Focused open source attacks. Smells like a corporate sponsored action.

https://www.wired.com/story/teampcp-software-supply-chain-attack-spree-github/

109 points · 2 comments · view on lemmy.world

2 Comments

Venator@lemmy.nz · 15 pts · 116d

I don't know that it's corporate sponsored so much as corporate subsidised: via LLMs that cost more to operate than people pay to use them...

Also probably a lot of well intentioned AI code introduced vulnerabilities and bugs, with each bug providing opportunities for a new supply chain attack in the form of a fix...

FarceOfWill@infosec.pub · 4 pts · 116d

The only sponsorship is from corps constantly paying data ransoms