mastodon.ie is one of the many independent Mastodon servers you can use to participate in the fediverse.
Irish Mastodon - run from Ireland, we welcome all who respect the community rules and members.

Administered by:

Server stats:

1.6K
active users

#supplychainattack

1 post1 participant0 posts today

⚠️ Linux wiper malware hidden in malicious Go modules on GitHub

「 The attack appears designed specifically for Linux-based servers and developer environments, as the destructive payload - a Bash script named done.sh, runs a ‘dd’ command for the file-wiping activity.

Furthermore, the payload verifies that it runs in a Linux environment (runtime.GOOS == "linux") before trying to execute 」

bleepingcomputer.com/news/secu

TIL Slopsquatting 🤖📦

Article très intéressant sur cette nouvelle technique de #typosquatting qui exploite les hallucinations récursives des LLM utilisés en programmation

Les LLM hallucinent des librairies/paquets imaginaires ➡️ des acteurs malveillants les enregistrent et les arment 🧨
Le tout sur fond de hype autour du "vibe coding"
⬇️
"The Rise of Slopsquatting: How AI Hallucinations Are Fueling a New Class of Supply Chain Attacks"
👇
socket.dev/blog/slopsquatting-

Via la toujours excellente Risky Bulletin Newsletter du jour
👇
risky.biz/risky-bulletin-ai-sl

SocketThe Rise of Slopsquatting: How AI Hallucinations Are Fueling...Slopsquatting is a new supply chain threat where AI-assisted code generators recommend hallucinated packages that attackers register and weaponize.

Microsoft warns that Chinese cyber-espionage threat group 'Silk Typhoon' has shifted its tactics, now targeting remote management tools and cloud services in supply chain attacks that give them access to downstream customers. #supplychainattack #CyberAlerts bleepingcomputer.com/news/secu

BleepingComputer · Silk Typhoon hackers now target IT supply chains to breach networksBy Bill Toulas