GITHUB, PYPI DEPLOY TIME-BASED DEFENSES AGAINST SUPPLY CHAIN ATTACKS
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
GitHub and PyPI have integrated time-based security mechanisms into Dependabot to protect against supply chain attacks. The new defense limits the window of exposure when malicious packages are introduced.
■ MORE FROM THE SECURITY DESK
Hackers compromised a heat-and-power facility in Poland that serves approximately 50,000 residents by exploiting a private APN connection to access its operational technology network.
Mozilla has replaced the GPG signing key used for Firefox and Thunderbird releases following an accidental exposure on GitHub. The security update ensures the integrity of future software releases.
A new attack reveals significant security vulnerabilities in passkey implementations, particularly exposing how Windows-based passkey apps handle authentication differently than other operating systems.
Cisco has disclosed two high-severity vulnerabilities in ClamAV that attackers can exploit to crash the scanning process. Public exploits are already available.