125 place 0

472 避免毒害開源供應鏈的因素

Tech Wire Asia
Sonatype @ Tech Wire Asia · 02/13/2023 03:00 EDT

避免毒害開源供應鏈的因素

多起重大的軟體供應鏈漏洞事件已儼然成為近期焦點新聞,在烏俄衝突爆發之初,node-ipc的開發人員就決定全面禁止俄羅斯境內任何IP位址使用自家程式碼,此舉在不知不覺之中間接影響了許多在該國運作的人道救援與慈善組織。在其他事件當中,開發人員對於自家原始碼充斥在盈利產品之中而感到不滿,開始藉由對自家GitHub投毒攻擊,來吸引使用者與廣大社群對他們缺乏金援現況的關注。 不可否認的是,公開的開發者資源資料庫正遭駭客竊取,他們已完全意識到一個簡單的誤植域名就有可能會將他們改寫的程式碼傳播到全球數千個專案之中。但大多數惡意供應鏈的惡意軟體案例都未被上報 – 可能是因為罄竹難書,開放原始碼軟體供應鏈網路安全供應商Sonatype在一次主動掃描時發現,光是整個npm生態系,就有102,930個惡意或潛在的惡意程式碼案例。一旦整合到開發管道中,被改寫的應用程式將隨即進入產品品質測試、測試、甚至是生產階段。接著,他們就能夠破壞雲端認證、劫持加密貨幣挖礦的處理週期、竊取公司的智慧資產,以及令人心煩的一連串惡意軟體攻擊事件。 因Linux核心初版的部署即引發專有UNIX的垂死掙扎,開發人員社群為大眾利益著想,已發布相關的資源與程式

To see detailed statistics for the news please log in »

Read the original

Add your comment
You must be logged in with Facebook to read and write comments.

A newsletter a day!

You may get 10 most important news around midday in daily newsletter. Press the button and we will send you the most important news only, no spam attached.

or register

LIKE us on Facebook so you won't miss the most important news of the day!

News from the same source
Tech Wire Asia Tech Wire Asia
Silicon Canals
Vishal Singh @ Silicon Canals 1 place · today 02:59 EDT

Stockholm-based Lovable, a platform that enables anyone to create software, announced that it closed a $7.5M (approximately €6.83M) pre-seed funding round. The round was led by Hummingbird and byFounders along with Deepmind angel operators, AI founders, and investors including Mattias Miksche and Bjarke Klinge Staun, Siavash Ghorbani (Shopify), Fredrik Hjelm (Voi), and Creandum co-founder Stefan ... Read more Read more

1,240 fresh

🔮
07.10.2024 ♐︎ Today will be a favorable day for Sagittarius in terms of health and work. You... Read more ›
Business Insider
Erin Liam @ Business Insider 1 place · today 01:45 EDT

Reese Witherspoon says her 'aha moment' in business came after realizing she needed help

"I had four employees, and I couldn't keep the lights on," said Witherspoon, the founder of Hello Sunshine. That was her "aha moment" to seek help. Read more

887 fresh

Business Insider
Matthew Loh @ Business Insider 2 place · 10/06/2024 20:44 EDT

I worked in China's brutal 996 tech culture. I'm relieved they laid me off.

Jack Forsdike, a 28-year-old from the UK, was on a 996 team for several months at a video game developer. He says he'll never go back to that life. Read more

882 fresh

Business Insider
Matthew Loh @ Business Insider 3 place · today 01:21 EDT

Taiwan's president is doubling down on sticking it to Beijing, saying China can't be the 'motherland' because its government is younger

Lai said at a National Day celebration that Taiwan's government was celebrating its 113th birthday, while Beijing's just celebrated its 75th. Read more

650 fresh

Eurogamer.net
Vikki Blake @ Eurogamer.net 1 place · 10/06/2024 10:37 EDT

Silent Hill 2 Remake Wikipedia page locked after salty fans try to rewrite its critically-acclaimed reception

Wikipedia has had to lock down the Silent Hill 2 Remake page after repeated vandalism from editors who refuse to accept that the remake of Konami's seminal horror game released to critical acclaim earlier this week. Read more Read more

584

Business Insider
Lloyd Lee @ Business Insider · 10/06/2024 20:53 EDT

Mark Zuckerberg just turned Porsche's minivan concept into a reality. Sort of.

Meta CEO Mark Zuckerberg, who has been undergoing a style evolution, just showed off a Porsche Cayenne that was retrofitted into a minivan. Read more

550 fresh

Digital Trends
Trevor Mogg @ Digital Trends 1 place · today 02:35 EDT

An ace photographer is about to leave the ISS. Here are his best shots

NASA astronaut Matthew Dominick has been sharing some awesome photos and videos taken during his first visit to the International Space Station. Read more

311 fresh

GSMArena.com
GSMArena.com 1 place · today 02:47 EDT

Infinix's ultra-thin phone is called Hot 50 Pro+, specs revealed

Infinix is expected to launch a phone with a 6 mm-thick body based on the Hot 50 5G design. Today, a new leak shed more light on the device. According to Passionategeekz, the phone is called Infinix Hot 50 Pro+ and measures 6.8 mm. It will be limited to LTE connectivity, as it will have a Helio G100 chipset. Infinix Hot 50 Pro+ retail box • Features It appears that... Read more

258 fresh

MacRumors
Tim Hardwick @ MacRumors 1 place · 10/06/2024 09:18 EDT

Apple to Release iOS 18.1 With Apple Intelligence on October 28

Apple intends to launch iOS 18.1 with the first set of much-anticipated Apple Intelligence features on October 28, according to Bloomberg's Mark Gurman. Writing in the latest edition of his Power On newsletter, Gurman says the release date is arriving this month a later than initially expected, as Apple is reportedly taking extra time to ensure a smooth rollout and prepare its AI cloud servers for the increased traffic. The... Read more

256

Gizmodo
Justin Carter @ Gizmodo 1 place · 10/06/2024 14:50 EDT

Hearing Tom Hardy Rap as Venom is So Weird and So Good

Yet again, Hardy uses himself to make a great case for why these Venom movies have been such fun, flaws and all. Read more

248

MacRumors
Joe Rossignol @ MacRumors 2 place · 10/06/2024 21:10 EDT

Alleged M4 MacBook Pro Unboxing Video Reveals These Four Upgrades

An alleged unboxing video for an unannounced 14-inch MacBook Pro with the M4 chip was uploaded to YouTube today by Russian channel Wylsacom. The video was later linked to on social media platform X by Bloomberg's Mark Gurman. It is possible that this is the same MacBook Pro box shown in photos that were shared by leaker ShrimpApplePro in late September, as he claimed that this MacBook Pro unit was... Read more

217 fresh

Business Insider
Katie Balevic @ Business Insider · 10/06/2024 21:14 EDT

Both Democrats and Republicans in North Carolina say misinformation is complicating Hurricane Helene relief efforts

Donald Trump and others have shared false claims about the federal hurricane response. Officials say it's making recovery harder. Read more

214 fresh

TechRadar
TechRadar 2 place · today 02:35 EDT

Deepfake regulation: A double-edged sword?

What legal protection currently exists around deepfake technologies, and where are businesses at risk? Read more

199 fresh

Business Insider
Mikhaila Friel @ Business Insider · 10/06/2024 06:40 EDT

$63 million Royal New Zealand Navy ship capsizes and sinks off Samoa

The HMNZS Manawanui ran aground on Saturday night before capsizing on Sunday morning. All 75 people on board the vessel were rescued. Read more

177

Gizmodo
Justin Carter @ Gizmodo 2 place · 10/06/2024 16:00 EDT

Josh Hutcherson Teases a Bigger, Scarier Five Nights at Freddy’s 2

Blumhouse's sequel is bringing new animatronics, a larger world, and proper frights along for the ride in 2025. Read more

170

The most popular news from the same source for the last week
Tech Wire Asia Tech Wire Asia
Tech Wire Asia
Verizon @ Tech Wire Asia 1 place · 10/01/2024 01:05 EDT

Be a leader in AI ethics to be a leader in AI

Rushing in to build your first genAI application without establishing a Responsible AI council to limit bias, raise fairness, and guide your red team in vulnerability testing virtually guarantees higher risk profiles from state actors and for-profit hackers. Read more

0

Tech Wire Asia
Muhammad Zulhusni @ Tech Wire Asia 1 place · 10/02/2024 03:44 EDT

How big data and AI are transforming India’s business landscape

Is the buzz phrase of yesteryear, ‘big data’ making a resurgence, or has the concept simply been underappreciated all along? The rise of AI systems has underscored the vital role data plays in modern businesses, pushing many organisations to finally capitalise on the data they generate daily. Data has always been important, but with AI’s... Read more » Read more

0

Tech Wire Asia
Joe Green @ Tech Wire Asia 2 place · 10/03/2024 07:08 EDT

Meta takes action in Australia after scam losses

Scams on Facebook and Meta target Australians. Meta announces FIRE to combat the problem. AI used to fake ‘celebrity’-promoted schemes. According to the Australian Competition & Consumer Commission, scams on Meta are costing its citizens in the region of AUS$93.5 million (£48.8m, US$64m) per year. Meta has responded with a new initiative it calls FIRE... Read more » Read more

0

Tech Wire Asia
Muhammad Zulhusni @ Tech Wire Asia 1 place · 10/03/2024 19:52 EDT

AI’s growing influence: How election integrity is at risk worldwide

AI is disrupting the 2024 US election, and worldwide. Regulation slow, leaving elections vulnerable to manipulation. For several years now, AI has disrupted the public’s ability to trust what it sees, hears, and reads. A noteworthy example is the Republican National Committee’s recent release of an AI-generated ad depicting an imagined nightmarish future in which... Read more » Read more

0

Most popular sources

  • You see 414 news out of 414.
  • Sources 63 out of 63.
Business Insider 36% 13
Eurogamer.net 15% 1
MacRumors 9% 9
Gizmodo 9% 18
Tom's Hardware 6% 1
View sources »

LIKE us on Facebook so you won't miss the most important news of the day!

07.10.2024 04:19
Last update: 04:11 EDT.
News rating updated: 11:11.

What is Times42?

Times42 brings you the most popular news from tech news portals in real-time chart.
Read about us in FAQ section.


Times42 © 2024