🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🕵️ SicherheitslückenBurn Out, Or Fade Away(14.09.2026 um 14:25 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11: Microsoft entfernt WMIC-Tool gegen Ransomware - ad-hoc-news.de(14.09.2026 um 07:58 Uhr)
🕵️ SicherheitslückenMicrosoft schließt Rekordzahl an Sicherheitslücken - techbook(14.09.2026 um 09:00 Uhr)
🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🕵️ SicherheitslückenBurn Out, Or Fade Away(14.09.2026 um 14:25 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11: Microsoft entfernt WMIC-Tool gegen Ransomware - ad-hoc-news.de(14.09.2026 um 07:58 Uhr)
🕵️ SicherheitslückenMicrosoft schließt Rekordzahl an Sicherheitslücken - techbook(14.09.2026 um 09:00 Uhr)

⚠️ Malware / Trojaner / Viren 🕛 vor 1 Monat 2 Min Lesezeit SECURITY-FEED
0

Dependency Confusion Still Works. Here's Why Your Tools Miss It

↗ Quelle (reddit.com)
🗣️ Stimme:

May Microsoft alert dropped 45 malicious npm packages targeting dev environments. 33 in the first wave, 12 more the next day. Dependency confusion. Same attack Alex Birsan pulled off back in 2021.

Still works. Still gets past everything.

Not because it's clever. Because of what your tools actually do.

SCA scanner sees a new package? It's comparing against a database of known bad stuff. A brand new public impostor isn't in that database yet, there's nothing to match against, gets flagged clean, installs without a second look.

Lockfile pinned to the right version? Fine, until someone adds a new dependency, or pins to latest, or a fresh install runs before the lockfile gets committed. That's when the resolver sees your private package name sitting on both a private and public registry, compares versions, picks the highest. Attacker published 9.9.9. Lockfile writes it down as legit on the next run like nothing happened.

Post-build scanning is just forensics at that point. Package already fetched. Install hooks already ran, with whatever access that grants inside the pipeline. You're not catching the attack, you're documenting it after the fact.

What actually stops it: Claim your internal package names on public registries first. Even empty placeholders work. An attacker can't register a name you already own.

Scope your internal packages,

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf reddit.com.
↗ Original-Artikel auf reddit.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
The Gemini desktop app is now available for Windows
1 Quelle
Burn Out, Or Fade Away
1 Quelle
Windows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC