logo

Roni Carta: From Bug Bounties to Building a Safer Supply Chain

ID: 0338d69e-09d1-5947-9693-d7c55bc09ffb

STIX ID: report--0338d69e-09d1-5947-9693-d7c55bc09ffb

Feed Name: HackerOne Blog

Threat Score
78/100

Date Published: 2026-01-29

Date Updated: 2026-06-12

...
...

This article profiles a bug-bounty hunter who uncovered repeating software supply-chain weaknesses across major organizations, and uses several high-impact examples — malicious npm packages shipping obfuscated malware, the GhostAction campaign that exfiltrated thousands of GitHub secrets, and a third-party compromise that facilitated a $1.5 billion crypto rerouting — to argue that third-party components are a systemic security risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.