this post was submitted on 10 Jul 2025
6 points (100.0% liked)
cybersecurity
4970 readers
30 users here now
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Community Rules
- Be kind
- Limit promotional activities
- Non-cybersecurity posts should be redirected to other communities within infosec.pub.
Enjoy!
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Someone used a hammer to smash a window and steal stuff. Quick, ban hammers!!!
Getting rid of the tools to exploit vulnerabilities doesn't get rid of the vulnerabilities, and security by obscurity is not security.
Concerning this particular article, perhaps the vulnerability here are not a mallicious software packages, but the management of these software repo's.
Should it be possible to upload a package on a repo with 99% of the same name as one that already exists without some additional checks?