Get a Pentest and security assessment of your IT network.

News

Attackers Aim at Software Supply Chain with Package Typosquatting

Researchers analyzed the package repository for the Ruby language looking for code packages. They found more than 760 malicious Gems with similar names to legitimate packages had polluted the Ruby Gems repository. The attack is similar to the typosquatting the company found in Python and the Node Package Manager repositories. The common attack typically focuses on creating file or domain names that are similar to common runtimes or destinations, respectively, in an attempt to catch infrequent typos. In the early 2000s, domain registrars began redirecting mistyped domains to their own landing pages.”]

Source: https://www.darkreading.com/application-security/attackers-aim-at-software-supply-chain-with-package-typosquatting

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin