Provenance Fails as npm Supply Chain Attack Hits
CloudSEK reports attackers abused npm trusted publishing to ship GHAPPIER loader, exposing limits of provenance attestations.
3 results for “cloudsek”
CloudSEK reports attackers abused npm trusted publishing to ship GHAPPIER loader, exposing limits of provenance attestations.
CloudSEK reports BigBear 2.0 phishing operation stole over 5,100 Microsoft credentials, hitting IT firms hardest.
CloudSEK details how a Trivy compromise cascaded into LiteLLM, affecting 2,500+ orgs and 434,000 pipelines.