The proliferation of supply chain attacks and assaults on open-source software parallels an epidemic, with prominent instances like Dependency Confusion, log4j, NPM, and Gem attacks. This session will dissect the What, Why, and How of these attacks, emphasizing their profound impact as potential weak links in the chain, and providing strategic prevention measures. Additionally, we’ll delve into extensive internet scanning of NPM packages to identify vulnerabilities susceptible to account takeover, and discuss strategies for both impact mitigation and defense.
#SAS2023 #SupplyChainAttacks #Kaspersky