146 - Invisible Threats: The Risks of Automatic Code Execution
カートのアイテムが多すぎます
カートに追加できませんでした。
ウィッシュリストに追加できませんでした。
ほしい物リストの削除に失敗しました。
ポッドキャストのフォローに失敗しました
ポッドキャストのフォロー解除に失敗しました
-
ナレーター:
-
著者:
Send us Fan Mail
We track the thread running through the biggest security stories of the week: automatic execution paths that get trusted too far and monitored too little. We break down what went wrong across legacy servers, the software supply chain, edge devices, and AI platforms, then land on one practical way to reduce risk fast.
• ColdFusion path traversal leading to unauthenticated remote code execution under risky RDS settings
• Legacy exposure driven by forgotten toggles, missing ownership, and incomplete asset inventory
• JS Crambler NPM compromise using real publisher credentials and a cross-platform info stealer
• Attacker pivot from preinstall hooks to imported code that executes at runtime
• ORB relay networks built from compromised routers to hide espionage origins
• AI tooling risks where “small” permissions reach across tenants and managed runtimes
• NPM v12 turning install scripts off by default and winding down weak publisher tokens
• Typosquat payment SDKs and fake aged GitHub repos undermining trust heuristics
All of that is in this week's written issue at InfoSec.watch.
Support the show
Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!