Supply chain attack on lottie-player: everything you need to know
Supply chain attack in popular lottie-player library compromises websites with malicious Web3 wallet prompts – update or revert the library to avoid the compromised versions.
With a B.S. degree in Computer Science and more than 5 years of experience in offensive security, Danielle has gained substantial expertise in red team operations and penetration testing. Now, as a threat researcher at Wiz, she specializes in network-based attack vector threats and threat intelligence. Over the past year, she has been immersed in developing proactive detection strategies and solutions aiming to efficiently identify and safeguard against threats in large cloud environments.
Supply chain attack in popular lottie-player library compromises websites with malicious Web3 wallet prompts – update or revert the library to avoid the compromised versions.
Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgently.