The Rust project warned last week that an ongoing social engineering campaign is targeting Rust-lang team members and the owners of popular crates to hijack developer credentials and deploy malicious packages. The crates.io team and the security response working group… Read More "Rust Team Members and Popular Crate Owners Targeted via Video Calls"
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
French cybersecurity firm CrowdSec has confirmed that approximately 300 private and public repositories were compromised and source code was stolen from them. The company provides open source, crowdsourced threat intelligence, including a lightweight security engine to detect and block attacks… Read More "CrowdSec Confirms Source Code Stolen in Supply Chain Attack"
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Customer engagement platform Brevo fell victim to a supply chain attack that resulted in malicious code being injected into over 100,000 websites. Brevo was initially hacked on September 10, when a threat actor exploited a vulnerability in Brevo’s handling of… Read More "Brevo Supply Chain Attack Injects Malware Into 100,000 Websites"