supply chain attack
Your data can get stolen through a company you've never heard of
Your data can get stolen through a company you've never heard of A company may do everything right. Then a partner falls victim to hackers--and it becomes a headache for us everyday folks. Cybersecurity for businesses involves a lot of jargon unfamiliar to us consumers, and for good reason. Such language generally doesn't apply to our lives. But one concept has begun affecting us everyday users more--supply chain attacks.
A Crypto Scam Targeted a Gay OnlyFans Star. Then His X Feed Was Flooded With 'MAGA Propaganda'
Then His X Feed Was Flooded With'MAGA Propaganda' In recent months hackers have attempted to extort money from porn stars with big followings, in some cases filling their feeds with pro-MAGA and crypto content. Patrick Bewley's X feed was normally filled with posts about leather three-ways and clips of poolhouse erotica . The gay OnlyFans star, known as Daddy Patrick, had decided to get into the adult industry at age 60 and in under two years his followers on X swelled to 132,000. But in April, his feed suddenly became very political --and very MAGA--with posts like " President Trump stuns the World announcing America has more oil than the next two largest Oil economies COMBINED." His account had been hacked.
The FCC Wants to Kill Burner Phones
After WIRED reported last week that Meta's smart glasses app contained code that would enable the company to activate face-recognition features on the devices, the company removed the code this week without commenting on why or whether it plans to add such functionality back into the app later. Another WIRED investigation this week found that xAI's Grok is still hosting sexualized deepfakes, including "nudified" images and videos, of celebrities and at least one prominent US politician. After limiting the release of its new Mythos-class AI model over concerns about its potential impacts on cybersecurity, Anthropic announced a model upgrade for partners in its limited-access group this week and launched a "safe" version of the model to the public with guardrails meant to keep the system from being used to fuel cyberattacks. Meanwhile, the United States Cybersecurity and Infrastructure Security Agency issued a new directive to federal agencies this week in reaction to new AI threats that includes a requirement to fix the most urgent software vulnerabilities in as little as three days. As Europe looks to separate and insulate itself from US Big Tech, WIRED created a timeline that tracks all the ways EU governments, companies, and other organizations are moving away from US tech.
Crypto Guys Bought the Answer to the CIA's Mysterious Kryptos Sculpture
They swear they haven't peeked at the closely guarded secret and that they'll keep the cryptographic competition going. On a blustery March day, the artist Jim Sanborn received visitors at his studio on an isolated island in the Chesapeake Bay. The visitors sat him down in front of a laptop, and he typed in a secret message. They compressed the message using a unique hash function, sent that to the cloud, and wiped the laptop clean. Sanborn hoped that this action would set him free.
Scammers Are Using Your Real Hotel Reservations to Trick You With Spear-Phishing Attacks
Customer data from more than 350 hotels around the world may have been accessed as part of realistic reservation-hijacking scams. Travelers' information and booking details may have been stolen from hundreds of hotels around the world, according to new findings from security researchers. These swiped trip details, such as booking names and reservation information, are then being repurposed by cybercriminals to create highly targeted phishing messages used to steal credit card information. At least 350 hotels, vacation rentals, motels, and guesthouses in 50 different countries have been caught up in so-called reservation hijacking scams, according to an analysis of phishing messages and cybercriminal infrastructure by security company Norton. Researchers say the use of legitimate booking information in phishing messages may increase the chances that someone clicks on a fraudulent link and hands over other sensitive details to criminals.
Cybercriminal Twins Caught After They Forgot to Turn Off Microsoft Teams Recording
Plus: Instructure's Canvas ransomware debacle comes to a close, an alleged dark net market kingpin gets arrested, OpenAI workers fall victim to a supply chain attack, and more. The worst part of your iPhone getting stolen may not be the theft itself. Instead, it's the phishing attacks waged against people in your contacts. New research this week shows that there's a thriving ecosystem for tools that let criminals unlock iPhones and target the phone numbers they find inside. Foxconn, the electronics manufacturing giant known for its role in building iPhones, revealed this week that it recently "suffered a cyberattack."
Leveraging Code Cohesion Analysis to Identify Source Code Supply Chain Attacks
Reuben, Maor, Mendel, Ido, Feldman, Or, Kravchik, Moshe, Guri, Mordehai, Puzis, Rami
Supply chain attacks significantly threaten software security with malicious code injections within legitimate projects. Such attacks are very rare but may have a devastating impact. Detecting spurious code injections using automated tools is further complicated as it often requires deciphering the intention of both the inserted code and its context. In this study, we propose an unsupervised approach for highlighting spurious code injections by quantifying cohesion disruptions in the source code. Using a name-prediction-based cohesion (NPC) metric, we analyze how function cohesion changes when malicious code is introduced compared to natural cohesion fluctuations. An analysis of 54,707 functions over 369 open-source C++ repositories reveals that code injection reduces cohesion and shifts naming patterns toward shorter, less descriptive names compared to genuine function updates. Considering the sporadic nature of real supply-chain attacks, we evaluate the proposed method with extreme test-set imbalance and show that monitoring high-cohesion functions with NPC can effectively detect functions with injected code, achieving a Precision@100 of 36.41% at a 1:1,000 ratio and 12.47% at 1:10,000. These results suggest that automated cohesion measurements, in general, and name-prediction-based cohesion, in particular, may help identify supply chain attacks, improving source code integrity.
An Empirical Study on Using Large Language Models to Analyze Software Supply Chain Security Failures
Singla, Tanmay, Anandayuvaraj, Dharun, Kalu, Kelechi G., Schorlemmer, Taylor R., Davis, James C.
As we increasingly depend on software systems, the consequences of breaches in the software supply chain become more severe. High-profile cyber attacks like those on SolarWinds and ShadowHammer have resulted in significant financial and data losses, underlining the need for stronger cybersecurity. One way to prevent future breaches is by studying past failures. However, traditional methods of analyzing these failures require manually reading and summarizing reports about them. Automated support could reduce costs and allow analysis of more failures. Natural Language Processing (NLP) techniques such as Large Language Models (LLMs) could be leveraged to assist the analysis of failures. In this study, we assessed the ability of Large Language Models (LLMs) to analyze historical software supply chain breaches. We used LLMs to replicate the manual analysis of 69 software supply chain security failures performed by members of the Cloud Native Computing Foundation (CNCF). We developed prompts for LLMs to categorize these by four dimensions: type of compromise, intent, nature, and impact. GPT 3.5s categorizations had an average accuracy of 68% and Bard had an accuracy of 58% over these dimensions. We report that LLMs effectively characterize software supply chain failures when the source articles are detailed enough for consensus among manual analysts, but cannot yet replace human analysts. Future work can improve LLM performance in this context, and study a broader range of articles and failures.
Let's Talk: Top tips for solving supply chain issues - Dynamic Business
In recent years, we've seen how rising costs, disrupted supply chains, and lockdowns can adversely affect businesses of any size. But there are some solutions that, if followed, can reduce your risk and help make turbulent times a little easier. This week on Let's Talk, our experts share their tips that will help you address the risks and prepare your business for any supply chain shocks. "There are several tactics that Australian business leaders can adopt to prepare for and address the aftershocks of shipment delays and stock unavailability. "Rather than relying on the just in time approach, which can be risky when there are supply shortages or shipping delays, the just in case approach is recommended. This approach focuses on forecasting demand to proactively secure sufficient supplies ahead of time. For this to work, a robust business management solution which grants to timely data which provides insight into incoming orders versus available stock is a key requirement. The just in case approach can boost profitability, while preventing wastage. "Having up-to-date industry data like procurement lead times, stock levels and order volumes can allow business owners to manage potential vulnerabilities in the supply chain and optimise efficiencies within. Finance teams can leverage this data allowing them to create more accurate financial forecasting models to save on supply chain costs and inventory management."
EvilModel: Malware that Hides Undetected Inside Deep Learning Models
A team of researchers from the University of California, San Diego, and the University of Illinois has found that it is also possible to hide malware in deep learning neural networks and deliver it to an unsuspecting target, without it being detected by conventional anti-malware software. Not surprisingly, this new work is highlighting the need for better cybersecurity measures to counteract and protect users from the very real possibility of AI-assisted attacks, especially as individuals and businesses become increasingly reliant on AI in their daily activities. In a pre-print paper outlining EvilModel -- the team's ominously named method for embedding malware in deep learning neural networks -- the team discovered that it was possible to infect a deep learning model with malware, and have it fool anti-malware detectors, all without significantly affecting the model's performance. To achieve this, the team used an approach known as steganography, where pieces of data in a system are swapped out for other bits of data that might have a hidden message or function. To hide their sample piece of malware, the team first started by deconstructing the malware into smaller pieces so that each piece measured only 3 bytes -- an insignificant enough size to evade detection.