Providing assistance to organisations with DevOps, DevSecOps, and modern infrastructure challenges in AWS or Kubernetes, as well as VAPT and ISO/SoC2 reports.
So, these threat actors successfully phished an author of multiple open source NPM packages with a total of 2 billion weekly downloads – including debug, chalk, and ansi-styles.
Since most companies run at least one React or Angular app, they had the opportunity to execute code on millions of systems across thousands of orgs.
And they used it to drop an amateurishly obfuscated crypto stealer, got caught by basic detection rules, and the issue was remediated after 2 hours.
I hope everyone understands how close this was – and can imagine what would’ve happened if someone with real skills had done it.
#NPM #Compromise #SupplyChain
I am excited to announce a new project, Hacker AI, an AI-powered tool that detects vulnerabilities in source code.
Check it out at https://t.co/hLuNQ0fpav.
Feedback is greatly appreciated.
The #AWS Region in India is now open. 🎉 🎊
From fast-growing startups to large enterprises, AWS is here to support innovation. 📈
Learn more about the AWS Asia Pacific (Hyderabad) region here: https://t.co/U9NnWeEPdc
Synack integration with @Microsoft Sentinel provides security teams end-to-end visibility, analysis and insights into #cyberattacks across cloud environments. Check out the blog to learn more about the announcement -> https://t.co/HLDDF66j9i