Fetching the paper…
Reading the bibliography…
The widespread dependency on open-source software makes it a fruitful target for malicious actors, as demonstrated by recurring attacks.
L. A. Goodman, “Snowball Sampling,” The Annals of Mathematical Statistics
1961
Earlier work this paper cites.
K. Thompson, “Reflections on trusting trust,” Commun. ACM
1984
Earlier work this paper cites.
B. Schneier, “Attack trees,” Dr. Dobb’s journal
1999
Earlier work this paper cites.
W. Goerigk, “On trojan horses in compiler implementations,” in Proc. des Workshops Sicherheit und Zuverlassigkeit softwarebasierter Systeme
1999
Earlier work this paper cites.
P. A. Karger and R. R. Schell, “Thirty years later: Lessons from the multics security evaluation,” in 18th Annual Computer Security Applications Conference, 2002. Proceedings
2002
Earlier work this paper cites.
E. Levy, “Poisoning the software supply chain,” IEEE Security Privacy
2003
Earlier work this paper cites.
D. A. Wheeler, “Countering trusting trust through diverse double-compiling,” in 21st Annual Computer Security Applications Conference (ACSAC’05)
2005
Earlier work this paper cites.
D. Wheeler, “Countering trusting trust through diverse double-compiling,” in 21st Annual Computer Security Applications Conference (ACSAC’05)
2005
Earlier work this paper cites.
S. Mauw and M. Oostdijk, “Foundations of attack trees,” vol. 3935, pp. 186–198, 07 2006
2006
Earlier work this paper cites.
A. Bellissimo, J. Burgess, and K. Fu, “Secure software updates: Disappointments and new challenges.,” in HotSec
2006
Earlier work this paper cites.
M. Naedele and T. E. Koch, “Trust and tamper-proof software delivery,” in Proceedings of the 2006 International Workshop on Software Engineering for Secure Systems
2006
Earlier work this paper cites.
B. Chess, F. D. Lee, and J. West, “Attacking the build through cross-build injection: how your build process can open the gates to a trojan horse,” 2007
2007
Earlier work this paper cites.
J. Cappos, J. Samuel, S. Baker, and J. Hartman, “Package management security,” 01 2008
2008
Earlier work this paper cites.
Elsevier, 2008
C. S. Wright, The IT regulatory and standards compliance handbook: How to survive information systems audit and assessments · 2008
Earlier work this paper cites.
J. Cappos, J. Samuel, S. Baker, and J. H. Hartman, “A look in the mirror: Attacks on package managers,” in Proceedings of the 15th ACM Conference on Computer and Communications Security
2008
Earlier work this paper cites.
B. Kitchenham, O. P. Brereton, D. Budgen, M. Turner, J. Bailey, and S. Linkman, “Systematic literature reviews in software engineering–a systematic literature review,” Information and software technology
2009
Earlier work this paper cites.
Rosenfeld Media, 2009
D. Spencer, Card sorting: Designing usable categories · 2009
Earlier work this paper cites.
F. Gröbert, A.-R. Sadeghi, and M. Winandy, “Software distribution as a malware infection vector,” in 2009 International Conference for Internet Technology and Secured Transactions, (ICITST)
2009
Earlier work this paper cites.
R. J. Ellison and C. Woody, “Supply-chain risk management: Incorporating security into software development,” in 2010 43rd Hawaii International Conference on System Sciences
2010
Earlier work this paper cites.
S. McClure, S. Gupta, C. Dooley, V. Zaytsev, X. B. Chen, K. Kaspersky, M. Spohn, and R. Permeh, “Protecting your critical assets-lessons learned from operation aurora,” Tech. Rep
2010
Earlier work this paper cites.
J. Samuel, N. Mathewson, J. Cappos, and R. Dingledine, “Survivable key compromise in software update systems,” in Proceedings of the 17th ACM Conference on Computer and Communications Security
2010
Earlier work this paper cites.
I. You and K. Yim, “Malware obfuscation techniques: A brief survey,” in 2010 International Conference on Broadband, Wireless Computing, Communication and Applications
2010
Earlier work this paper cites.
I. Haddad and B. Warner, “Understanding the open source development model,” Linux Journal
2011
Earlier work this paper cites.
C. W. Axelrod, “Assuring software and hardware security and integrity throughout the supply chain,” in 2011 IEEE International Conference on Technologies for Homeland Security (HST)
2011
Earlier work this paper cites.
C. J. Alberts, A. J. Dorofee, R. Creel, R. J. Ellison, and C. Woody, “A systemic approach for assessing software supply-chain risk,” in 2011 44th Hawaii International Conference on System Sciences
2011
Earlier work this paper cites.
P. R. Croll, “Supply chain risk management - understanding vulnerabilities in code you buy, build, or integrate,” in 2011 IEEE International Systems Conference
2011
Earlier work this paper cites.
J. K. Smith, “Security incident on fedora infrastructure on 23 jan 2011,” 2011
2011
Earlier work this paper cites.
M. Glassman and M. J. Kang, “Intelligence in the internet age: The emergence and evolution of open source intelligence (osint),” Computers in Human Behavior
2012
Earlier work this paper cites.
Springer Science & Business Media, 2012
C. Wohlin, P. Runeson, M. Höst, M. C. Ohlsson, B. Regnell, and A. Wesslén, Experimentation in software engineering · 2012
Earlier work this paper cites.
A. Ojamaa and K. Düüna, “Assessing the security of node.js platform,” in 2012 International Conference for Internet Technology and Secured Transactions
2012
Earlier work this paper cites.
Newnes, 2013
W. Albert and T. Tullis, Measuring the user experience: collecting, analyzing, and presenting usability metrics · 2013
Earlier work this paper cites.
S. Du, T. Lu, L. Zhao, B. Xu, X. Guo, and H. Yang, “Towards an analysis of software supply chain risk management,” in Proceedings of the World Congress on Engineering and Computer Science
2013
Earlier work this paper cites.
M. Silic and A. Back, “Information security and open source dual use security software: trust paradox,” in IFIP International Conference on Open Source Systems
2013
Earlier work this paper cites.
V. Gruhn, C. Hannebauer, and C. John, “Security of public continuous integration services,” in Proceedings of the 9th International Symposium on Open Collaboration
2013
Earlier work this paper cites.
J. Tellnes, “Dependencies: No software is an island,” Master’s thesis, The University of Bergen, 2013
2013
Earlier work this paper cites.
K. Alhamed, M. C. Silaghi, I. Hussien, and Y. Yang, “Security by decentralized certification of automatic-updates for open source software controlled by volunteers,” in Workshop on Decentralized Coordination
2013
Earlier work this paper cites.
S. Du, T. Lu, L. Zhao, B. Xu, X. Guo, and H. Yang, “Towards an analysis of software supply chain risk management,” 2013
2013
Earlier work this paper cites.
Z. Durumeric, F. Li, J. Kasten, J. Amann, J. Beekman, M. Payer, N. Weaver, D. Adrian, V. Paxson, M. Bailey, and J. A. Halderman, “The matter of heartbleed,” in Proceedings of the 2014 Conference on Internet Measurement Conference
2014
Earlier work this paper cites.
X. de Carné de Carnavalet and M. Mannan, “Challenges and implications of verifiable builds for security-critical open-source software,” in Proceedings of the 30th Annual Computer Security Applications Conference
2014
Earlier work this paper cites.
B. A. Sabbagh and S. Kowalski, “A socio-technical framework for threat modeling a software supply chain,” IEEE Security Privacy
2015
Earlier work this paper cites.
S. Zhang, X. Zhang, X. Ou, L. Chen, N. Edwards, and J. Jin, “Assessing attack surface with component-based package dependency,” in International Conference on Network and System Security
2015
Earlier work this paper cites.
H. Plate, S. E. Ponta, and A. Sabetta, “Impact assessment for vulnerabilities in open-source software libraries,” in 2015 IEEE International Conference on Software Maintenance and Evolution (ICSME)
2015
Earlier work this paper cites.
B. Delamore and R. K. L. Ko, “A global, empirical analysis of the shellshock vulnerability in web applications,” in 2015 IEEE Trustcom/BigDataSE/ISPA
2015
Earlier work this paper cites.
L. Bass, R. Holz, P. Rimba, A. B. Tran, and L. Zhu, “Securing a deployment pipeline,” in 2015 IEEE/ACM 3rd International Workshop on Release Engineering
2015
Earlier work this paper cites.
J. Rossignol, “What you need to know about ios malware xcodeghost,” URL: www. macrumors. com/2015/09/20/xcodeghost-chinese-malwarefaq
2015
Earlier work this paper cites.
PhD thesis, Universität Hamburg, Fachbereich Informatik, 2016
N. P. Tschacher, Typosquatting in programming language package managers · 2016
Earlier work this paper cites.
S. Torres-Arias, A. K. Ammula, R. Curtmola, and J. Cappos, “On omitting commits and committing omissions: Preventing git metadata tampering that (re)introduces software vulnerabilities,” in 25th USENIX Security Symposium (USENIX Security 16)
2016
Earlier work this paper cites.
J. Pewny and T. Holz, “Evilcoder: Automated bug insertion,” in Proceedings of the 32nd Annual Conference on Computer Security Applications
2016
Earlier work this paper cites.
T. K. Kuppusamy, S. Torres-Arias, V. Diaz, and J. Cappos, “Diplomat: Using delegations to protect community repositories,” in Proceedings of the 13th Usenix Conference on Networked Systems Design and Implementation
2016
Earlier work this paper cites.
A. Avram, “Npm was broken for 2.5 hours,” URL: www. infoq. com/news/2016/03/npm/
2016
Earlier work this paper cites.
“kik, left-pad, and npm,” URL: blog. npmjs. org/post/141577284765/kik-left-pad-and-npm
2016
Earlier work this paper cites.
S. Benthall, “Assessing software supply chain risk using public data,” in 2017 IEEE 28th Annual Software Technology Conference (STC)
2017
Earlier work this paper cites.
B. Pfretzschner and L. ben Othmane, “Identification of dependency-based attacks on node.js,” in Proceedings of the 12th International Conference on Availability, Reliability and Security
2017
Earlier work this paper cites.
T. K. Kuppusamy, V. Diaz, and J. Cappos, “Mercury: Bandwidth-effective prevention of rollback attacks against community repositories,” in 2017 USENIX Annual Technical Conference (USENIX ATC 17)
2017
Earlier work this paper cites.
B. Lamowski, C. Weinhold, A. Lackorzynski, and H. Härtig, “Sandcrust: Automatic sandboxing of unsafe components in rust,” in Proceedings of the 9th Workshop on Programming Languages and Operating Systems
2017
Earlier work this paper cites.
R. Goyal, G. Ferreira, C. Kästner, and J. Herbsleb, “Identifying unusual commits on github: Goyal et al .,” Journal of Software: Evolution and Process
2017
Earlier work this paper cites.
Sonatype, “Q3 2021 state of the software supply chain report,” URL: www. sonatype. com/resources/state-of-the-software-supply-chain-2021
2018
Earlier work this paper cites.
K. Tuma, G. Calikli, and R. Scandariato, “Threat analysis of software systems: A systematic literature review,” Journal of Systems and Software
2018
Earlier work this paper cites.
A. Blackstone et al
2018
Earlier work this paper cites.
A. V. Barabanov, A. S. Markov, M. I. Grishin, and V. L. Tsirlov, “Current taxonomy of information security threats in software development life cycle,” in 2018 IEEE 12th International Conference on Application of Information and Communication Technologies (AICT)
2018
Earlier work this paper cites.
C.-A. Staicu, M. Pradel, and B. Livshits, “Synode: Understanding and automatically preventing injection attacks on node. js.,” in NDSS
2018
Earlier work this paper cites.
A. Sabetta and M. Bezzi, “A practical approach to the automatic classification of security-relevant commits,” in 2018 IEEE International Conference on Software Maintenance and Evolution (ICSME)
2018
Earlier work this paper cites.
L. Neil, S. Mittal, and A. Joshi, “Mining threat intelligence about open-source projects and libraries from code repository issues and bug reports,” in 2018 IEEE International Conference on Intelligence and Security Informatics (ISI)
2018
Earlier work this paper cites.
I. Pashchenko, H. Plate, S. E. Ponta, A. Sabetta, and F. Massacci, “Vulnerable open source dependencies: Counting those that matter,” in Proceedings of the 12th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement
2018
Earlier work this paper cites.
N. Vasilakis, B. Karel, N. Roessler, N. Dautenhahn, A. DeHon, and J. M. Smith, “Breakapp: Automated, flexible application compartmentalization.,” in NDSS
2018
Cited alongside, same era.
H. Assal and S. Chiasson, “Security in the software development lifecycle,” in Fourteenth symposium on usable privacy and security (SOUPS 2018)
2018
Cited alongside, same era.
R. Goyal, G. Ferreira, C. Kästner, and J. Herbsleb, “Identifying unusual commits on github,” Journal of Software: Evolution and Process
2018
Cited alongside, same era.
J. Coelho, M. T. Valente, L. L. Silva, and E. Shihab, “Identifying unmaintained projects in github,” in Proceedings of the 12th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement
2018
Cited alongside, same era.
M. Beltov, “Arch linux aur repository found to contain malware,” URL: sensorstechforum. com/arch-linux-aur-repository-found-contain-malware/
[Online; accessed 20-October-2021]
T. Costa, “strong_password v0.0.7 rubygem hijacked,” 2019 · 2021
Later among the works it cites.
[Online; accessed 20-October-2021]
R. Naraine, “Open-source ProFTPD hacked, backdoor planted in source code,” 2010 · 2021
Later among the works it cites.
[Online; accessed 20-October-2021]
S. J. Vaughan-Nichols, “Php supply chain attack shows open source’s virtues and vices,” 2021 · 2021
Later among the works it cites.
[Online; accessed 20-October-2021]
R. Lakshmanan, “Critical jenkins server vulnerability could leak sensitive information,” 2020 · 2021
Later among the works it cites.
[Online; accessed 20-October-2021]
Microsoft Defender Security Research Team, “Attack inception: Compromised supply chain within a supply chain poses new risks,” 2018 · 2021
Later among the works it cites.
[Online; accessed 20-October-2021]
Autosoft, “A confusing dependency,” 2021 · 2021
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2018
Cited alongside, same era.
A. Decan, T. Mens, and E. Constantinou, “On the impact of security vulnerabilities in the npm package dependency network,” in Proceedings of the 15th International Conference on Mining Software Repositories
2018
Cited alongside, same era.
R. Cox, “Our software dependency problem,” Unpublished essay, available online in January: https://research. swtch. com/deps. pdf
2019
Cited alongside, same era.
M. Zimmermann, C.-A. Staicu, C. Tenny, and M. Pradel, “Small world with high risks: A study of security threats in the npm ecosystem,” in 28th USENIX Security Symposium (USENIX Security 19)
2019
Cited alongside, same era.
O. Duman, M. Ghafouri, M. Kassouf, R. Atallah, L. Wang, and M. Debbabi, “Modeling supply chain attacks in iec 61850 substations,” in 2019 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm)
2019
Cited alongside, same era.
K. Singi, V. Kaulgud, R. J. C. Bose, and S. Podder, “Shift - software identity framework for global software delivery,” in 2019 ACM/IEEE 14th International Conference on Global Software Engineering (ICGSE)
2019
Cited alongside, same era.
R. K. Vaidya, L. D. Carli, D. Davidson, and V. Rastogi, “Security issues in language-based sofware ecosystems,” 2019
2019
Cited alongside, same era.
C. Paule, T. F. Düllmann, and A. Van Hoorn, “Vulnerabilities in continuous delivery pipelines? a case study,” in 2019 IEEE International Conference on Software Architecture Companion (ICSA-C)
2019
Cited alongside, same era.
J. Engelberg, “Bash uploader security update,” URL: about. codecov. io/security-update/
2021
Later among the works it cites.
[Online; accessed 20-October-2021]
M. Hanley, “Github’s commitment to npm ecosystem security,” 2021 · 2021
Later among the works it cites.
[Online; accessed 20-October-2021]
Google, “Google’s open source documentation.” · 2021
Later among the works it cites.
Microsoft Corporation, “3 ways to mitigate risk when using private package feeds,” URL: azure. microsoft. com/en-us/resources/3-ways-to-mitigate-risk-using-private-package-feeds/
2021
Later among the works it cites.
A. Kjäll, S. Kristoffersen, and S. Pettersen, “How we protected ourselves from the dependency confusion attack,” URL: schibsted. com/blog/dependency-confusion-how-we-protected-ourselves/
2021
Later among the works it cites.
C. Soto-Valero, N. Harrand, M. Monperrus, and B. Baudry, “A comprehensive study of bloated dependencies in the maven ecosystem,” Empirical Software Engineering
2021
Later among the works it cites.
N. Forsgren, B. Alberts, K. Backhouse, G. Baker, G. Cecarelli, D. Jedamski, S. Kelly, and C. Sullivan, “2020 state of the octoverse: Securing the world’s software,” 2021
2021
Later among the works it cites.
C. Lamb and S. Zacchiroli, “Reproducible builds: Increasing the integrity of software supply chains,” IEEE Software
2021
Later among the works it cites.
[Online; accessed 20-October-2021]
GitHub, “The 2021 state of the octoverse,” 2021 · 2021
Later among the works it cites.
[Online; accessed 20-October-2021]
European Network and Information Security Agency, “Enisa threat landscape for supply chain attacks 2021,” 2021 · 2021
Later among the works it cites.
M. Ensor and D. Stevens, “Shifting left on security: Securing software supply chains,” URL: cloud. google. com/files/shifting-left-on-security.pdf
2021
Later among the works it cites.
2022
Closest in time.
[Accessed 15-Mar-2022]
E. Roth, “Open source developer corrupts widely-used libraries, affecting tons of projects.” https://www.theverge.com/2022/1/9/22874949/developer-corrupts-open-source-libraries-projects-affected · 2022
Closest in time.
[Accessed 18-Mar-2022]
L. Tal, “Alert: peacenotwar module sabotages npm developers in the node-ipc package to protest the invasion of ukraine.” https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-package-vulnerability/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
“PyPI Python repository hit by typosquatting sneak attack.” https://nakedsecurity.sophos.com/2017/09/19/pypi-python-repository-hit-by-typosquatting-sneak-attack/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
“npm Blog Archive: ‘crossenv‘ malware on the npm registry.” https://blog.npmjs.org/post/163723642530/crossenv-malware-on-the-npm-registry · 2022
Closest in time.
[Accessed 15-Mar-2022]
“skcsirt-sa-20170909-pypi.” https://www.nbu.gov.sk/skcsirt-sa-20170909-pypi/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
Bertus, “Discord Token Stealer Discovered in PyPI Repository.” https://bertusk.medium.com/discord-token-stealer-discovered-in-pypi-repository-e65ed9c3de06 · 2022
Closest in time.
[Accessed 15-Mar-2022]
R. Lakshmanan, “Malicious NPM Libraries Caught Installing Password Stealer and Ransomware.” https://thehackernews.com/2021/10/malicious-npm-libraries-caught.html · 2022
Closest in time.
[Accessed 15-Mar-2022]
Bertus, “Cryptocurrency Clipboard Hijacker Discovered in PyPI Repository.” https://bertusk.medium.com/cryptocurrency-clipboard-hijacker-discovered-in-pypi-repository-b66b8a534a8 · 2022
Closest in time.
[Accessed 15-Mar-2022]
“Malicious packages found to be typo-squatting in Python Package Index.” https://snyk.io/blog/malicious-packages-found-to-be-typo-squatting-in-pypi/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
“How to ask to ban the application for security reasons? Issue #651.” https://github.com/canonical-web-and-design/snapcraft.io/issues/651 · 2022
Closest in time.
[Accessed 15-Mar-2022]
“An emergency re-review of kernel commits authored by members of the university of minnesota, due to the hypocrite commits research paper.” https://lore.kernel.org/lkml/202105051005.49BFABCE@keescook/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
“CVE - CVE-2021-42574.” https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42574 · 2022
Closest in time.
[Accessed 15-Mar-2022]
“CVE - CVE-2021-42694.” https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42694 · 2022
Closest in time.
[Accessed 15-Mar-2022]
“GitHub - mortenson/pr-sneaking: A repository demonstrating how you can sneak malicious code into Github PRs.” https://github.com/mortenson/pr-sneaking · 2022
Closest in time.
[Accessed 15-Mar-2022]
“Why npm lockfiles can be a security blindspot for injecting malicious modules Snyk.” https://snyk.io/blog/why-npm-lockfiles-can-be-a-security-blindspot-for-injecting-malicious-modules/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
H. Garrood, “Malicious code in the PureScript npm installer - Harry Garrood.” https://harry.garrood.me/blog/malicious-code-in-purescript-npm-installer/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
“Trusted Relationship, Technique T1199 - MITRE att&ck.” https://attack.mitre.org/techniques/T1199/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
“Valid Accounts, Technique T1078 - MITRE att&ck.” https://attack.mitre.org/techniques/T1078/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
“Unsecured Credentials, Technique T1552 - MITRE att&ck.” https://attack.mitre.org/techniques/T1552/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
“php.internals: Changes to Git commit workflow.” https://news-web.php.net/php.internals/113838 · 2022
Closest in time.
[Accessed 15-Mar-2022]
“Backdoor planted in PHP Git repository after server hack.” https://portswigger.net/daily-swig/backdoor-planted-in-php-git-repository-after-server-hack · 2022
Closest in time.
[Accessed 15-Mar-2022]
“Malicious remote code execution backdoor discovered in the popular bootstrap-sass Ruby gem.” https://snyk.io/blog/malicious-remote-code-execution-backdoor-discovered-in-the-popular-bootstrap-sass-ruby-gem/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
“strong_password v0.0.7 rubygem hijacked.” https://withatwist.dev/strong-password-rubygem-hijacked.html · 2022
Closest in time.
[Accessed 15-Mar-2022]
“[CVE-2019-15224] Version 1.6.13 published with malicious backdoor. Issue #713.” https://github.com/rest-client/rest-client/issues/713 · 2022
Closest in time.
[Accessed 15-Mar-2022]
“Brute Force, Technique T1110 - MITRE att&ck.” https://attack.mitre.org/techniques/T1110/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
E. Holmes, “How I gained commit access to Homebrew in 30 minutes.” https://medium.com/@vesirin/how-i-gained-commit-access-to-homebrew-in-30-minutes-2ae314df03ab · 2022
Closest in time.
[Accessed 15-Mar-2022]
“CERT/CC Vulnerability Note VU#319816.” https://www.kb.cert.org/vuls/id/319816 · 2022
Closest in time.
[Accessed 15-Mar-2022]
“CAPEC - CAPEC-60: Reusing Session IDs (aka Session Replay) (Version 3.7).” https://capec.mitre.org/data/definitions/60.html · 2022
Closest in time.
[Accessed 15-Mar-2022]
T. H. II, “Compromised npm Package: event-stream.” https://medium.com/intrinsic-blog/compromised-npm-package-event-stream-d47d08605502 · 2022
Closest in time.
[Accessed 15-Mar-2022]
“OWASP Top Ten 2017 - A6:2017-Security Misconfiguration.” https://owasp.org/www-project-top-ten/2017/A6_2017-Security_Misconfiguration · 2022
Closest in time.
[Accessed 15-Mar-2022]
“CWE - CWE-16: Configuration (4.6).” https://cwe.mitre.org/data/definitions/16.html · 2022
Closest in time.
[Accessed 15-Mar-2022]
“Exploit Public-Facing Application, Technique T1190 - MITRE att&ck.” https://attack.mitre.org/techniques/T1190/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
“Operation ShadowHammer: A High Profile Supply Chain Attack.” https://securelist.com/operation-shadowhammer-a-high-profile-supply-chain-attack/90380/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
R. Naraine, “Open-source ProFTPD hacked, backdoor planted in source code.” https://www.zdnet.com/article/open-source-proftpd-hacked-backdoor-planted-in-source-code/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
“Adobe to revoke crypto key abused to sign malware apps (corrected).” https://arstechnica.com/information-technology/2012/09/adobe-to-revoke-crypto-key-abused-to-sign-5000-malware-apps/ · 2022
Closest in time.
[Accessed 15-Mar-2022]
“Siloscape: First Known Malware Targeting Windows Containers to Compromise Cloud Environments.” https://unit42.paloaltonetworks.com/siloscape/ · 2022
Closest in time.
[Accessed 16-Mar-2022]
“Max.Computer - How to take over the computer of any Java (or Clojure or Scala) developer.” https://max.computer/blog/how-to-take-over-the-computer-of-any-java-or-clojure-or-scala-developer/ · 2022
Closest in time.
[Accessed 16-Mar-2022]
“CAPEC-142: DNS Cache Poisoning (Version 3.7).” https://capec.mitre.org/data/definitions/142.html · 2022
Closest in time.
[Accessed 16-Mar-2022]
“Attack inception: Compromised supply chain within a supply chain poses new risks.” https://www.microsoft.com/security/blog/2018/07/26/attack-inception-compromised-supply-chain-within-a-supply-chain-poses-new-risks/ · 2022
Closest in time.
[Accessed 16-Mar-2022]
“CWE - CWE-601: URL Redirection to Untrusted Site.” https://cwe.mitre.org/data/definitions/601.html · 2022
Closest in time.
[Accessed 16-Mar-2022]
“A Confusing Dependency.” https://autsoft.net/hu/a-confusing-dependency/ · 2022
Closest in time.
[Accessed 16-Mar-2022]
A. L. Johnson, “Dragonfly: Western energy companies under sabotage threat.” https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=7382dce7-0260-4782-84cc-890971ed3f17&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments , 2014 · 2022
Closest in time.
[Accessed 16-Mar-2022]
“Beware of hacked ISOs if you downloaded Linux Mint on February 20th!.” https://blog.linuxmint.com/?p=2994 · 2022
Closest in time.
[Accessed 16-Mar-2022]
“How to Bury a Major Breach Notification.” https://krebsonsecurity.com/2017/02/how-to-bury-a-major-breach-notification/ · 2022
Closest in time.
[Accessed 16-Mar-2022]
“Supply‑chain attack on cryptocurrency exchange gate.io.” https://www.welivesecurity.com/2018/11/06/supply-chain-attack-cryptocurrency-exchange-gate-io/ · 2022
Closest in time.