As cited
Copy frozen at (site build).
threat intel
When AppSec Scanners Become a Supply Chain Attack Vector
Researchers have identified a new attack vector in which security scanners embedded within software supply chains can be compromised to gain access to downstream targets. The attack exploits the trusted position of these tools to establish a foothold for further exploitation.
Why it matters: Development teams and software vendors using compromised scanners in their CI/CD pipelines face supply chain compromise risk; practitioners should assess whether their scanners themselves are properly secured and validated.
- Source published
- First seen by Cybersecurity Tracker