Get a Pentest and security assessment of your IT network.

News

Attackers Aim at Software Supply Chain with Package Typosquatting

Researchers analyzed the package repository for the Ruby language looking for code packages. They found more than 760 malicious Gems with similar names to legitimate packages had polluted the Ruby Gems repository. The attack is similar to the typosquatting the company found in Python and the Node Package Manager repositories. The common attack typically focuses on creating file or domain names that are similar to common runtimes or destinations, respectively, in an attempt to catch infrequent typos. In the early 2000s, domain registrars began redirecting mistyped domains to their own landing pages.”]

Source: https://www.darkreading.com/application-security/attackers-aim-at-software-supply-chain-with-package-typosquatting

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

RasGas, The Second Victim!

News

Technical analysis of the Locker virus on mobile phones