Software supply chains are increasingly vulnerable to attacks, as demonstrated by incidents like poisoned VS Code extensions that can compromise thousands of repositories within minutes; organizations can reduce risk through operational hygiene practices including pinning dependencies, using lockfiles, running risky installs in sandboxed environments, implementing signed commits on protected branches, monitoring CI/CD pipelines and package registries, and maintaining vigilance across all security touchpoints.
深度探索
先修知识
- 暂无数据。
后续步骤
- 暂无数据。
深度探索
6000 devs installed malware in 18 minutes本站添加:
It feels like the supply chain for software engineering is at its most vulnerable than it's ever [music] been.
Things like a poisoned VS Code editor extension that was live for 18 minutes getting installed and then leaking thousands of repos would have been much harder before, but AI has made software quite vulnerable. And this is the reality of what's just been happening over the last couple of weeks at large companies [music] like Microsoft. And this is not to defend or blast Microsoft. There's always going to be things that any company or individual can do to reduce the blast radius and have [music] improved security practices. What's more interesting about this is this pattern of increasingly high threat attacks. Like the most recent Shy Halud incident. The latest waves of people stealing [music] maintainer tokens and running inside the actual build systems. But there are still a lot of things that can be done.
You can [music] pin dependencies and try to commit lock files, run risky installs inside of dev containers [music] or sandbox them, try things like signed commits on protected branches, monitor your CI/CD [music] pipeline, your NPM packages, and also just your billing portals. [music] There shouldn't be an assumption that you can avoid every single malicious package because that's just not realistic. There are a lot of preventive measures that you can [music] try to take that I will also link below in the description of this post.
相关推荐
resume fixed instantly 😭 Comment “app”andI’ll sendyou the link #parakeetaipartnership #resumetips
Ritcareer
686 views•2026-05-31
3D Basics in C
HirschDaniel
2K views•2026-06-05
Re: 🗣️📍theprophedu📍2026 GST 103 CLASS (E-EXAM REVISION)
theprophedu
636 views•2026-06-04
Search Algorithms Explained in 60 Seconds! 🤖💨
samarthtuliofficial
218 views•2026-06-01
Making Minecraft Clone with C++ & Raylib
PecaCSLive
686 views•2026-06-04
Instagram accounts got PWNed
EricParker
13K views•2026-06-03
So What's Odin Lang Even Good For
TechOverTea
131 views•2026-06-01
🚀 BCS613C Compiler Design | Module 1 to 5 Schema Evaluation 🔥 | VTU 6th Sem 💯 #VTU #bcs613c #exam
Pranavaa-y4y
104 views•2026-06-02











