Source |
The Hacker News |
Identifiant |
4711793 |
Date de publication |
2022-05-20 02:41:05 (vue: 2022-05-20 11:07:13) |
Titre |
Researchers Uncover Rust Supply-Chain Attack Targeting Cloud CI Pipelines |
Texte |
A case of software supply chain attack has been observed in the Rust programming language's crate registry that leveraged typosquatting techniques to publish a rogue library containing malware.
Cybersecurity firm SentinelOne dubbed the attack "CrateDepression."
Typosquatting attacks take place when an adversary mimics the name of a popular package on a public registry in hopes that developers |
Notes |
|
Envoyé |
Oui |
Condensat |
adversary attack attacks take been case chain cloud containing cratedepression cybersecurity developers dubbed firm has hopes language leveraged library malware mimics name observed package pipelines place when popular programming public publish registry registry that researchers rogue rust sentinelone software supply s crate targeting techniques typosquatting uncover |
Tags |
|
Stories |
|
Move |
|