Source |
The Hacker News |
Identifiant |
3591934 |
Date de publication |
2021-11-01 04:25:57 (vue: 2021-11-01 12:06:22) |
Titre |
New \'Trojan Source\' Technique Lets Hackers Hide Vulnerabilities in Source Code |
Texte |
A novel class of vulnerabilities could be leveraged by threat actors to inject visually deceptive malware in a way that's semantically permissible but alters the logic defined by the source code, effectively opening the door to more first-party and supply chain risks.
Dubbed "Trojan Source attacks," the technique "exploits subtleties in text-encoding standards such as Unicode to produce source |
Notes |
|
Envoyé |
Oui |
Condensat |
actors alters as unicode to attacks but chain class code could deceptive defined door dubbed effectively encoding exploits first hackers hide inject lets leveraged logic malware more new novel opening party permissible produce risks semantically source standards subtleties such supply technique text that threat trojan visually vulnerabilities way |
Tags |
Malware
Threat
|
Stories |
|
Move |
|