Menu

#SupplyChainSecurity

3 posts

Feed·
3 of 3 posts
Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers
🖼️
0

Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers

DEV Community·SnykSec·about 1 month ago
#MyE34yx6

Attackers exploited a GitHub Actions script injection vulnerability to publish a malicious version of the elementary-data Python CLI (v0.23.3), embedding a credential-stealing backdoor that targeted dbt profiles, cloud provider keys, and SSH secrets from…

15s
Read More
How Client-Side Protection & Compliance Detects Real-World Magecart Attacks
📰
0

How Client-Side Protection & Compliance Detects Real-World Magecart Attacks

Akamai·Ziv Eli·about 1 month ago
#LXTv3xAW

In this blog, we will take a look at and break down a recent Magecart attack detected and mitigated by Client-Side Protection & Compliance. The impacted customer operates a large international e-commerce business in which one of its websites was…

15s
Read More