Featured

Picking Lockfiles: Attacking & Defending Your Supply Chain



Published
An advantage of open source software (OSS) development is that it enables contributions from the public, adding new features and improvements. This also makes OSS projects a target of supply chain attacks. We present both an offensive and defensive perspective of an attack technique that hides malicious code in open source contributions and that reduce the likelihood of the modifications being caught during review...

By: Greg Johnson & Dennis Appelt

Full Abstract & Presentation Materials: https://www.blackhat.com/eu-21/briefings/schedule/#picking-lockfiles--attacking--defending-your-supply-chain-24844
Category
Management
Be the first to comment