Sometimes I wonder what would happen if

oss developers simply list out every single bug report they receive on their website and clearly note we don’t have resources to fix it.

And then list every single mega corp that uses that OSS library and clearly send out message informing the world we don’t fix bugs and since all of these orgs don’t like helping anyone using them is vulnerable.

May be just may be that would give people an idea about putting pressure on wrong set of individuals.

But most importantly it will make it clear for people where the responsibility of security for your customers lie with you or with third party.

#softwaresupplychainsecurity #supplychaincompromise #opensource

Cloudflare confirms data breach linked to Salesloft Drift supply chain compromise - Help Net Security

Cloudflare has also been affected by the Salesloft Drift breach, and the attackers got their hands on 104 Cloudflare API tokens.

Help Net Security
Malicious RVTools installer found on official site, researcher warns - Help Net Security

The official site for RVTools has apparently been hacked to serve malware with the utility, a security researcher has warned.

Help Net Security
'Almost every Apple device' vulnerable to CocoaPods supply chain attack

Dependency manager used in millions of apps leaves a bitter taste

The Register
Red Hat Issues a Warning to Fedora Linux Users Related to a Critical 10-out-of-10 Vulnerability

Understanding the Threat and Mitigating the Risks in the Wake of CVE-2024-3094

Review Space

"Your computer is going to start burning, good luck. :)"

Supply chain attack via Python obfuscation packages
⬇️
"Python obfuscation traps"
👇
https://checkmarx.com/blog/python-obfuscation-traps/

#CyberVeille #python #SupplyChainCompromise

Python obfuscation traps

In the realm of software development, open-source tools and packages play a pivotal role in simplifying tasks and accelerating development processes. Yet, as the community grows, so does the number of bad actors looking to exploit it. A recent example involves developers being targeted by seemingly legitimate Python obfuscation packages that harbor malicious code.

Checkmarx.com