https://www.openwall.com/lists/oss-security/2025/08/13/9
#FOSS #supplychain
Trump Threatens 100% Tariff on Chips, With a Big Caveat - The tariff would not apply to businesses that make a commitment to build and invest in th... - https://www.nytimes.com/2025/08/06/technology/trump-chip-tariffs-semiconductors.html #regulationandderegulationofindustry #unitedstatespoliticsandgovernment #internationaltradeandworldmarket #factoriesandmanufacturing #customs(tariff) #computerchips #trumpdonaldj #unitedstates #supplychain #appleinc #taiwan
I've just released a major new project, Appraisal2
- https://github.com/appraisal-rb/appraisal2 - a hard fork of the unfinished appraisal v3.0.0.rc1
Appraisal2 integrates with bundler and rake to test your library against different versions of dependencies in repeatable scenarios called "appraisals".
Appraisal2 is designed to make it easy to check for regressions in your library without interfering with day-to-day development using Bundler.
OK, but why?
Cicha aktualizacja z malware w rozszerzeniach do Google Chrome i Microsoft Edge zainfekowała 2,3 mln użytkowników.
Kilkanaście złośliwych rozszerzeń do przeglądarki Google Chrome i Microsoft Edge mogło śledzić użytkowników, wykradać dane dotyczące aktywności w przeglądarce i przekierowywać do potencjalnie niebezpiecznych adresów internetowych. Były dostępne w oficjalnych sklepach Google i Microsoft. Łącznie zostały pobrane 2,3 miliona razy. Większość dodatków zapewniało reklamowaną funkcjonalność udając legalne narzędzia, takie jak...
#WBiegu #Chrome #Dodatki #Edge #Google #Malware #Microsoft #Supplychain
A Field Guide to the North American Cold Chain - So far in the “Field Guide” series, we’ve mainly looked at critical infrastructure... - https://hackaday.com/2025/07/17/a-field-guide-to-the-north-american-cold-chain/ #refrigerator #engineering #supplychain #fieldguide #coldchain #logistics #featured #interest #shipping #freezer #produce #food
Hackaday Links: June 8, 2025 - When purchasing high-end gear, it’s not uncommon for manufacturers to include a li... - https://hackaday.com/2025/06/08/hackaday-links-june-8-2025/ #hackadaycolumns #hackadaylinks #counterfeit #supplychain #emergentai #andromeda #packaging #milkyway #robotdog #robotics #5090rtx #unitree #galaxy #nvidia #temu #d2w #dip #dog #qfn #qfp #w2w
Why Making an iPhone in the U.S. Would Be So Difficult - Apple has resisted pressure to make its most important product in the United States since... - https://www.nytimes.com/2025/05/23/technology/apple-iphone-trump-india-china.html #factoriesandmanufacturing #computersandtheinternet #cooktimothyd #trumpdonaldj #supplychain #appleinc #iphone #china #india
This hasn't made the news anywhere, but if you know a small business in Canada right now that ships to the US, they are actually getting crushed by the border between Canada-USA being in absolute chaos.
Tons of trucks are being sent back. Packages denied.
This is absolute hell. Much worse now than anytime since the whole tariff situation started.
Outside of the logistics and ecommerce circles, pure silence, nobody knows
Small- & medium-sized farms were already struggling amid worsening #climate shocks & volatile commodities #markets, on top of being squeezed by large #corporations that dominate the #SupplyChain.
In recent weeks, #farmers in Texas & across the midwest have suffered millions of dollars of crop losses due to unprecedented heavy rainfall & #flooding.
@GossiTheDog
If China(and/or asia) would go full contra, a LOT of biz in the US would just go broke. #supplychain
@ulrichkelber gibt es Informationen darüber, wie @zendis sich gegen #supplyChain -Attacken und Sicherheitslücken in den zugrundeliegenden #OpenSource -Lösungen von #OpenDesk und #OpenCode wappnet, um zusätzlich zur #Souveränität auch die IT-Sicherheit der Systeme ausreichend sicherzustellen? Wie wird bei der Weiterenwicklung und Updates geprüft, damit kein Schadcode eingeschleust wird?
#ITSecurity #Zendis #OpenSource #HybriderKrieg #OpSec #Kritis
Supply-chain CAPTCHA attack hits over 100 car dealerships - A security researcher has discovered that the websites of over 100 car dealerships have b... https://www.bitdefender.com/en-us/blog/hotforsecurity/supply-chain-captcha-attack-hits-over-100-car-dealerships #supplychain #guestblog #clipboard #malware #captcha
It would appear as if Wiz may have discovered another supply-chain compromise:
https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup
The attack involved compromising the v1 tag of reviewdog/action-setup between March 11th 18:42 and 20:31 UTC. Unlike the tj-actions attack that used curl to retrieve a payload, this attack directly inserted a base64-encoded malicious payload into the install.sh file. When executed, the code dumped CI runner memory containing workflow secrets, which were then visible in logs as double-encoded base64 strings. The attack chain appears to have started with the compromise of reviewdog/action-setup, which was then used to compromise the tj-actions-bot Personal Access Token (PAT), ultimately leading to the compromise of tj-actions/changed-files. Organizations are advised to check for affected repositories using GitHub queries, examine workflow logs for evidence of compromise, rotate any leaked secrets, and implement preventive measures like pinning actions to specific commit hashes rather than version tags.
Jak literówka w pakiecie Go przetrwała trzy lata… w tle atak na łańcuch dostaw
Badacze Socket.dev zaprezentowali odkryty atak na łańcuch dostaw celujący w projekty napisane w Golangu. Atak wykorzystywał literówkę (tzw. typosquatting) w znanej bibliotece BoltDB, obsługującej bazę danych typu klucz-wartość. Oryginalny projekt został zarchiwizowany jakiś czas temu i nie jest już rozwijany. Atakujący sklonowali repozytorium, nadali mu bardzo zbliżoną nazwę i dodali...
#WBiegu #Go #ŁańcuchDostaw #Podatność #Supplychain
https://sekurak.pl/jak-literowka-w-pakiecie-go-przetrwala-trzy-lata-w-tle-atak-na-lancuch-dostaw/
Reproducible-openSUSE (RBOS) hits a milestone! 100% bit-identical packages built; boosting #supplychain #security & #software integrity! #openSUSE #Linux https://news.opensuse.org/2025/02/18/rbos-project-hits-milestone/
Delivering Malware Through Abandoned Amazon S3 Buckets
Here’s a supply-chain attack just waiting to happen. A group of researchers searched for, and then registered, abandoned Amazon S3 buckets for about $400. These buckets contained software libraries that are still used. Presumably the project... https://www.schneier.com/blog/archives/2025/02/delivering-malware-through-abandoned-amazon-s3-buckets.html
Celebrating our 2024 open-source contributions - While Trail of Bits is known for developing security tools like Slither, Medusa, and Fick... https://blog.trailofbits.com/2025/01/23/celebrating-our-2024-open-source-contributions/ #artificialintelligence #machinelearning #cryptography #supplychain #blockchain #opensource #compilers #reversing #llvm
New additional information, new plugin identified as malicious
VPNCity - Fast & Unlimited VPN | Unblocker - nnpnnpemnckcfdebeekibpiijlicmpom
https://hackread.com/16-chrome-extensions-hacked-credential-theft-scheme/
------------------
Malicious parties have taken over popular Chrome plugins to push malware.
I can confirm it is not just Cyberhaven plugin. We dont have a list of impacted plugins, just reports of machines reaching out to the reported malicious domains from Chrome. Still gathering informaiton.
https://therecord.media/hackers-target-vpn-ai-extensions-google-chrome-malicious-updates
https://x.com/jaimeblascob/status/1872445912175534278
Edited to add additional IOCs (IP of C&C and Domains):
149.28.124[.]84
bookmarkfc.info,
cyberhavenext.pro,
parrottalks.info,
uvoice.live,
vpncity.live
castorus.info, censortracker.pro, ext.linewizeconnect.com, iobit.pro, moonsift.store, readermodeext.info, wayinai.live, yescaptcha.pro and yujaverity.info
#Cloudflare verliert #Logging-Daten seiner Kunden
"Mehrere Stunden an #Protokolldaten eines Großteils der Cloudflare-Kundschaft sind #verschwunden. Dabei wollte der Konzern nur eine kleine Änderung einführen.
Laut Cloudflare sind nur etwa 3,5 Stunden an Logging-Daten verschwunden. Innerhalb dieses Zeitfensters betrifft der #Datenverlust allerdings rund 55 Prozent aller Protokolle, die der Dienst normalerweise an Kunden übermittelt..."
#Lieferkette #SupplyChain
https://www.golem.de/news/nicht-nur-microsoft-kann-das-cloudflare-verliert-logging-daten-seiner-kunden-2411-191180.html
Cyberangriff auf Drittanbieter: Starbucks muss Gehälter wohl manuell auszahlen
"Neben Starbucks hat das attackierte Unternehmen noch weitere prominente Kunden – darunter Ford, Nissan, Microsoft, Samsung, Lenovo und Coca Cola..."
#Ransomware #Lieferkette #SupplyChain
https://www.golem.de/news/cyberangriff-auf-drittanbieter-starbucks-muss-gehaelter-wohl-manuell-auszahlen-2411-191147.html