GitHub repojacking attack: 10 lessons for software teams
Software supply chain attacks are on the rise because of their reach. Here are 10 valuable lessons from the recent GitHub namespace attack.
Stay updated with breaking news from Tim Mackey. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Software supply chain attacks are on the rise because of their reach. Here are 10 valuable lessons from the recent GitHub namespace attack.
Languages such as C and C++ rely too heavily on the programmer not making simple memory-related security errors.
The announcement has been noteworthy as this is only the second time OpenSSL has classified a flaw as “critical” since the Heartbleed bug in 2014. It has also been somewhat controversial among the security community, with some questioning whether the OpenSSL project's decision to go public about the vulnerability before the patch gives attackers more opportunities to exploit it.
Checkmarx researchers say the vulnerability was fixed, but warns that the potential attack surface for such “hidden malicious code” may grow exponentially.