PSA: HEADS UP EVERYONE! Another project noticed they were being targeted with similar social engineering tactics as the xz-utils backdoor attack. Be on the lookout for random people demanding that you add someone new as a maintainer for vague but urgent "reasons". Google their emails, check their GitHub/GitLab histories, see if they are on Mastodon/Reddit/"X"/LinkedIn. If they do not have an internet footprint, they are probably a plant.
https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/
#opensource #opensourcesecurity
Conversation
Notices
-
Embed this notice
postmodern (postmodern@ruby.social)'s status on Tuesday, 16-Apr-2024 16:15:50 JST postmodern