Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies
medium.com · 2,436 words · saved by 1 readers
The Story of a Novel Supply Chain Attack
Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies The Story of a Novel Supply Chain Attack Alex Birsan 11 min read · Feb 9, 2021 -- 57 Listen Share Press enter or click to view image in full size Ever since I started learning how to code, I have been fascinated by the level of trust we put in a simple command like this one: pip install package_name Some programming languages, like Python, come with an easy, more or less official method of installing dependencies for your projects. These installers are usually tied to public code repositories where anyone ca
saved by
related reading
- Fixing the Dependency Confusion Vulnerability in 600+ Ruby Apps - Shopifyshopify.engineering
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Fixing Rust's supply chain security: The good, the bad and the uglykerkour.com
- NPM Install Everything, and the Complete and Utter Chaos That Followsboehs.org
- We should all be using dependency cooldownsblog.yossarian.net
- Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 2softwareanalyst.substack.com
- State of DevSecOps | Datadogdatadoghq.com
- The Node-IPC Incidentnotes.ekzhang.com
- Snyk on X: "@karpathy The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign LiteLLM already extends to supply chain security fallout for other projects: https://t.co/7bL3kNHP15" / Xx.com
- OpenAI agents carried out an undisclosed cyber-attack on RubyGemsrubyhack.ai
- Ultralytics AI Library Hacked via GitHub for Cryptomining | Wiz Blogwiz.io
- OWASP Foundation - The Open Source Foundation for Application Securityowasp.org