MavenGate Attack Could Let Hackers Hijack Java and Android via Abandoned Libraries
ID: 3a3bf218-8283-59d0-8f92-aa3b22edbdf7
STIX ID: report--3a3bf218-8283-59d0-8f92-aa3b22edbdf7
Feed Name: The Hacker News
Threat Score
Oversecured disclosed "MavenGate", a supply-chain attack that leverages ownership of expired reversed domains and vulnerable repository groupId management to hijack Maven/Gradle dependencies and inject malicious code into Java and Android builds; a proof-of-concept showed 6,170 of 33,938 domains were vulnerable, and Sonatype has applied mitigations and improved validation procedures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
