The company said it found more evidence of compromise across its customer base. Exposure, which has yet to be defined, poses significant downstream risk.
The attack, which originated at Context.ai, showcases the pitfalls of interconnected cloud applications and SaaS integrations with overly privileged permissions.
The company said a developer tool automatically retrieved a malicious version of the popular open-source library, but insists the integrity of its systems and software were not…
Attackers compromised the open-source security tool and published malicious versions of the software. Mandiant warns the fallout could impact up to 10,000 downstream victims.
The latest executive order pushes Washington to crack down on cyber fraud, but a different mandate eases software security accountability, leaving an inconsistent strategy that keeps the…
Construction on an Oncor electricity power plant by the new Skybox Power Campus data colocation center in North Austin, Texas. Cybersecurity must be table stakes as the data center boom continues, this op-ed argues. (Getty Images)
Light reflects off glass panels on Salesforce Tower through the fog in San Francisco on July 31, 2018. (Carlos Avila Gonzalez/The San Francisco Chronicle via Getty Images)
Ranking member Raja Krishnamoorthi (D-IL) participates in the first hearing of the U.S. House Select Committee on Strategic Competition between the United States and the Chinese Communist Party, in the Cannon House Office Building on February 28, 2023 in Washington, DC. In an exclusive, Rep. Raja Krishnamoorthi, D-Ill., told CyberScoop that policymakers must learn from past mistakes around 5G. (Photo by Kevin Dietsch/Getty Images)