Future supply chain attacks:
1. Publish a fake GHSA
2. Publish a compromised patch release
3. Wait for the CI/CD and automations based on CVEs and GHSAs
New: CISA is weighing a proposal to cut the default remediation time for known-exploited-vulnerabilities (KEVs) down to 3 days from the current 2-3 week timeframe.
If confirmed, more evidence that patch cycles are converging toward zero.
www.reuters.com/legal/litiga...
www.reuters.com
U.S. cybersecurity officials are considering sharply shorter deadlines for fixing critical flaws in government IT systems, amid concerns hackers could exploit them using artificial‑intelligence tools...