8484 подписчиков
50 видео
Demo: lottie-player Taken Over by Attackers
How Python Entry Points manipulate plugins - pytest
Using Python Entry Points to manipulate CLI commands
Command-Jacking: A supply chain attack technique that trojanizes all your CLI commmands
A New North Korean Group Emerges, Disrupting the Open Source Ecosystem
Simplicity of falling victim to a malicious package - Keylogger
November 2023 - Monthly Dive Into Software Supply Chain Security
Recent North Korea attacks on software supply chain
The GitHub Black Market: Gaming the Star Ranking Game
Surprise: When Dependabot Contributes Malicious Code
Users of Telegram, AWS, and Alibaba Cloud Targeted in Latest Supply Chain Attack
Your monthly dive into Software Supply Chain Security - August 2023
How 140k NuGet, NPM, and PyPi Packages Were Used to Spread Phishing Links
LofyGang - Connecting The Dots
LofyGang - Discord Malware