Telegram Group & Telegram Channel
🚨 Атака Π½Π° PyPI, npm ΠΈ RubyGems: сотни врСдоносных ΠΏΠ°ΠΊΠ΅Ρ‚ΠΎΠ² Π² ΠΎΡ„ΠΈΡ†ΠΈΠ°Π»ΡŒΠ½Ρ‹Ρ… рССстрах

πŸ” Π˜ΡΡΠ»Π΅Π΄ΠΎΠ²Π°Ρ‚Π΅Π»ΠΈ ΠΎΠ±Π½Π°Ρ€ΡƒΠΆΠΈΠ»ΠΈ ΠΌΠ°ΡΡΠΎΠ²ΡƒΡŽ кампанию ΠΏΠΎ Ρ€Π°Π·ΠΌΠ΅Ρ‰Π΅Π½ΠΈΡŽ врСдоносных Π±ΠΈΠ±Π»ΠΈΠΎΡ‚Π΅ΠΊ Π² популярных экосистСмах:

πŸ§ͺ Π§Ρ‚ΠΎ ΠΏΡ€ΠΎΠΈΠ·ΠΎΡˆΠ»ΠΎ:
β€’ На npm ΠΎΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½Ρ‹ Ρ„Π΅ΠΉΠΊΠΎΠ²Ρ‹Π΅ вСрсии Π±ΠΈΠ±Π»ΠΈΠΎΡ‚Π΅ΠΊ Π²Ρ€ΠΎΠ΄Π΅ Hardhat, ΠΊΡ€Π°Π΄ΡƒΡ‰ΠΈΠ΅ ΠΏΡ€ΠΈΠ²Π°Ρ‚Π½Ρ‹Π΅ ΠΊΠ»ΡŽΡ‡ΠΈ ΠΈ .env
β€’ Π’ PyPI появились ΠΊΠ»ΠΎΠ½Ρ‹ requests, urllib3 ΠΈ Π΄Ρ€., с врСдоносными вставками
β€’ Π’ RubyGems β€” Π±ΠΎΠ»Π΅Π΅ 700 ΠΏΠ°ΠΊΠ΅Ρ‚ΠΎΠ², ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡŽΡ‰ΠΈΡ… тайпосквоттинг (`activesupportt`, httpartyy ΠΈ Ρ‚.Π΄.)

🎯 ЦСль β€” Ρ€Π°Π·Ρ€Π°Π±ΠΎΡ‚Ρ‡ΠΈΠΊΠΈ. ΠŸΠ°ΠΊΠ΅Ρ‚Ρ‹ ΡΠΎΠ±ΠΈΡ€Π°ΡŽΡ‚:
– ΠΌΠ½Π΅ΠΌΠΎΠ½ΠΈΠΊΠΈ
– ΠΏΡ€ΠΈΠ²Π°Ρ‚Π½Ρ‹Π΅ ΠΊΠ»ΡŽΡ‡ΠΈ
– ΠΊΠΎΠ½Ρ„ΠΈΠ³ΠΈ AWS/GCP
– ΡΠΈΡΡ‚Π΅ΠΌΠ½ΡƒΡŽ ΠΈΠ½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΡŽ

πŸ›‘ Π§Ρ‚ΠΎ Π΄Π΅Π»Π°Ρ‚ΡŒ:
– ΠŸΡ€ΠΎΠ²Π΅Ρ€ΡΠΉ названия ΠΏΠ°ΠΊΠ΅Ρ‚ΠΎΠ² (тайпосквоттинг β€” Π³Π»Π°Π²Π½Ρ‹ΠΉ ΠΏΡ€ΠΈΡ‘ΠΌ)
– Запускай pip audit, npm audit, bundler audit
– Π˜ΡΠΏΠΎΠ»ΡŒΠ·ΡƒΠΉ Π²ΠΈΡ€Ρ‚ΡƒΠ°Π»ΡŒΠ½Ρ‹Π΅ окруТСния ΠΈ ΠΌΠΈΠ½ΠΈΠΌΡƒΠΌ ΠΏΡ€Π°Π²
– Подпиши зависимости, Π³Π΄Π΅ это Π²ΠΎΠ·ΠΌΠΎΠΆΠ½ΠΎ (Π½Π°ΠΏΡ€ΠΈΠΌΠ΅Ρ€, Ρ‡Π΅Ρ€Π΅Π· Sigstore)

πŸ“Œ ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅



group-telegram.com/pythonl/4852
Create:
Last Update:

🚨 Атака Π½Π° PyPI, npm ΠΈ RubyGems: сотни врСдоносных ΠΏΠ°ΠΊΠ΅Ρ‚ΠΎΠ² Π² ΠΎΡ„ΠΈΡ†ΠΈΠ°Π»ΡŒΠ½Ρ‹Ρ… рССстрах

πŸ” Π˜ΡΡΠ»Π΅Π΄ΠΎΠ²Π°Ρ‚Π΅Π»ΠΈ ΠΎΠ±Π½Π°Ρ€ΡƒΠΆΠΈΠ»ΠΈ ΠΌΠ°ΡΡΠΎΠ²ΡƒΡŽ кампанию ΠΏΠΎ Ρ€Π°Π·ΠΌΠ΅Ρ‰Π΅Π½ΠΈΡŽ врСдоносных Π±ΠΈΠ±Π»ΠΈΠΎΡ‚Π΅ΠΊ Π² популярных экосистСмах:

πŸ§ͺ Π§Ρ‚ΠΎ ΠΏΡ€ΠΎΠΈΠ·ΠΎΡˆΠ»ΠΎ:
β€’ На npm ΠΎΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½Ρ‹ Ρ„Π΅ΠΉΠΊΠΎΠ²Ρ‹Π΅ вСрсии Π±ΠΈΠ±Π»ΠΈΠΎΡ‚Π΅ΠΊ Π²Ρ€ΠΎΠ΄Π΅ Hardhat, ΠΊΡ€Π°Π΄ΡƒΡ‰ΠΈΠ΅ ΠΏΡ€ΠΈΠ²Π°Ρ‚Π½Ρ‹Π΅ ΠΊΠ»ΡŽΡ‡ΠΈ ΠΈ .env
β€’ Π’ PyPI появились ΠΊΠ»ΠΎΠ½Ρ‹ requests, urllib3 ΠΈ Π΄Ρ€., с врСдоносными вставками
β€’ Π’ RubyGems β€” Π±ΠΎΠ»Π΅Π΅ 700 ΠΏΠ°ΠΊΠ΅Ρ‚ΠΎΠ², ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡŽΡ‰ΠΈΡ… тайпосквоттинг (`activesupportt`, httpartyy ΠΈ Ρ‚.Π΄.)

🎯 ЦСль β€” Ρ€Π°Π·Ρ€Π°Π±ΠΎΡ‚Ρ‡ΠΈΠΊΠΈ. ΠŸΠ°ΠΊΠ΅Ρ‚Ρ‹ ΡΠΎΠ±ΠΈΡ€Π°ΡŽΡ‚:
– ΠΌΠ½Π΅ΠΌΠΎΠ½ΠΈΠΊΠΈ
– ΠΏΡ€ΠΈΠ²Π°Ρ‚Π½Ρ‹Π΅ ΠΊΠ»ΡŽΡ‡ΠΈ
– ΠΊΠΎΠ½Ρ„ΠΈΠ³ΠΈ AWS/GCP
– ΡΠΈΡΡ‚Π΅ΠΌΠ½ΡƒΡŽ ΠΈΠ½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΡŽ

πŸ›‘ Π§Ρ‚ΠΎ Π΄Π΅Π»Π°Ρ‚ΡŒ:
– ΠŸΡ€ΠΎΠ²Π΅Ρ€ΡΠΉ названия ΠΏΠ°ΠΊΠ΅Ρ‚ΠΎΠ² (тайпосквоттинг β€” Π³Π»Π°Π²Π½Ρ‹ΠΉ ΠΏΡ€ΠΈΡ‘ΠΌ)
– Запускай pip audit, npm audit, bundler audit
– Π˜ΡΠΏΠΎΠ»ΡŒΠ·ΡƒΠΉ Π²ΠΈΡ€Ρ‚ΡƒΠ°Π»ΡŒΠ½Ρ‹Π΅ окруТСния ΠΈ ΠΌΠΈΠ½ΠΈΠΌΡƒΠΌ ΠΏΡ€Π°Π²
– Подпиши зависимости, Π³Π΄Π΅ это Π²ΠΎΠ·ΠΌΠΎΠΆΠ½ΠΎ (Π½Π°ΠΏΡ€ΠΈΠΌΠ΅Ρ€, Ρ‡Π΅Ρ€Π΅Π· Sigstore)

πŸ“Œ ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅

BY Python/ django




Share with your friend now:
group-telegram.com/pythonl/4852

View MORE
Open in Telegram


Telegram | DID YOU KNOW?

Date: |

Channels are not fully encrypted, end-to-end. All communications on a Telegram channel can be seen by anyone on the channel and are also visible to Telegram. Telegram may be asked by a government to hand over the communications from a channel. Telegram has a history of standing up to Russian government requests for data, but how comfortable you are relying on that history to predict future behavior is up to you. Because Telegram has this data, it may also be stolen by hackers or leaked by an internal employee. The last couple days have exemplified that uncertainty. On Thursday, news emerged that talks in Turkey between the Russia and Ukraine yielded no positive result. But on Friday, Reuters reported that Russian President Vladimir Putin said there had been some β€œpositive shifts” in talks between the two sides. "There is a significant risk of insider threat or hacking of Telegram systems that could expose all of these chats to the Russian government," said Eva Galperin with the Electronic Frontier Foundation, which has called for Telegram to improve its privacy practices. I want a secure messaging app, should I use Telegram? On Feb. 27, however, he admitted from his Russian-language account that "Telegram channels are increasingly becoming a source of unverified information related to Ukrainian events."
from es


Telegram Python/ django
FROM American