Hacking Humans
Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is Selena Larson [https://www.linkedin.com/in/selenalarson/], Proofpoint [https://www.proofpoint.com/] intelligence analyst and host of their podcast DISCARDED [https://www.proofpoint.com/us/podcasts/discarded]. Inspired by the residents of a building in New York’s exclusive upper west side, Selena is joined by her co-hosts N2K Networks [https://www.n2k.com/] Dave Bittner [https://www.linkedin.com/in/dave-bittner-27231a4/] and Keith Mularski [https://www.linkedin.com/in/keith-mularski-b737551/], former FBI cybercrime investigator and now Chief Global Ambassador at Qintel [https://www.linkedin.com/company/qintel/]. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, our hosts dive into the evolving threat of software supply chain attacks and the growing risks facing the open-source ecosystem. As developers increasingly rely on third-party packages and AI-powered coding tools, attackers are finding new ways to abuse trusted software to reach a wider range of targets. The discussion explores why these attacks are becoming more common, what recent incidents reveal about the state of software security, and what organizations can do to better protect themselves. Sources: [https://cyberscoop.com/supply-chain-attack-shai-hulud-npm/] Shai-Hulud worm returns stronger and more automated than ever before [https://cyberscoop.com/supply-chain-attack-shai-hulud-npm/] [https://cyberscoop.com/mini-shai-hulud-supply-chain-malware-attack/] ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack [https://cyberscoop.com/mini-shai-hulud-supply-chain-malware-attack/] [https://cms.thecyberwire.com/%C2%A0%E2%81%A0https://www.sans.org/blog/what-we-learned-axios-npm-supply-chain-compromise-emergency-briefing] What We Learned: Axios NPM Supply Chain Compromise Emergency Briefing [https://www.sans.org/blog/what-we-learned-axios-npm-supply-chain-compromise-emergency-briefing] Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise [https://www.trendmicro.com/en_us/research/26/c/inside-litellm-supply-chain-compromise.html]
785 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Hacking Humans!