Supply-Chain Attacks Cluster: 230,000 Advisories, Five Patterns (opens in new tab)
Pulled the full OSV mirror for npm and PyPI — 230,000+ advisories. The malicious-tagged subset clusters into five recurring patterns. None of them are clever. All of them keep working. A note on why two decades of EDR/XDR investment is structurally unable to stop the next event-stream.
Read the original article