Roni Carta: From Bug Bounties to Building a Safer Supply Chain
ID: 0338d69e-09d1-5947-9693-d7c55bc09ffb
STIX ID: report--0338d69e-09d1-5947-9693-d7c55bc09ffb
Feed Name: HackerOne Blog
Threat Score
This article profiles a bug-bounty hunter who uncovered repeating software supply-chain weaknesses across major organizations, and uses several high-impact examples — malicious npm packages shipping obfuscated malware, the GhostAction campaign that exfiltrated thousands of GitHub secrets, and a third-party compromise that facilitated a $1.5 billion crypto rerouting — to argue that third-party components are a systemic security risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
