Source |
The Hacker News |
Identifiant |
2323934 |
Date de publication |
2021-02-10 04:57:14 (vue: 2021-02-10 13:05:36) |
Titre |
Dependency Confusion Supply-Chain Attack Hit Over 35 High-Profile Companies |
Texte |
In what's a novel supply chain attack, a security researcher managed to breach over 35 major companies' internal systems, including that of Microsoft, Apple, PayPal, Shopify, Netflix, Yelp, Tesla, and Uber, and achieve remote code execution.
The technique, called dependency confusion or a substitution attack, takes advantage of the fact that a piece of software may include components from a mix |
Notes |
|
Envoyé |
Oui |
Condensat |
achieve advantage apple attack breach called chain code companies components confusion dependency execution fact from high hit include including internal major managed may microsoft mix netflix novel over paypal piece profile remote researcher security shopify software substitution supply systems takes technique tesla uber what yelp |
Tags |
|
Stories |
Uber
|
Move |
|
Src |
Date (GMT) |
Titre |
Description |
Tags |
Stories |
Notes |
 |
2021-02-10 16:03:00 |
(Déjà vu) Researcher Hacks Apple and Microsoft (lien direct) |
Novel supply chain attack allows researcher to hack internal systems of major companies |
Hack
|
|
|