home.social

#supplychain — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #supplychain, aggregated by home.social.

fetched live
  1. Arch froze AUR after a 3rd malware wave (1,900+ pkgs). A GrapheneOS panic-password became a federal "destruction of evidence" charge. AI mines the commons free; builders ship open AMD firmware, GOG on Linux, a Rust X server, 68 patches. Under siege. Analysis: https://hilariouschaos.com/post/12587898

    ── Watch the video ──
    🎬 Odysee: https://odysee.com/open-source-under-siege-malware-waves-ai-slop-and-a-privacy-#e9f66ba0176d7c0760f8e0a635bd194f2783652c


    #linux #open-source #security #supply-chain #AI #surveillance #e9f66ba0176d7c0760f8e0a635bd194f2783652c
  2. Arch froze AUR after a 3rd malware wave (1,900+ pkgs). A GrapheneOS panic-password became a federal "destruction of evidence" charge. AI mines the commons free; builders ship open AMD firmware, GOG on Linux, a Rust X server, 68 patches. Under siege. Analysis: https://hilariouschaos.com/post/12587898

    ── Watch the video ──
    🎬 Odysee: https://odysee.com/open-source-under-siege-malware-waves-ai-slop-and-a-privacy-#e9f66ba0176d7c0760f8e0a635bd194f2783652c


    #linux #open-source #security #supply-chain #AI #surveillance #e9f66ba0176d7c0760f8e0a635bd194f2783652c
  3. 🛡️ Weekly CVE Roundup: July 26, 2026. This week we are tackling a critical RCE in auth-gate-middleware (CVE-2026-44021). We also explore why header-based authentication bypasses remain a persistent threat in modern cloud-native environments. Stay ahead of the threats. Full analysis here: cvedatabase.com/blog/weekly-cv

  4. A Deep Dive Into the Latest XCSSET Version

    After months of dormancy, XCSSET malware version 40 emerged in April 2026 targeting macOS developers through supply chain attacks. The malware hides in Xcode projects of legitimate applications on GitHub, spreading through infected development environments. V40 features advanced detection evasion through polymorphic payload generation, fileless persistence, and in-memory execution while weakening security mechanisms. It introduces 17 distinct modules including a Chrome hijacking backdoor via Chrome DevTools Protocol and a Telegram trojanizer. The malware employs multi-layered encryption, disables system security updates, terminates cloud telemetry, and locks XProtect signature databases. Primary targeting focuses on developers across South Asia. The infrastructure utilizes approximately 40 domains registered in Russia and India, demonstrating a geographic pivot in operations.

    Pulse ID: 6a7059ccae49a160e5763d1d
    Pulse Link: otx.alienvault.com/pulse/6a705
    Pulse Author: AlienVault
    Created: 2026-08-03 09:05:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Chrome #Cloud #CyberSecurity #Encryption #GitHub #India #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #Russia #SMS #SouthAsia #SupplyChain #Telegram #Trojan #bot #developers #AlienVault

  5. A Deep Dive Into the Latest XCSSET Version

    After months of dormancy, XCSSET malware version 40 emerged in April 2026 targeting macOS developers through supply chain attacks. The malware hides in Xcode projects of legitimate applications on GitHub, spreading through infected development environments. V40 features advanced detection evasion through polymorphic payload generation, fileless persistence, and in-memory execution while weakening security mechanisms. It introduces 17 distinct modules including a Chrome hijacking backdoor via Chrome DevTools Protocol and a Telegram trojanizer. The malware employs multi-layered encryption, disables system security updates, terminates cloud telemetry, and locks XProtect signature databases. Primary targeting focuses on developers across South Asia. The infrastructure utilizes approximately 40 domains registered in Russia and India, demonstrating a geographic pivot in operations.

    Pulse ID: 6a7059ccae49a160e5763d1d
    Pulse Link: otx.alienvault.com/pulse/6a705
    Pulse Author: AlienVault
    Created: 2026-08-03 09:05:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Chrome #Cloud #CyberSecurity #Encryption #GitHub #India #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #Russia #SMS #SouthAsia #SupplyChain #Telegram #Trojan #bot #developers #AlienVault

  6. Attacks on the software supply chain are increasing rapidly. We have therefore updated our guide on how to make your projects more secure, adding answers to the following questions:
    • How can you make your code more secure?
    • How can you ensure separation of concerns?
    • How can you continuously verify the security of your dependencies?
    • How do you create SBOMs?
    python4data.science/en/latest/
    #Python #SupplyChain #Vulnerability #SBOM

  7. Attacks on the software supply chain are increasing rapidly. We have therefore updated our guide on how to make your projects more secure, adding answers to the following questions:
    • How can you make your code more secure?
    • How can you ensure separation of concerns?
    • How can you continuously verify the security of your dependencies?
    • How do you create SBOMs?
    python4data.science/en/latest/
    #Python #SupplyChain #Vulnerability #SBOM

  8. Alluminio, la guerra in Iran non si vede più nei prezzi (ma si vede altrove)
    metallirari.com/alluminio-guer
    Il prezzo dell’alluminio sull’LME è tornato ai livelli pre-conflitto nonostante due milioni di tonnellate di produzione perse nel Golfo per la guerra in Iran. Cosa c’è dietro questa calma apparente?
    #Alluminio #LME #Iran #CommodityMarkets #Indonesia #Cina #CBAM #MetalliIndustriali #GeopoliticaEconomica #SupplyChain

  9. Arch froze AUR after a 3rd malware wave (1,900+ pkgs). A GrapheneOS panic-password became a federal "destruction of evidence" charge. AI mines the commons free; builders ship open AMD firmware, GOG on Linux, a Rust X server, 68 patches. Under siege. Analysis: https://hilariouschaos.com/post/12566907


    #linux #open-source #security #supply-chain #AI #surveillance
  10. Arch froze AUR after a 3rd malware wave (1,900+ pkgs). A GrapheneOS panic-password became a federal "destruction of evidence" charge. AI mines the commons free; builders ship open AMD firmware, GOG on Linux, a Rust X server, 68 patches. Under siege. Analysis: https://hilariouschaos.com/post/12566907


    #linux #open-source #security #supply-chain #AI #surveillance
  11. RE: ec.social-network.europa.eu/@E

    ... but what we really want is to know what #software products have been developed with #AI, and if the #supplychain for any service we use is reliant on it - since both those facts all but guarantees the product is crap, already or soon.

  12. RE: ec.social-network.europa.eu/@E

    ... but what we really want is to know what #software products have been developed with #AI, and if the #supplychain for any service we use is reliant on it - since both those facts all but guarantees the product is crap, already or soon.

  13. Pain or gain? US moves to decouple its defence industry from China’s rare earths

    A recent US executive order requires major arms manufacturers to trace their multi-tier supply chains and actively phase…
    #NewsBeep #News #Business #Beijing #CA #Canada #China #DonaldTrump #executiveorder #gallium #Germanium #Irán #NorthKorea #Pentagon #rareearths #Russia #supplychain #UnitedStates #us #washington
    newsbeep.com/ca/841340/

  14. Security Tip: Verify dependency integrity. 🛡️ Pinning versions is great, but integrity hashes (like those in package-lock.json or go.sum) are your defense against tampered packages. If a mirror is compromised, a checksum mismatch is your first warning sign. Always enforce integrity checks in your build pipeline to protect your supply chain.

    Stay ahead of emerging threats: cvedatabase.com

  15. The Arch Linux AUR is back in lockdown after another attack vector targeting its community-maintained packages.

    AUR's trust model — open contributions, voluntary review — is both its strength and its persistent challenge. No single patch fixes a social supply chain problem.

    #infosec #supplychain #linux
    fossforce.com/2026/07/new-atta

  16. The Arch Linux AUR is back in lockdown after another attack vector targeting its community-maintained packages.

    AUR's trust model — open contributions, voluntary review — is both its strength and its persistent challenge. No single patch fixes a social supply chain problem.

    #infosec #supplychain #linux
    fossforce.com/2026/07/new-atta

  17. 🛡️ Arch Linux dezactivează opțiunea de adoptare a pachetelor orfane din AUR pentru a opri preluările malițioase!

    Echipa de securitate Arch Linux a luat o măsură radicală pe platforma AUR (Arch User Repository): funcționalitatea prin care oricine putea deveni maintainer al unui pachet orfan (unmaintained) a fost temporar dezactivată.

    ✨ Ce s-a întâmplat și ce înseamnă această decizie:

    ⚠️ Preluări ostile de pachete (Malicious Takeovers):
    • Măsura vine în urma unor tentative recente în care atacatorii au preluat pachete abandonate de către creatorii lor originali și le-au injectat cod malițios înainte de a le republica.

    🔒 Protecția utilizatorilor pe primul loc:
    • Prin blocarea adoptării automate a pachetelor fără mentenor, echipa Arch previne atacurile de tip supply chain care vizau comunitatea ce instalează aplicații din AUR.

    ⚙️ Proces mai strict de verificare:
    • În loc ca adoptarea să se facă la un simplu click, schimbarea maintainerilor pentru pachetele orfane va necesita o revizuire manuală și aprobări din partea echipei AUR Trusted Users.

    🐧 Avertisment pentru utilizatori:
    • Rămâne un memento important de a verifica întotdeauna fișierele PKGBUILD înainte de a instala sau actualiza aplicații din AUR, mai ales când folosiți un AUR helper automat.

    O decizie fermă și necesară pentru menținerea securității în cadrul unuia dintre cele mai mari depozite de software comunitare! 🛡️

    #ArchLinux #AUR #CyberSecurity #Linux #OpenSource #SupplyChain #LinuxSecurity #TechNews #SoftwareLibre

  18. 🛡️ Arch Linux dezactivează opțiunea de adoptare a pachetelor orfane din AUR pentru a opri preluările malițioase!

    Echipa de securitate Arch Linux a luat o măsură radicală pe platforma AUR (Arch User Repository): funcționalitatea prin care oricine putea deveni maintainer al unui pachet orfan (unmaintained) a fost temporar dezactivată.

    ✨ Ce s-a întâmplat și ce înseamnă această decizie:

    ⚠️ Preluări ostile de pachete (Malicious Takeovers):
    • Măsura vine în urma unor tentative recente în care atacatorii au preluat pachete abandonate de către creatorii lor originali și le-au injectat cod malițios înainte de a le republica.

    🔒 Protecția utilizatorilor pe primul loc:
    • Prin blocarea adoptării automate a pachetelor fără mentenor, echipa Arch previne atacurile de tip supply chain care vizau comunitatea ce instalează aplicații din AUR.

    ⚙️ Proces mai strict de verificare:
    • În loc ca adoptarea să se facă la un simplu click, schimbarea maintainerilor pentru pachetele orfane va necesita o revizuire manuală și aprobări din partea echipei AUR Trusted Users.

    🐧 Avertisment pentru utilizatori:
    • Rămâne un memento important de a verifica întotdeauna fișierele PKGBUILD înainte de a instala sau actualiza aplicații din AUR, mai ales când folosiți un AUR helper automat.

    O decizie fermă și necesară pentru menținerea securității în cadrul unuia dintre cele mai mari depozite de software comunitare! 🛡️

    #ArchLinux #AUR #CyberSecurity #Linux #OpenSource #SupplyChain #LinuxSecurity #TechNews #SoftwareLibre

  19. A logistics company sells reliability, not persuasion. A shipment either arrives on time or it doesn't — and marketing hype doesn't fix a missed delivery. Here's what digital marketing for logistics and supply chain companies in Egypt actually needs to focus on: outsourcing-eg.com/digital-mar #LogisticsMarketing #SupplyChain #DigitalMarketing #Egypt #5DOutsourcing

    outsourcing-eg.com/digital-mar

  20. A logistics company sells reliability, not persuasion. A shipment either arrives on time or it doesn't — and marketing hype doesn't fix a missed delivery. Here's what digital marketing for logistics and supply chain companies in Egypt actually needs to focus on: outsourcing-eg.com/digital-mar #LogisticsMarketing #SupplyChain #DigitalMarketing #Egypt #5DOutsourcing

    outsourcing-eg.com/digital-mar

  21. Maersk changes Northern Star service after weather disruption

    Maersk said MAERSK NINGBO 626N/631S would omit Shanghai and induce Xiamen twice to reduce schedule delays after adverse weather.

    #EU #Denmark #Logistics #Shipping #SupplyChain #Operations

    maersk.com/news/articles/2026/

  22. Understanding Vendor Lock-In: Impacts, Examples, and Avoidance Strategies

    This article is intended to help readers better understanding vendor lock-in by identifying its impacts, examining examples, and highlighting avoidance strategies.

    After reading, you should:

    be familiar with the concept of vendor lock in
    be aware of potential impacts vendor lock-in can ...
    Continued 👉 blog.radwebhosting.com/underst #datagovernance #vendorlockin #supplychain #businesscontinuance #digitalsovereignty

  23. Understanding Vendor Lock-In: Impacts, Examples, and Avoidance Strategies

    This article is intended to help readers better understanding vendor lock-in by identifying its impacts, examining examples, and highlighting avoidance strategies.

    After reading, you should:

    be familiar with the concept of vendor lock in
    be aware of potential impacts vendor lock-in can ...
    Continued 👉 blog.radwebhosting.com/underst #datagovernance #vendorlockin #supplychain #businesscontinuance #digitalsovereignty