Minacce e avversari · Supply chain
L’abuso di RubyGems espone il registry, non solo i package La vera compromissione è nel control plane del registry. Questo attacco ha colpito le difese anti-abuso di RubyGems stesso, quindi controllare i gem locali manca il punto debole: se il servizio può ancora bloccare registrazioni di massa, upload di junk e creazione ostile di account.
3 fonti · 13 mag
Cronologia Fonti 13 mag Risky Biz News
Risky Bulletin: Damaging worm rips through npm ecosystem
RubyGems disables sign-ups after an attack on staff, Instructure paid the ransom, the Gentlemen ransomware operation gets hacked, and anot [Read More
originale 13 mag SecurityWeek
Hundreds of Malicious Packages Force RubyGems to Suspend Registrations
More than 500 packages were pushed during the attack, but the target appears to have been RubyGems itself rather than users.
originale 12 mag The Hacker News
RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded
RubyGems halted new registrations after a major attack involving hundreds of malicious packages, increasing supply chain risks.
originale Part of the PlainSec briefing for 2026-05-13
Every edition of this story: L’abuso di RubyGems espone il registry, non solo i package
Altro da oggi
Minacce e avversari · Supply chain
L’abuso di RubyGems espone il registry, non solo i package La vera compromissione è nel control plane del registry. Questo attacco ha colpito le difese anti-abuso di RubyGems stesso, quindi controllare i gem locali manca il punto debole: se il servizio può ancora bloccare registrazioni di massa, upload di junk e creazione ostile di account.
3 fonti · 13 mag
Cronologia Fonti 13 mag Risky Biz News
Risky Bulletin: Damaging worm rips through npm ecosystem
RubyGems disables sign-ups after an attack on staff, Instructure paid the ransom, the Gentlemen ransomware operation gets hacked, and anot [Read More
originale 13 mag SecurityWeek
Hundreds of Malicious Packages Force RubyGems to Suspend Registrations
More than 500 packages were pushed during the attack, but the target appears to have been RubyGems itself rather than users.
originale 12 mag The Hacker News
RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded
RubyGems halted new registrations after a major attack involving hundreds of malicious packages, increasing supply chain risks.
originale Part of the PlainSec briefing for 2026-05-13
Every edition of this story: L’abuso di RubyGems espone il registry, non solo i package
Altro da oggi