April 29, 2024, 5:06 a.m. | Kaaviya Ragupathy

Cyber Security News cybersecuritynews.com

Researchers discovered a vulnerability in an archived Apache project, highlighting the risk of using outdated third-party dependencies, where attackers can exploit the way package managers prioritize public repositories to install a malicious package with the same name as a legitimate private dependency.  The vulnerability is especially concerning for archived projects, as they likely won’t receive […]


The post Vulnerability in Apache Project  Let Hackers Launch Supply Chain Attacks appeared first on Cyber Security News.

apache attackers attacks can cyber security dependencies dependency exploit hackers install launch malicious managers name package package managers party prioritize private project projects public repositories researchers risk supply supply chain supply chain attacks third third-party vulnerability

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Consultant/Senior Consultant – Categoria Protetta L. 68/99

@ BIP | Italy

SoC Security Architect, Platform Architecture

@ Apple | San Diego, California, United States

Cloud Engineer II- SOC Analyst

@ Insight Enterprises, Inc. | Gurugram Gurgaon HR, IN