Timeline of the xz open source attack
A detailed timeline of the multi-year social engineering attack that led to a backdoor in the xz compression library, a major open source supply chain incident.
A detailed timeline of the multi-year social engineering attack that led to a backdoor in the xz compression library, a major open source supply chain incident.
Running Ken Thompson's backdoored compiler from his classic 1983 Turing Award lecture 'Reflections on Trusting Trust' to demonstrate supply chain security risks.
Analysis of a malicious backdoor discovered in the popular bootstrap-sass Ruby gem, its impact, and essential security best practices for developers.