home.social

#supplychainattacks — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #supplychainattacks, aggregated by home.social.

fetched live
  1. VentureBeat: Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools. “Slopsquatting is a new type of supply chain attack that uses large language model (LLM) hallucinations to inject malicious code into development workflows. The term combines ‘AI slop’ and ‘typosquatting,’ a deceptive practice where attackers register misspelled or lookalike versions […]

    https://rbfirehose.com/2026/07/18/venturebeat-forget-typosquatting-slopsquatting-is-the-software-supply-chain-threat-created-by-ai-coding-tools/
  2. VentureBeat: Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools. “Slopsquatting is a new type of supply chain attack that uses large language model (LLM) hallucinations to inject malicious code into development workflows. The term combines ‘AI slop’ and ‘typosquatting,’ a deceptive practice where attackers register misspelled or lookalike versions […]

    https://rbfirehose.com/2026/07/18/venturebeat-forget-typosquatting-slopsquatting-is-the-software-supply-chain-threat-created-by-ai-coding-tools/
  3. Oh, great! Ruby Bundler now comes with a "cooldown" feature, because who doesn't love waiting around for their gems to turn into fine wine before installing them? 🍷 Just what we needed—more "exciting" ways to fight those pesky supply chain attacks by doing absolutely nothing for a few days. 🙄👏
    blog.rubygems.org/2026/06/03/c #RubyBundler #CooldownFeature #SupplyChainAttacks #GemInstallation #DeveloperHumor #RubyCommunity #HackerNews #ngated

  4. Oh, great! Ruby Bundler now comes with a "cooldown" feature, because who doesn't love waiting around for their gems to turn into fine wine before installing them? 🍷 Just what we needed—more "exciting" ways to fight those pesky supply chain attacks by doing absolutely nothing for a few days. 🙄👏
    blog.rubygems.org/2026/06/03/c #RubyBundler #CooldownFeature #SupplyChainAttacks #GemInstallation #DeveloperHumor #RubyCommunity #HackerNews #ngated

  5. #Supplychainattacks targeting security and developer tools continue, with #SAP, #Intercom, and #lightning #npmpackages compromised. The attacks, attributed to TeamPCP, involve credential-stealing malware that self-propagates, encrypts stolen data, and exfiltrates it to a new GitHub repository. theregister.com/2026/04/30/sup #tech #media #news

  6. #Supplychainattacks targeting security and developer tools continue, with #SAP, #Intercom, and #lightning #npmpackages compromised. The attacks, attributed to TeamPCP, involve credential-stealing malware that self-propagates, encrypts stolen data, and exfiltrates it to a new GitHub repository. theregister.com/2026/04/30/sup #tech #media #news

  7. Malware Poisons Open Source Tools in Dual Supply Chain Attacks

    Imagine trusting a tool, only to have it secretly turned against you - that's what happened in March when two massive supply chain attacks infected popular open source tools with malware, putting tens of thousands of organizations at risk. The full extent of the damage may not be known for months, but one thing is…

    osintsights.com/malware-poison

    #SupplyChainAttacks #OpenSourceSecurity #MalwareOperations #EmergingThreats #NationState

  8. 🐱‍💻 Oh, Astral's here to save us all from the horrors of open source security, one blog post at a time. Because, clearly, a company that "builds tools" for "millions" will tame the wild world of supply chain attacks with just a sprinkle of their secret sauce. 🥄✨
    astral.sh/blog/open-source-sec #OpenSourceSecurity #AstralSupplyChain #CybersecurityBlog #SupplyChainAttacks #TechInnovation #HackerNews #ngated

  9. 🐱‍💻 Oh, Astral's here to save us all from the horrors of open source security, one blog post at a time. Because, clearly, a company that "builds tools" for "millions" will tame the wild world of supply chain attacks with just a sprinkle of their secret sauce. 🥄✨
    astral.sh/blog/open-source-sec #OpenSourceSecurity #AstralSupplyChain #CybersecurityBlog #SupplyChainAttacks #TechInnovation #HackerNews #ngated

  10. Es gibt beim Einsatz einer weitreichenden #HomeAutomation schwere nicht zu vernachlässigende #Sicherheitsrisiken, nicht
    nur durch Einsatz von #agenticAI.

    Der Ersteller dieses Threads hat völlig recht.

    Aber auch durch die vielen Integrationen und Plugins (z.T. auch externe über diverse Repos) ergibt sich ein erhebliches Verwundbarkeitspotential.

    community.simon42.com/t/warnun

    #InfoSec #SupplyChainAttacks

  11. Es gibt beim Einsatz einer weitreichenden #HomeAutomation schwere nicht zu vernachlässigende #Sicherheitsrisiken, nicht
    nur durch Einsatz von #agenticAI.

    Der Ersteller dieses Threads hat völlig recht.

    Aber auch durch die vielen Integrationen und Plugins (z.T. auch externe über diverse Repos) ergibt sich ein erhebliches Verwundbarkeitspotential.

    community.simon42.com/t/warnun

    #InfoSec #SupplyChainAttacks

  12. Template for AI startup:

    * pitch trivial features anyone with a brain can do and has in fact been doing just fine for decades now, thanks

    * requires giving them read/copy/exfiltrate rights to your critical PII, secrets, I.P. and source code (ideally also "security scan" the latter and "patch" commit to the latter) and/or full access to your Google accounts, AWS, etc -- but you can TOTALLY trust them, bro

    * have names of 1 to 4 young Russian/Chinese/Indian males associated with it in GitHub (assuming you can even find names). oh and Anthropic Claude as a "co-commiter" or LLM du jour. though they TOTALLY WROTE ALL OF IT THEMSELVES, BRO!

    good luck, kids

    #AI
    #LLM
    #Claude
    #supplychainattacks
    #cybersecurity

  13. So Senna just told me about the most recent attack on #NPM.

    I swear I wrote the above post independent of that! The problem ist just so pervasive that you keep running into it.

    #supplychainattacks

  14. So Senna just told me about the most recent attack on #NPM.

    I swear I wrote the above post independent of that! The problem ist just so pervasive that you keep running into it.

    #supplychainattacks

  15. A single weak link can bring down giants. Recent supply-chain attacks exploited trusted vendor vulnerabilities to compromise big names like Palo Alto, Google, and more. How deep does the security gap really run?

    thedefendopsdiaries.com/unders

    #supplychainattacks
    #cybersecurity
    #infosec
    #databreach
    #thirdpartysecurity

  16. Supply-chain attacks are a favourite in the toolbox of cyber warfare. The SolarWinds attack remains in the history books of cybersecurity for the clever use of patching as an attack vector to disrupt C2 infrastructure.

    Read how it unfolded in our deep dive article! 👇

    negativepid.blog/the-solarwind

    #cyberwarfare #supplychainattacks #patching #cozybear #orion #C2

  17. Are Web Components & Cybersecurity A Better Combo?

    I'm not trying to dunk on popular #UI #frameworks – I'm sure they're totally fine for #cybersecurity stuff, probably get loads of reviews and #audits.

    But from my angle: Web Components are *native* to the #browser. Doesn't that just inherently reduce the risk of **#SupplyChainAttacks** (you know, like a rogue `npm install` on a bad network) for your #AppSecurity?

    Or am I overthinking it, and the #framework choice is less important than the #browser, #OS, or #device running it? What are your thoughts, #DevCommunity?

    ---

    Quick context: I've got a #ReactJS #messagingApp (repo here: github.com/positive-intentions) and a separate #UIFramework (repo here: github.com/positive-intentions) built with #Lit (which uses Web Components). I'm genuinely wondering if there's a compelling #cybersecurity reason to refactor the chat app to use my #WebComponent UI framework. Might be a whole new level of #SecurityByDesign for #FrontEndDev.

    FYI, same question's on Reddit here: reddit.com/r/ExperiencedDevs/c, got some good #insights, but want to make sure nothing's getting overlooked! Let's discuss #InfoSec #WebDev #JavaScript #OpenSource #TechQuestion.

  18. Are Web Components & Cybersecurity A Better Combo?

    I'm not trying to dunk on popular #UI #frameworks – I'm sure they're totally fine for #cybersecurity stuff, probably get loads of reviews and #audits.

    But from my angle: Web Components are *native* to the #browser. Doesn't that just inherently reduce the risk of **#SupplyChainAttacks** (you know, like a rogue `npm install` on a bad network) for your #AppSecurity?

    Or am I overthinking it, and the #framework choice is less important than the #browser, #OS, or #device running it? What are your thoughts, #DevCommunity?

    ---

    Quick context: I've got a #ReactJS #messagingApp (repo here: github.com/positive-intentions) and a separate #UIFramework (repo here: github.com/positive-intentions) built with #Lit (which uses Web Components). I'm genuinely wondering if there's a compelling #cybersecurity reason to refactor the chat app to use my #WebComponent UI framework. Might be a whole new level of #SecurityByDesign for #FrontEndDev.

    FYI, same question's on Reddit here: reddit.com/r/ExperiencedDevs/c, got some good #insights, but want to make sure nothing's getting overlooked! Let's discuss #InfoSec #WebDev #JavaScript #OpenSource #TechQuestion.

  19. Supply-chain attacks are a favourite in the toolbox of cyber warfare. The SolarWinds attack remains in the history books of cybersecurity for the clever use of patching as an attack vector to disrupt C2 infrastructure.

    Read how it unfolded in our deep dive article! 👇

    negativepid.blog/the-solarwind

    #cyberwarfare #supplychainattacks #patching #cozybear #orion #C2

  20. What is a supply chain attack in crypto and how to prevent it? - Supply chain attacks in crypto exploit trusted depe... - cointelegraph.com/explained/wh #supplychainattacks

  21. What is a supply chain attack in crypto and how to prevent it? - Supply chain attacks in crypto exploit trusted depe... - cointelegraph.com/explained/wh #supplychainattacks

  22. Undocumented backdoor found in Bluetooth chip used by a billion devices

    > The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence.

    bleepingcomputer.com/news/secu

    #infosec #supplychainsecurity #supplychainattacks

  23. The Register: It’s only a matter of time before LLMs jump start supply-chain attacks. ” Now that criminals have realized there’s no need to train their own LLMs for any nefarious purposes – it’s much cheaper and easier to steal credentials and then jailbreak existing ones – the threat of a large-scale supply chain attack using generative AI becomes more real.”

    https://rbfirehose.com/2024/12/30/the-register-its-only-a-matter-of-time-before-llms-jump-start-supply-chain-attacks/