fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

#SupplyChain

27 posts24 participants0 posts today

DATE: April 15, 2025 at 06:00PM
SOURCE: BioWorld MedTech

Direct article link at end of text block below.

Impact of #tariffs on supplies of #semiconductor tough to calculate

t.co/LL9opMvzgj

#medtech #trade #SupplyChain

Here are any URLs found in the article text:

t.co/LL9opMvzgj

#medtech

Articles can be found by scrolling down the page at bioworld.com/topics/85-bioworl .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org
.
NYU Information for Practice puts out 400-500 good quality health-related research posts per week but its too much for many people, so that bot is limited to just subscribers. You can read it or subscribe at @PsychResearchBot
.
Since 1991 The National Psychologist has focused on keeping practicing psychologists current with news, information and items of interest. Check them out for more free articles, resources, and subscription information: nationalpsychologist.com
.
EMAIL DAILY DIGEST OF RSS FEEDS -- SUBSCRIBE:
subscribe-article-digests.clin
.
READ ONLINE: read-the-rss-mega-archive.clin
.
It's primitive... but it works... mostly...
.
-------------------------------------------------

t.coImpact of tariffs on supplies of semiconductor tough to calculateBy Mark McCarty
Continued thread

Wenn es so schöne Fussgängerampeln mit Textansagen gibt, kann man diese Ansagen dann ändern? Das müssen sich Unbekannte im Silicon Valley gedacht haben, bevor sie die Ampelansagen durch angebliche Texte von Tech-Milliardären ersetzten. Die Stadt reagierte und hat die ganze Funktion vorerst deaktiviert.

Mit KI erzeugter Programmcode bezieht sich manchmal auf Module, die es gar nicht gibt. Findige Angreifer haben nun begonnen, derartige Module zu publizieren.
#SupplyChain
dnip.ch/2025/04/15/dnip-briefi

Erstellt mit ChatGPT 4o
Das Netz ist politisch · DNIP Briefing #20: Sitzungsprotokoll mal anders - Das Netz ist politischDie Redaktion präsentiert jeden Dienstag die Geschichten, die sie bewegt, aufgerüttelt oder zum Nachdenken angeregt hat.

Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware

Slow Pisces, a North Korean state-sponsored threat group, is targeting cryptocurrency developers through LinkedIn with malicious coding challenges. The group impersonates recruiters and sends malware disguised as project tasks, infecting systems with RN Loader and RN Stealer. Their campaign uses GitHub repositories containing adapted open-source projects in Python and JavaScript. The malware employs YAML deserialization and EJS rendering to execute arbitrary code from command-and-control servers. Slow Pisces has reportedly stolen over $1 billion from the cryptocurrency sector in 2023, using various methods including fake trading applications and supply chain compromises. The group's operational security is noteworthy, with payloads existing only in memory and deployed selectively.

Pulse ID: 67fd5a2e0a1353fab9d93ea5
Pulse Link: otx.alienvault.com/pulse/67fd5
Pulse Author: AlienVault
Created: 2025-04-14 18:55:42

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

New supply chain attacks called "slopsquatting" in AI coding attempts to leverage AI models tendency to hallucinate non-existent package names.

Research indicates roughly 20% of the sampled Python and JavaScript code samples recommended packages didn't exist.

bleepingcomputer.com/news/secu #slopsquatting #hallucinations #AI #coding #supplychain #python #javascript #cybersecurity

Atomic and Exodus crypto wallets targeted in malicious npm campaign

A malicious npm package named pdf-to-office was discovered targeting cryptocurrency wallets. The package, posing as a PDF to Office converter, injects malicious code into locally installed Atomic and Exodus wallets. This attack modifies legitimate files to redirect crypto funds to the attacker's wallet. The campaign shows persistence, as removing the malicious package doesn't remove the injected code from the wallets. Multiple versions of both wallets were targeted, with the attackers adapting their code accordingly. This incident highlights the growing scope of software supply chain risks, particularly in the cryptocurrency industry, and emphasizes the need for improved monitoring of both source code repositories and locally deployed applications.

Pulse ID: 67fd41f7af4b02a0fd75fb69
Pulse Link: otx.alienvault.com/pulse/67fd4
Pulse Author: AlienVault
Created: 2025-04-14 17:12:23

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

🚨 AI Code Assistants: A Double-Edged Sword? 🚨

AI-powered coding tools are revolutionizing development workflows, but they come with hidden dangers:

🔹 Hallucinated Dependencies: AI suggests packages that don’t exist.
🔹 Slopsquatting Attacks: Malicious actors register these fake packages, leading to potential security breaches.
🔹 Automated Installation Risks: Some AI agents might auto-install these without developer awareness.
🔹 False Legitimacy: AI-generated summaries can falsely validate these malicious packages.

🛡️ Stay Vigilant: Always double-check AI-generated code and dependencies. Trust, but verify.

#AI #CyberSecurity #DevSecOps #SupplyChain #SoftwareDevelopment
theregister.com/2025/04/12/ai_

The Register · LLMs can't stop making up software dependencies and sabotaging everythingBy Thomas Claburn

How Data Analytics is Revolutionizing Supply Chain Optimization

🚚📊 Is your supply chain ready for the future?

Data analytics is becoming a game-changer in supply chain management—helping businesses forecast demand, reduce costs, and respond faster to market changes.

Discover how your supply chain can benefit from analytics! 🔍📦

#SupplyChain #DataAnalytics #BusinessIntelligence #Logistics #Optimization

👉 [apsense.com/article/844786-dat]