Over 35 Tech Companies Compromised in Novel Software Supply Chain Attackby@sonatype
453 reads

Over 35 Tech Companies Compromised in Novel Software Supply Chain Attack

tldt arrow
Read on Terminal Reader🖨️

Too Long; Didn't Read

Security researcher Alex Birsan breached systems of over 35 tech companies in what has been described as a novel software supply chain attack. The attack is of particular significance as unlike traditional typosquatting or brandjacking supply-chain attacks that Sonatype has talked about before, the targeted companies automatically received Birsan’s malicious packages without them making any spelling mistakes, or any social engineering involved. For demonstrating the seriousness of this type of attack, Birsan has been awarded upwards of $130,000 in bug bounties.

Companies Mentioned

Mention Thumbnail
Mention Thumbnail

Coin Mentioned

Mention Thumbnail
featured image - Over 35 Tech Companies Compromised in Novel Software Supply Chain Attack
sonatype HackerNoon profile picture

@sonatype

sonatype

react to story with heart
sonatype HackerNoon profile picture
by sonatype @sonatype.Find and fix critical security, performance, reliability, and style issues in developer code.
Visit Us

RELATED STORIES

L O A D I N G
. . . comments & more!
Hackernoon hq - po box 2206, edwards, colorado 81632, usa