๆ่ญฐ็จ๏ผ
โธ Securing the Open Source Telco Cloud: SBOMs, Supply Chains, and Compliance at Scale
๐ค Brian Su + Terry Shih๏ผ่ฑๆ่ญฐ็จ๏ผ
โธ ๅพ OpenSSF Scorecard ๅฐ S2C2F๏ผไผๆฅญๅ ง้จๆจๅ้ๆบๆฒป็็ๅฏฆๆฐๆกๆถๆฏไป้บผ๏ผ
๐ค Ryan Hsieh ่ฌๆ่ฑช
โธ ้ๆบๆฏๅ ่ฒป็ๅ๏ผๅพ CNCF ๅคงไฝฟ่ฆ่ง็ไบบๆใไผๆฅญใๆฟ็ญไธๆนๅฐๅข
๐ค ๆขฏๅฃ tico88612
โธ ไปฅ CRA ็บไพ่จ่ซ็ขๅ่ณๅฎๅ่ฆไธ็้ๆบ่ญฐ้กโโๆณ่ฆไพไบ๏ผ้ๆบไบบๆบๅๅฅฝไบๅ๏ผ
๐ค ๆๅฉ่
โธ Your Container Images Are a Liability: The Supply Chain Debt Nobody Is Paying Down
๐ค Hrittik Roy + Parth Goswami ๏ผ่ฑๆ่ญฐ็จ๏ผ๐ 8/8~8/9๏ผๆฅ๏ผ10:00 ่ตท
๐ ็ ้ฝๅคงๆจ TR209 ๆๅฎค๏ผไบๆจ๏ผ
ๅฎๆด่ญฐ็จ๏ผhttps://coscup.org/2026/track/526๐ ๅฆๆไฝ ๅจไผๆฅญ่ฃกๆจๅ้ๆบใ่ฒ ่ฒฌ่ณๅฎๅ่ฆใๆ้ๅฟ AI ็ๆ ็ณป็ๆชไพ๏ผ้ๅคฉ็ๅ ดๆฌกๆฏ็บไฝ ้่บซๆ้ ็๏ผ๐ฌ๐ค
#COSCUP2026 #OCF #OpenSourcePolicy #้ๆบๆฟ็ญ #OpenSource #SBOM #SupplyChainSecurity #CRA #OpenSSF #S2C2F #CNCF #ไผๆฅญ้ๆบ #ไพๆ้ๅฎๅ จ #่ณๅฎๅ่ฆ #AI #FOSS #FLOSS #้ๆบไบบๅนดๆ #TechEvent #Taiwan
-
@hacksilon PS. I like to add more hashtags to make it easier for people to find your post about malicious adform package.
#supplychain #supplychainsecurity #supplychainattack #npm #npmsecurity #ioc