Official Red Hat NPM accounts have been compromised and used to push a malicious worm that spreads from machine to machine, where it pilfers sensitive credentials in hopes of stealing yet more confidential data, researchers said.
The supply-chain attack began Monday and remained active at the time this post went live, according to researchers at security firm Aikido. It’s the result of the threat actor responsible for the hack taking control of @redhat-cloud-services, a legitimate channel in the npm repository that’s reserved for official Red Hat packages. As such, the channel is widely trusted by developers who rely on Red Hat cloud services.
The vicious cycle of today’s supply-chain attacks
It’s unclear precisely how the threat actor took control of the namespace, but it almost certainly involved the compromise of credentials required to access it, possibly through a previous supply-chain attack. More than 30 packages seem to be affected.Read full article
Comments
OpenAI推出‘Trusted Access for Cyber program’,通过向可信网络安全防御者提供先进AI模型,加速漏洞检测与修补进程。该计划旨在应对当前漏洞修补响应迟缓的痛点,利用AI技术提升分析效率,缩短安全风险窗口。行业分析认为,此举推动AI增强防御范式,促进协同安全,但也面临模型可靠性及企业接受度等挑战。未来有望激发创新,助力构建更安全的数字基础设施。