Sure, you can double‑check package names, stick to trusted maintainers, and install only from reputable sources. But even if you play everything perfectly, what happens when the infrastructure itself is what gets pwned?
This research goes past the packages themselves and straight into the machinery underneath: exploiting the registry services, CDNs and proxie that every build quietly depends on. Once we treated those systems as the real attack surface, things got interesting fast.
This talk walks through how we uncovered critical vulnerabilities across package distribution infrastructure of JavaScript, Julia, Go, .NET, Lua, and more — bugs that enabled account takeover, package hijacks, server-side RCE, and other ecosystem‑level compromises quietly embedded in the infrastructure. Even when developers do everything right, the systems delivering their code can still be the weak link.
The problem isn't always just your dependencies; it's sometimes the systems that ship them. This is our journey into breaking (and ultimately helping secure) the foundations of modern software distribution.
Tsi-Lin Ng | Security Researcher, DEVCORE
https://ift.tt/Z5EBAl2
source https://www.youtube.com/watch?v=TPpHyYv6SqU
Subscribe to:
Post Comments (Atom)
-
WeChat, with over 1.2 billion monthly active users, stands as the most popular messaging and social media platform in China and third global...
-
Unmasking State-Sponsored Mobile Surveillance Malware from Russia, China, and North Korea – Threat Actors, Tactics, and Defense Strategies S...
No comments:
Post a Comment