Categories
podcast

Angry Tech News #29: Supply Chain Advisor

Malicious OSS, Netflix conjecture, A win in the right to repair fight, and yet another Chrome zero-day yawn

Links

node-ipc malicious update
https://www.wired.com/story/developer-altered-open-source-software-to-wipe-files-in-russia/
https://www.zdnet.com/article/corrupted-open-source-software-enters-the-russian-battlefield/
https://github.com/advisories/GHSA-97m3-w2cp-4xx6

Malicious Azure-targeting NPM packages
https://www.zdnet.com/article/malicious-npm-packages-target-azure-developers-to-steal-personal-data/

Netflix offers way to pay more if you share passwords
https://about.netflix.com/en/news/paying-to-share-netflix-outside-your-household

John Deere repair program
https://www.deere.com/en/news/all-news/john-deere-expands-access-to-self-repair-resources/

Yet another critical Chrome vulnerability
https://www.bleepingcomputer.com/news/security/emergency-google-chrome-update-fixes-zero-day-used-in-attacks/

Categories
podcast

Angry Tech News #7: Munition Parser

Argentinian data breach, NPM supply chain attack, Apple as a bad security neighbor, Play store fees dropping, and the return of the 90s encryption ban

Links:

Argentina RENAPER DB breached
https://therecord.media/hacker-steals-government-id-database-for-argentinas-entire-population/
https://techstory.in/argentinas-entire-population-at-risk-hacker-steals-government-id-database/

NPM supply chain attack: UA-Parser-JS lib released with backdoor
https://www.bleepingcomputer.com/news/security/popular-npm-library-hijacked-to-install-password-stealers-miners/
https://blog.sonatype.com/npm-project-used-by-millions-hijacked-in-supply-chain-attack

Apple silently fixing reported bugs without giving credit
https://www.bleepingcomputer.com/news/apple/apple-silently-fixes-ios-zero-day-asks-bug-reporter-to-keep-quiet/

Bringing back the encryption ban – this time “hacking tools”
https://www.bleepingcomputer.com/news/security/us-govt-to-ban-export-of-hacking-tools-to-authoritarian-regimes/
https://public-inspection.federalregister.gov/2021-22774.pdf