Dec. 20, 2022, 10:52 p.m. | SC Staff

SC Magazine feed for Risk Management www.scmagazine.com

SentinelOne SDK-impersonating PyPi package leveraged in supply chain attack SecurityWeek reports that a malicious PyPi package masquerading as a SentinelOne software development kit is being used in a new supply chain attack aimed at distributing a backdoor code for data theft.

attack data security impersonating package pypi pypi package sdk sentinelone supply supply chain supply chain attack third party risk

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Consultant

@ Auckland Council | Central Auckland, NZ, 1010

Security Engineer, Threat Detection

@ Stripe | Remote, US

DevSecOps Engineer (Remote in Europe)

@ CloudTalk | Prague, Prague, Czechia - Remote

Security Architect

@ Valeo Foods | Dublin, Ireland

Security Specialist - IoT & OT

@ Wallbox | Barcelona, Catalonia, Spain