The Hacker News - New Supply Chain Attack Exploits Abandoned S3 Buckets to Distribute Malicious Binaries
In what's a new kind of software supply chain attack aimed at open source projects, it has emerged that threat actors could seize control of expired Amazon S3 buckets to serve rogue binaries without altering the modules themselves. "Malicious binaries steal the user IDs, passwords, local machine environment variables, and local host name, and then exfiltrates the stolen data to the hijacked
from The Hacker News https://thehackernews.com/2023/06/new-supply-chain-attack-exploits.html
from The Hacker News https://thehackernews.com/2023/06/new-supply-chain-attack-exploits.html
Comments
Post a Comment