About This Hashtag
#supplychainsecurity
16 posts· Last used 13d
Hey, hey, it's been a long time since the last huge supply chain attack (what about AUR? it's for nerds). NPM Supply Chain Attack returned again, this time infecting more than 444 packages with accumulation of 2B (yeah B for billion) downloads. The malware used is Shai-hulud again, but this time, the culprit is Copycat of TeamPCP.
What should you do?
- Check if you are affected, if so, downgrade your library version
- Rotate your keys and do 2FA
- Search for infected accounts in your system, if there is one, remove it... or kill it with cold blood.
More details: https://www.ox.security/blog/a-new-infostealer-worm-hits-npm-affecting-keyv-and-cacheable/
#cybersecurity #infosec #security #supplychainsecurity #supplychain #npm#shaihuludmalware
🚨 BREAKING: Ernst & Young (EY) has disclosed a data breach after attackers compromised a third-party IT support platform, exposing sensitive client tax information and financial documents.
Attackers reportedly accessed the platform between March 28 and April 12, downloading tax-related files before the intrusion was detected.
EY says there's no evidence of misuse so far, but affected clients are being offered 24 months of identity monitoring.
Read the full breakdown 👇 🔗 https://thecybersecguru.com/news/ey-data-breach-client-tax-information-third-party-hack/
#EY #DataBreach #CyberSecurity #CyberAttack #InfoSec #ThirdPartyRisk #SupplyChainSecurity #TaxData #IdentityTheft #DataPrivacy #ThreatIntel #SecurityNews #CyberNews #Privacy #InfosecCommunity