Supply Chain Attacks Are Getting Smarter While Ransomware Groups Adapt to Shrinking Profits
Supply Chain Attacks Are Getting Smarter While Ransomware Groups Adapt to Shrinking Profits
This week brought some sobering reminders about how creative attackers are getting with their methods. Between a sophisticated supply chain campaign hitting developer tools and ransomware groups pivoting their tactics due to declining profits, it’s clear that threat actors are adapting faster than many of us would like.
GlassWorm Returns with a Vengeance
The GlassWorm supply-chain campaign is back, and this time they’ve cast a much wider net. We’re talking about a coordinated attack that hit over 400 packages and repositories across GitHub, npm, and even VSCode/OpenVSX extensions.