Linux kernel Rust adoption is now permanent after memory safety bugs drove an estimated 80 percent of kernel CVEs, Greg Kroah ...
Hackers faked Rust developer David Tolnay's identity to poison the arrayref crate; Wiz links the attack's infrastructure to ...
The attack did not require a downstream vulnerability. Simply pulling in a tainted dependency and running a Cargo build was ...
Cargo, Rust's package manager, runs build scripts during compilation. This allowed proc-macro1 to identify the operating ...
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain ...
North Korean hackers compromised the popular arrayref package in a supply chain attack targeting the Rust ecosystem.
Rust’s security team has disclosed a supply-chain attack involving a malicious arrayref 0.3.10 release and several related ...
Researchers found significant infrastructure overlap between the attack on three Rust crates and recent North Korea-linked ...
The attack involved injecting a dependency on a malicious package, proc-macro1, which impersonated the popular proc-macro2 ...
A major software supply chain attack has struck the Rust ecosystem after threat actors hijacked widely used crates and ...
Rust deletes malicious releases of three crates after a proc-macro1 build script downloaded and ran a remote payload during ...
Wiz says the supply chain attack that poisoned arrayref, a Rust package present in roughly three-quarters of environments ...