@GossiTheDog Yes, since 2017ish, for example
caspicat@infosec.exchange
@caspicat@infosec.exchange
Posts
-
Did I miss that CVEs are allocated for supply chain compromises nowadays? -
info on the github breach appears to only be available on xitter 🙄 , I fished it out for you.@soviut @0xabad1dea Checkmarkx (appsec company!) recently couldn't kick out the attackers for a month, so one of their recommended action to clients was to disable auto update of the Checkmarkx extension in VSCode (which was poisoned)