DEV Community

#supplychain

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Artifact repositories as attack surface: 17,883 JFrog Artifactory assets and the supply chain behind them

Artifact repositories as attack surface: 17,883 JFrog Artifactory assets and the supply chain behind them

Comments
3 min read
I Now Plan Laptops the Way Our Buyers Plan Stock

I Now Plan Laptops the Way Our Buyers Plan Stock

Comments
2 min read
Artifact Repositories Are Trust Anchors: Incident Response for a Compromised Build Pipeline

Artifact Repositories Are Trust Anchors: Incident Response for a Compromised Build Pipeline

Comments
3 min read
GitHub got pwned through one VSCode extension. 3,800 repos.

GitHub got pwned through one VSCode extension. 3,800 repos.

Comments
5 min read
The JFrog Artifactory authentication bypass: when an empty signing key becomes an admin token

The JFrog Artifactory authentication bypass: when an empty signing key becomes an admin token

Comments
3 min read
The Credential Relay Economy: How Supply Chain Attacks Chain Through SaaS Vendors

The Credential Relay Economy: How Supply Chain Attacks Chain Through SaaS Vendors

Comments
2 min read
Software Supply Chains Have an Address: Mapping Exposed Artifact Repositories with ZoomEye

Software Supply Chains Have an Address: Mapping Exposed Artifact Repositories with ZoomEye

Comments
3 min read
The Ghost in the Machine: Unraveling Persistent Git Compromises Beyond Your Control

The Ghost in the Machine: Unraveling Persistent Git Compromises Beyond Your Control

Comments
5 min read
The Artifactory Token Chain: Why Build Repositories Are a Credential Store

The Artifactory Token Chain: Why Build Repositories Are a Credential Store

Comments
4 min read
700 Agents, 25 Actions Each, and Nothing Fired

700 Agents, 25 Actions Each, and Nothing Fired

Comments
3 min read
The Artifact Repository Is a Trust Root: Reading the JFrog Artifactory Authentication Bypass

The Artifact Repository Is a Trust Root: Reading the JFrog Artifactory Authentication Bypass

Comments
4 min read
The Shai-Hulud npm worm showed that opening a folder is enough to run code

The Shai-Hulud npm worm showed that opening a folder is enough to run code

Comments
3 min read
Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces

Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces

Comments
3 min read
One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk

One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk

Comments
3 min read
The Default Join Key That Let Attackers Mint Admin Tokens on JFrog Artifactory

The Default Join Key That Let Attackers Mint Admin Tokens on JFrog Artifactory

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.