None
EN
Amazon uncovers broad North Korean hacking campaign against open-source software
['David Dimolfetta']
Nextgov/FCW - All Content
In each incident, the hackers tricked a trusted software maintainer and used the access to publish an update containing malicious code, according to Amazon.
Open-source software — code that can be freely inspected, modified and reused — underpins operating systems, web servers, encryption tools and many of the applications businesses rely on daily all over the world.
AI is also making malicious software harder to spot, the blog warned.
Concerns about open-source software security have increasingly drawn attention in Washington.
Last August, Nextgov/FCW first reported that an employee of the Russian technology company Yandex was the sole maintainer of a widely used open-source tool embedded in at least 30 pre-built software packages available to the Defense Department.