supply-chain-attack

Tag

Cards List
#supply-chain-attack

GNU IFUNC is the real culprit behind CVE-2024-3094

Hacker News Top · yesterday Cached

The article argues that GNU IFUNC and design decisions linking OpenSSH to SystemD were the primary enablers of the CVE-2024-3094 xz-utils backdoor, rather than the malicious code itself.

0 favorites 0 likes
#supply-chain-attack

A Roblox cheat and one AI tool brought down Vercel's platform

Hacker News Top · 2026-04-21 Cached

A Roblox cheat infected a Context.ai employee with Lumma Stealer, which led to compromised OAuth credentials being used to breach Vercel's internal systems, exposing non-sensitive environment variables and highlighting risks of broad AI tool OAuth permissions.

0 favorites 0 likes
#supply-chain-attack

Our response to the Axios developer tool compromise

OpenAI Blog · 2026-04-10 Cached

OpenAI disclosed a security incident where the Axios developer tool was compromised as part of a broader supply chain attack, potentially exposing their macOS code signing certificate. OpenAI found no evidence of data compromise but is proactively revoking and rotating its certificate, requiring users to update their macOS applications.

0 favorites 0 likes
← Back to home

Submit Feedback