Get a Pentest and security assessment of your IT network.

Cyber Security

Dependency Confusion Supply-Chain Attack Hit Over 35 High-Profile Companies

Microsoft, Apple, PayPal, Shopify, Netflix, Yelp, Tesla, Uber, and Uber all affected. Security researcher Alex Birsan has been collectively awarded over $130,000 in bug bounties for his efforts. The technique, called dependency confusion or a substitution attack, takes advantage of the fact that a piece of software may include components from a mix of private and public sources. Microsoft has released a new white paper on Tuesday outlining three ways to mitigating risks when using private package feeds.

Source: https://thehackernews.com/2021/02/dependency-confusion-supply-chain.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security