home.social

#supplychaincompromise — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #supplychaincompromise, aggregated by home.social.

fetched live
  1. UK Water Utility Exposed: Hackers Hid Undetected for 20 Months

    In a shocking revelation, hackers secretly lurked on South Staffordshire Water's corporate network for 20 months, evading detection until a performance issue sparked an investigation in July 2022. The stealthy attackers gained unauthorized access via a September 2020 phishing attack, harvesting credentials and…

    osintsights.com/uk-water-utili

    #WaterUtilityHack #UndetectedThreats #RansomwareAttempt #PhishingAttack #SupplyChainCompromise

  2. A month-long breach saw DAEMON Tools' official installers distributing malware, signed with *their own* legitimate digital certificates. Kaspersky researchers uncovered this sophisticated supply chain compromise, which bypassed standard security checks and targeted high-value organizations in retail, government, and manufacturing for espionage. The attackers used multi-protocol C2…

    tpp.blog/192uc7c

    #cybersecurity #daemontools #supplychaincompromise

    🤖 This post was AI-generated.

  3. Sometimes I wonder what would happen if

    oss developers simply list out every single bug report they receive on their website and clearly note we don’t have resources to fix it.

    And then list every single mega corp that uses that OSS library and clearly send out message informing the world we don’t fix bugs and since all of these orgs don’t like helping anyone using them is vulnerable.

    May be just may be that would give people an idea about putting pressure on wrong set of individuals.

    But most importantly it will make it clear for people where the responsibility of security for your customers lie with you or with third party.

    #softwaresupplychainsecurity #supplychaincompromise #opensource

  4. Sometimes I wonder what would happen if

    oss developers simply list out every single bug report they receive on their website and clearly note we don’t have resources to fix it.

    And then list every single mega corp that uses that OSS library and clearly send out message informing the world we don’t fix bugs and since all of these orgs don’t like helping anyone using them is vulnerable.

    May be just may be that would give people an idea about putting pressure on wrong set of individuals.

    But most importantly it will make it clear for people where the responsibility of security for your customers lie with you or with third party.

    #softwaresupplychainsecurity #supplychaincompromise #opensource

  5. Sometimes I wonder what would happen if

    oss developers simply list out every single bug report they receive on their website and clearly note we don’t have resources to fix it.

    And then list every single mega corp that uses that OSS library and clearly send out message informing the world we don’t fix bugs and since all of these orgs don’t like helping anyone using them is vulnerable.

    May be just may be that would give people an idea about putting pressure on wrong set of individuals.

    But most importantly it will make it clear for people where the responsibility of security for your customers lie with you or with third party.

    #softwaresupplychainsecurity #supplychaincompromise #opensource

  6. Sometimes I wonder what would happen if

    oss developers simply list out every single bug report they receive on their website and clearly note we don’t have resources to fix it.

    And then list every single mega corp that uses that OSS library and clearly send out message informing the world we don’t fix bugs and since all of these orgs don’t like helping anyone using them is vulnerable.

    May be just may be that would give people an idea about putting pressure on wrong set of individuals.

    But most importantly it will make it clear for people where the responsibility of security for your customers lie with you or with third party.

    #softwaresupplychainsecurity #supplychaincompromise #opensource

  7. Sometimes I wonder what would happen if

    oss developers simply list out every single bug report they receive on their website and clearly note we don’t have resources to fix it.

    And then list every single mega corp that uses that OSS library and clearly send out message informing the world we don’t fix bugs and since all of these orgs don’t like helping anyone using them is vulnerable.

    May be just may be that would give people an idea about putting pressure on wrong set of individuals.

    But most importantly it will make it clear for people where the responsibility of security for your customers lie with you or with third party.

    #softwaresupplychainsecurity #supplychaincompromise #opensource