troet.cafe ist Teil eines dezentralisierten sozialen Netzwerks, angetrieben von Mastodon.
Hallo im troet.cafe! Dies ist die derzeit größte deutschsprachige Mastodon Instanz zum tröten, neue Leute kennenlernen, sich auszutauschen und Spaß zu haben.

Verwaltet von:

Serverstatistik:

7,2 Tsd.
aktive Profile

Mehr erfahren

#supplychain

20 Beiträge17 Beteiligte2 Beiträge heute

Typosquatted Go Packages Deliver Malware Loader Targeting Li...

A malicious campaign is targeting the Go ecosystem with typosquatted packages that install hidden loader malware on Linux and macOS systems. The threat actor has published at least seven packages impersonating popular Go libraries, using array-based string obfuscation to hide malicious commands. The packages download and execute remote scripts that install an ELF file named f0eee999, which exhibits minimal initial malicious behavior. The campaign specifically targets UNIX-like environments, placing developers at risk. Multiple domains and fallback infrastructure suggest a persistent and adaptable threat actor. Developers are advised to implement real-time scanning tools, code audits, and careful dependency management to mitigate the risk of supply chain compromises.

Pulse ID: 67efc6e6d18160ba914fc662
Pulse Link: otx.alienvault.com/pulse/67efc
Pulse Author: AlienVault
Created: 2025-04-04 11:47:50

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.
#CyberSecurity#ELF#InfoSec

PoisonSeed Campaign Targets CRM and Bulk Email Providers in Supply Chain Spam Operation

The PoisonSeed campaign is targeting enterprise organizations and individuals outside the cryptocurrency industry by phishing CRM and bulk email provider credentials. The attackers export email lists and send bulk spam from compromised accounts, primarily to support cryptocurrency spam operations. The campaign uses a novel cryptocurrency seed phrase poisoning attack, providing security seed phrases to trick victims into copying them into new cryptocurrency wallets for future compromise. While similarities exist with Scattered Spider and CryptoChameleon groups, PoisonSeed is currently classified separately due to unique characteristics. The campaign has targeted companies like Coinbase, Ledger, Mailchimp, SendGrid, Hubspot, Mailgun, and Zoho, using sophisticated phishing techniques and automated processes to quickly exploit compromised accounts.

Pulse ID: 67ef8546d1d9ef9cd8e91906
Pulse Link: otx.alienvault.com/pulse/67ef8
Pulse Author: AlienVault
Created: 2025-04-04 07:07:50

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

Whoa, this is wild: a supply chain attack using GitHub Actions *nearly* nailed Coinbase. Seriously intense stuff! 🤯

Turns out, all it took was a swiped Personal Access Token (PAT). If you're wondering, think of a PAT as basically the master key to GitHub... get your hands on one, and you can cause some *major* havoc. 🔑

Speaking from my pentesting experience, it's often the tiny details that lead to the biggest breaches. So, definitely double-check those GitHub Actions workflows and *please*, rotate your PATs regularly! Remember, Security by Design isn't just some fancy term – it's absolutely essential. And let's be clear: automated scans are *not* the same as a real penetration test. Sorry, not sorry.

Anyone else run into similar situations? What tools are you folks using to lock down your CI/CD pipelines? Drop your thoughts below!

🧠 BLOCKCHAIN
🔴 Watr Targets Tariffs with Blockchain

🔸 New Web3 startup Watr says it can pre-validate tariffs using blockchain before trades happen.
🔸 Led by ex-Shell and JPMorgan execs, platform is used by top miners & auto firms.
🔸 Now shifting focus from ESG to trade compliance, backed by Avalanche blockchain.
🔸 Could streamline $20T global commodity trade amid tariff hikes.

#Web3#Blockchain#TradeTech

The EU hones in on Central Asia in race for raw materials.

The EU has raised billions for the region to diversify supply chains and reduce dependence on China.

Experts say the idea is to offer competitive deals and build local industry while encouraging sustainable mining.

mediafaro.org/article/20250402

A drilling vehicle in Kazakhstan. | Image: Jens Büttner/dpa/picture alliance
DW · The EU hones in on Central Asia in race for raw materials.Von Anchal Vohra
#EU#Minerals#Mining
Antwortete Jérôme

Bloomberg alerts sent on this:
*CANADA, MEXICO NOT SUBJECT TO RECIPROCAL TARIFFS FOR NOW
*US CONTINUES USMCA EXEMPTION FOR CANADA, MEXICO TARIFFS

BREAKING: Canada gets an exemption from Trump's baseline 10% tariffs, Bloomberg reports. At least for now, the existing tariff exemption for USMCA compliant goods will continue. (It's not immediately clear to me if Canadian autos will still get hit with the 25% tariff on foreign cars)

The list of tarifs announced today, for each country

Canada not listed, so likely 10%.
EDIT: Canada is exempted entirely beside what was announced already in the last few weeks

Unclear if it is the new baseline tariff or the extra on top of what exists already.

(No Alt text on the photos yet)

Average person will be 40% poorer if world warms by 4C
Experts say previous #economic models underestimated impact of #globalheating – as well as likely ‘cascading #supplychain disruptions’
Australian scientists study suggests average per person #GDP across the globe will be reduced by 16% even if warming is kept to 2C above pre-industrial levels. This is a much greater reduction than previous estimates, which found the reduction would be 1.4%.
theguardian.com/environment/20 #climate #climatechange

The Guardian · Average person will be 40% poorer if world warms by 4C, new research showsVon Graham Readfearn

So with an #crazyweirdo in command, that talks about new #tariffs on average once per week if not more often, do you want to rely on products from such a country in your #supplychain ?

Want to buy a billion dollar war plane from the #usa when #weirdoinchief might decide next week that your maintenance contract (these go over 30+ years) is suspended because of your countries #diversity policy? Or because it allows "X" in the sex field in the passport? 6/6

alojapan.com/1232366/semicondu Semiconductor chip fabrication comes to Hokkaido island #hardware #Hokkaido #HokkaidoNews #innovation #news #SupplyChain #北海道 Semiconductor chip fabrication in Northern Japan.A new hands-on government approach boosts tech funding.IBM partners with local startup, backed by Sony & Toyota. The Northernmost island in the Japanese archipelago, Hokkaido, is perhaps best known for its hot springs, cold winters, spider crab delicacies, and ski-ing. B…