tech
In 2020, hackers hid malicious code inside a routine software update from the firm SolarWinds, quietly infecting thousands of organizations that trusted the vendor.
A supply chain attack works by compromising a trusted vendor so that malicious code rides along inside something customers already trust, like a routine software update. In the SolarWinds case, attackers slipped tainted code into legitimate updates, which were then automatically installed by thousands of organizations worldwide, giving hackers a foothold inside networks that had no reason to suspect their trusted supplier.
A denial-of-service attack floods a system with traffic to knock it offline, which is a very different goal from quietly infiltrating networks through a trusted update. A brute-force attack simply guesses passwords repeatedly until one works, again unrelated to hiding malware inside legitimate software.
The SolarWinds incident helped popularize the 'software bill of materials,' essentially an ingredient list disclosing every component and dependency inside an application, so organizations can spot risks hidden deep in their software supply chain.
tech
What term describes this scam that uses AI to clone a real person's face or voice?Which kind of file is being phased out here?What is this emerging approach called?What is this Apple feature called?What is this social-engineering trick commonly called?What is this quiet, continuous form of authentication called?What does an AI coding assistant like Copilot mainly do?What everyday task do these AI 'live translation' tools aim to handle?What does a text-to-video AI like Sora generate?What is the main idea behind these 'generative' search answers?What does 'orchestrating' multiple AI agents mean?Starting in 2023, what did rivals like Ford, GM, and Rivian agree to do?Quration — Quration Play