Destructive malware available in NPM repo went unnoticed for 2 years
https://arstechni.ca/xDjo #coderepositories #Security #malware #Biz&IT
#npm
Destructive malware available in NPM repo went unnoticed for 2 years
Payloads were set to spontaneously detonate on specific dates with no warning.
Ars Technica
Zapier says someone broke into its code repositories and may have accessed customer data
Zapier is notifying customers about a “security incident,” which involved an unauthorized user gaining access to the company’s code repositories and “certain custom information.”
The VergeOctopus Scanner Sinks Tentacles into GitHub Repositories
At least 26 different open-source code repositories were found to be infected with an unusual attack on the open-source software supply chain.
Threatpost - English - Global - threatpost.comHow to Get a Handle on Patch Management
As the number vulnerabilities hit a historic high, battle-worn security teams are upping their patching game.
Threatpost - English - Global - threatpost.com