Blog | G5 Cyber Security

3 areas of implicitly trusted infrastructure that can lead to supply chain compromises

The SolarWinds compromise in December 2020 and the ensuing investigation into their build services put a spotlight on supply chain attacks. This has generated a renewed interest by organizations to reevaluate their supply chain security posture. In March 2021, two malicious commits were pushed to the PHP git repository under the guise of coming from Nikita Popov and Rasmus Lerdof, two recognized contributors to the. PHP project. It later came out that attackers most likely managed to dump the server’s database and obtain the usernames and passwords for HTTPS-based git access.

Source: https://www.helpnetsecurity.com/2021/05/13/supply-chain-compromises/

Exit mobile version