2026-08-20 18:40:54
If you are developing in #Rustlang then you should check this post: #cybersecurity #infosec #supplychain #supplychainattack
If you are developing in #Rustlang then you should check this post: #cybersecurity #infosec #supplychain #supplychainattack
RE: #Supplychain attack on #NPM, particularly the #Cacheable and #Keyv ecosystems. Combine the list of affected packages published by @… with those by Wiz and Ox Security for a full picture:
https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack
https://www.ox.security/blog/a-new-infostealer-worm-hits-npm-affecting-keyv-and-cacheable/
This afternoon a couple of my CI/CD pipelines broke because a user deleted all their their public repositories from #Github .
I suppose many people are starting to be fed up with all what's going on with big companies stealing our code to train their #LLMs, or maybe it's something else... who knows. It's not like we have a single reason to be discontent with Github / Microsoft.
Anyway... I started reviewing all my projects to ensure that I mirror all my critical dependencies so I don't suffer the same problem again.
#CICD #AI #GenerativeAI #SupplyChain