Tag: supply-chain
-
Apple CocoaPods Bugs Expose Millions of Apps to Code Injection
Critical dependency manager supply chain vulnerabilities have exposed millions and millions of devices to arbitrary malware for the better part of dec… First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/apple-cocoapods-bugs-expose-apps-code-injection
-
Millions of Apple Applications Were Vulnerable to CocoaPods Supply Chain Attack
First seen on techrepublic.com Jump to article: www.techrepublic.com/article/apple-applications-cocoapods-supply-chain-attack/
-
Practical Guidance For Securing Your Software Supply Chain
The heightened regulatory and legal pressure on software-producing organizations to secure their supply chains and ensure the integrity of their softw… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/practical-guidance-for-securing-your.html
-
Polyfill.io Supply Chain Attack: 384,773 hosts still embedding a polyfill JS script linking to the malicious domain
Cybersecurity company Censys has identified over 380,000 hosts that are still referencing the malicious polyfill.io domain. Censys reported that over … First seen on securityaffairs.com Jump to article: securityaffairs.com/165302/hacking/polyfill-io-supply-chain-attack.html
-
Almost Every Apple Device Vulnerable To CocoaPods Supply Chain Attack
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/36053/Almost-Every-Apple-Device-Vulnerable-To-CocoaPods-Supply-Chain-Attack.html
-
Over 110,000 Websites Affected by Hijacked Polyfill Supply Chain Attack
Google has taken steps to block ads for e-commerce sites that use the Polyfill.io service after a Chinese company acquired the domain and modified the… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/over-110000-websites-affected-by.html
-
Cybersecurity in der Lieferkette: Wie Sie Ihre SoftwareChain schützen
Software-Lieferketten stehen unter Druck: Eine Schwachstelle entlang der Lieferkette kann zu einer Vielzahl von Opfern führen. So können sich Unterneh… First seen on csoonline.com Jump to article: www.csoonline.com/de/a/wie-sie-ihre-software-supply-chain-schuetzen
-
Over 380,000+ Hosts Embedding Polyfill JS script Linking to Malicious Domain
Over 380,000 web hosts have been found embedding a compromised Polyfill.io JavaScript script, linking to a malicious domain. This supply chain attack … First seen on gbhackers.com Jump to article: gbhackers.com/hosts-embedding-polyfill-js/
-
‘Polyfill’ Supply Chain Threat: 4x Worse Than We Thought
First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/polyfill-supply-chain-richixb/
-
How AI could bolster software supply chain security
Supply chain risks have become more complicated and continue to affect a variety of organizations, but Synopsys’ Tim Mackey believes AI could help cre… First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366586557/How-AI-could-bolster-software-supply-chain-security
-
CocoaPods: Anfällig für Supply-Chain-Angriffe in zahllosen Mac- und iOS-Apps
Der Dependency-Manager auf Open-Source-Basis steckt in Millionen von Swift- und Objective-C-Programmen. Offenbar standen für fast ein Jahrzehnt die To… First seen on heise.de Jump to article: www.heise.de/news/CocoaPods-Anfaellig-fuer-Supply-Chain-Angriffe-in-zahllosen-Mac-und-iOS-Apps-9786099.html
-
Supply chain attack against iOS, macOS apps likely with severe CocoaPods bugs
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/supply-chain-attack-against-ios-macos-apps-likely-with-severe-cocoapods-bugs
-
Securing Supply Chains After Baltimore
In March, a container ship leaving the Helen Delich Bentley Port of Baltimore struck a support piling holding up the Francis Scott Key Bridge, knockin… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/securing-supply-chains-after-baltimore/
-
CVE of the month, the supply chain attack hidden for 10 years CVE-2024-38368
For over a decade, a massive vulnerability that could have unleashed a huge supply chain attack lay dormant. Luckily the good guys found it first or s… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/cve-of-the-month-the-supply-chain-attack-hidden-for-10-years-cve-2024-38368/
-
384,000 sites link to code library caught performing supply-chain attack
First seen on arstechnica.com Jump to article: arstechnica.com/
-
New body IMCSO to elevate standards and streamline provisioning of cybersecurity services in Maritime
The maritime industry is vitally important to the global supply chain for multiple reasons, from food, medicine and consumer goods to fuel and other i… First seen on itsecurityguru.org Jump to article: www.itsecurityguru.org/2024/06/21/new-body-imcso-to-elevate-standards-and-streamline-provisioning-of-cybersecurity-services-in-maritime
-
‘Perfect 10’ Apple Supply Chain Bug, Millions of Apps at Risk of CocoaPods RCE
First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/cocoapods-apple-vulns-richixbw/
-
Polyfill.io Supply Chain Attack Smacks Down 100K+ Websites
The site is supplying malicious code that delivers dynamically generated payloads and can lead to other attacks, after a Chinese organization bought i… First seen on darkreading.com Jump to article: www.darkreading.com/remote-workforce/polyfillio-supply-chain-attack-smacks-down-100k-websites
-
Building Resilience in the Chip Supply Chain
To bolster digital security and resilience across the semiconductor supply chain, a critical first step is that organizations across the supply chain … First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/building-resilience-in-the-chip-supply-chain/
-
WordPress Supply Chain Attack Spreads Across Multiple Plug-ins
First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/wordpress-supply-chain-attack-multiple-plug-ins
-
More than 100K sites impacted by Polyfill supply chain attack
First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/more-than-100k-sites-impacted-by-polyfill-supply-chain-attack/
-
Polyfill.io, BootCDN, Bootcss, Staticfile attack traced to 1 operator
The recent large scale supply chain attack conducted via multiple CDNs, namely Polyfill.io, BootCDN, Bootcss, and Staticfile that affected up to tens … First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/polyfillio-bootcdn-bootcss-staticfile-attack-traced-to-1-operator/
-
High-Risk Overflow Bug in Intel Chips Likely Impacts 100s of PC Models
The old, but newly disclosed, vulnerability is buried deep inside personal computers, servers, and mobile devices, and their supply chains, making rem… First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/high-risk-overflow-bug-in-intel-chips-likely-impacts-100s-of-pc-models
-
Polyfill.io JavaScript supply chain attack impacts over 100K sites
Over 100,000 sites have been impacted in a supply chain attack by the Polyfill.io service after a Chinese company acquired the domain and the script w… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/polyfillio-javascript-supply-chain-attack-impacts-over-100k-sites/
-
Plugins on WordPress.org backdoored in supply chain attack
A threat actor modified the source code of at least five plugins hosted on WordPress.org to include malicious PHP scripts that create new accounts wit… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/plugins-on-wordpressorg-backdoored-in-supply-chain-attack/
-
WordPress Plugin Supply Chain Attack Gets Worse
First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/wordpress-plugin-malware-richixbw/
-
B+ security rating masks healthcare supply chain risks
While the healthcare sector gets a B+ security rating for the first half of 2024, it faces a critical vulnerability: supply chain cyber risk, accordin… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/26/healthcare-security-ratings/
-
Polyfill Supply Chain Attack Hits Over 100k Websites
More than 100,000 websites are affected by a supply chain attack injecting malware via a Polyfill domain. The post n 100,000 websites are affected by … First seen on securityweek.com Jump to article: www.securityweek.com/polyfill-supply-chain-attack-hits-over-100k-websites/
-
Cloud and Other Supply Chain Security: What Questions to Ask
Supply chains tend to be incredibly complex. As a result, many organizations struggle with their supply chain risk assessments. Yet the risks in the s… First seen on itgovernanceusa.com Jump to article: www.itgovernanceusa.com/blog/securing-your-supply-chain-and-third-parties
-
Several Plugins Compromised in WordPress Supply Chain Attack
Five WordPress plugins were injected with malicious code that creates a new administrative account. The post dPress plugins were injected with malicio… First seen on securityweek.com Jump to article: www.securityweek.com/several-plugins-compromised-in-wordpress-supply-chain-attack/

