Cybercriminals claim they have access to various shipping and logistics company networks, causing what researchers say could be a “precarious situation” for the struggling supply chain sector.
The Lazarus group has been recently observed “building supply-chain attack capabilities” by targeting a legitimate South Korean security software and an IT asset monitoring solution vendor.
Microsoft said that the threat group has used phishing and password-spraying attacks to compromise at least 14 IT service providers this year.
GitHub has eliminated support for passwords for Git operations and now requires the use of a hardware security key or other strong 2FA option.
At Black Hat, Matt Tait of Corellium said the supply chain security problem may get far worse if platform providers don't step in to address it.