Microsoft, Apple, Netflix, Tesla and 31 other companies’ internal systems were discovered with security vulnerability- Technology News, Firstpost


A security researcher recently discovered a vulnerability that let him access the internal system of 35 companies – which includes tech giants like Microsoft, Apple, Netflix, Tesla, Uber and PayPal – in a novel software supply chain attack. For the attack, the researcher uploaded malware to open source repositories including PyPI, npm, and RubyGems, which were then automatically distributed downstream into the companies’ internal applications. The particular supply chain attack leverages a unique design flaw of the open-source ecosystems – called dependency confusion – and it needs no action by the victim, who automatically receive the malicious packages.

The report on the vulnerability discovered by the researcher, Alex Birsan, was first reported by Bleeping Computer.

Birsan made use of DNS to exfiltrate the data to bypass detection.

 Microsoft, Apple, Netflix, Tesla and 31 other companies internal systems were discovered with security vulnerability

Representational Image

Using this technique, Birsan executed a successful supply chain attack against Microsoft, Apple, PayPal, Shopify, Netflix, Tesla, Yelp, and Uber simply by publishing public packages using the same name as the company’s internal ones.

 

“I believe dependency confusion is quite different from typosquatting or brandjacking, as it does not necessarily require any sort of manual input from the victim…Rather, vulnerabilities or design flaws in automated build or installation tools may cause public dependencies to be mistaken for internal dependencies with the exact same name,” Birsan said.

The researcher earned over $130,000 in bug bounties for his ethical research. Microsoft awarded him their highest bug bounty of $40,000. PayPal has disclosed that it will be awarding Birsan a $30,000 bounty amount. Another $30,000 reward came from Apple.

Birsan added that Shopify awarded a $30,000 bug bounty for finding the issue.

Tesla and other companies also rewarded him with their specific bounty programs.

{n.callMethod? n.callMethod.apply(n,arguments):n.queue.push(arguments)}

; if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0'; n.queue=[];t=b.createElement(e);t.async=!0; t.src=v;s=b.getElementsByTagName(e)[0]; s.parentNode.insertBefore(t,s)}(window,document,'script', 'https://connect.facebook.net/en_US/fbevents.js'); fbq('init', '259288058299626'); fbq('track', 'PageView');



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

Releated

Bored of Default Signal Stickers? Here’s How You Can Download and Create More Stickers

Easiest Ways to Download and Create Signal Stickers

One of the most popular features of WhatsApp is the ability to send stickers. If you have migrated to Signal have after WhatsApp’s privacy policy changes, you might have been taken aback by the sparsity of default sticker packs. So here’s a quick guide to downloading some extra stickers and even creating some of your […]

How to Use Signal on Your Laptop or PC

How to Use Signal on Your Laptop or PC

Wondering how to use Signal on your laptop or PC? If you have a Signal account, the popular messaging app will let you sync your account between your phone and your laptop or PC with a few easy steps. Signal is increasingly becoming popular as an instant messaging alternative to WhatsApp. It lets you send […]

%d bloggers like this: