-
-
Notifications
You must be signed in to change notification settings - Fork 1k
Open
Labels
2021Relates to 202 T10Relates to 202 T10
Description
Hi there,
I was thinking, for the next edition of the OWASP (2025?) a good example of Supply Chain attack could be the polyfill.io incident.
It's a good example of why not to trust 3rd party CDNs, especially considering how widespread it got, affecting over 100k websites across the world.
And it was the result of a popular domain expiring and being acquired by a malicious party.
A good place to place this would be in the "Software and Data Integrity Failures" chapter, probably together with (or in lieu of) the SolarWinds Orion attack:
Top10/2021/docs/en/A08_2021-Software_and_Data_Integrity_Failures.md
Lines 70 to 71 in 90859c5
| around 100 or so were affected. This is one of the most far-reaching and | |
| most significant breaches of this nature in history. |
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
2021Relates to 202 T10Relates to 202 T10