Expel Quarterly Threat Report Q3 2024, volume V: Preparing for software supply chain risk
ID: 836959cc-6ea8-52d2-90fa-97ba63553492
STIX ID: report--836959cc-6ea8-52d2-90fa-97ba63553492
Feed Name: Expel Blog
Threat Score
This Q3 quarterly threat report examines emerging software supply-chain risks and related trends, highlighting attacks such as package revival hijacking and typosquatting of GitHub Actions, notes an increase in infostealer malware (e.g., Lumma), and recommends mitigations including maintaining SBOMs, using dependency-scanning tools, and pinning workflows to commit hashes to reduce supply-chain and workflow compromise risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
