logo

Expel Quarterly Threat Report Q3 2024, volume V: Preparing for software supply chain risk

ID: 836959cc-6ea8-52d2-90fa-97ba63553492

STIX ID: report--836959cc-6ea8-52d2-90fa-97ba63553492

Feed Name: Expel Blog

Threat Score
60/100

Date Published: 2024-10-28

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

This Q3 quarterly threat report examines emerging software supply-chain risks and related trends, highlighting attacks such as package revival hijacking and typosquatting of GitHub Actions, notes an increase in infostealer malware (e.g., Lumma), and recommends mitigations including maintaining SBOMs, using dependency-scanning tools, and pinning workflows to commit hashes to reduce supply-chain and workflow compromise risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.