
Adrian discusses a coordinated supply chain attack and critical vulnerabilities affecting major platforms.
This episode covers a coordinated supply chain attack on PHP's Packagist repository, mass exploitation of a critical Ghost CMS vulnerability turning websites into malware traps, and the ironic exposure of AWS GovCloud credentials by a CISA contractor's public GitHub repo. Adrian breaks down how attackers are poisoning dependencies upstream, automating large-scale injections, and why even the agencies protecting federal networks aren't immune to basic security mistakes.
Host: Adrian North
Organizations: PHP, Packagist, Ghost CMS, AWS GovCloud, CISA
Explore listener stats, chart rankings, contacts and more on the Signal Check podcast page.