Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Don’t eat the ChocoPoCs! How vulnerability researchers were repeatedly targeted by trojanised exploits

Summary

A suspicious contribution request led YesWeHack and Sekoia researchers to uncover sophisticated malware targeting the vulnerability research supply chain.

Why it matters

Trojanized proof-of-concept exploits turn the vulnerability-research workflow itself into an attack surface. Researchers should isolate, inspect and verify exploit code before execution.
Published
Collected

original ↗

Related coverage

back