Assessed Claims
When an incident breaks, the shortage is rarely coverage. It is that nobody reconciles the coverage. These are the specific claims this publication has checked against primary sources, and what each check found.
7 claims assessed · how the ratings work
- The attackers replaced Codecov's IP address in the Bash Uploader
Codecov Bash Uploader Compromise: 60 Days of Silent CI Credential Theft
- The 3CX macOS build server was compromised with the SIMPLESEA backdoor
3CX Supply Chain Attack (CVE-2023-29059): The First Cascading Software Compromise
- Commit timestamps place the xz backdoor author in a UTC+8 country
XZ Utils Supply Chain Backdoor (CVE-2024-3094): A Multi-Year Open Source Compromise
- The 3CX compromise put 600,000 businesses at risk
3CX Supply Chain Attack (CVE-2023-29059): The First Cascading Software Compromise
- The 3CX attackers were linked to the North Korean group APT43
3CX Supply Chain Attack (CVE-2023-29059): The First Cascading Software Compromise
- Codecov attackers breached hundreds of restricted customer networks
Codecov Bash Uploader Compromise: 60 Days of Silent CI Credential Theft
- North Korea was confirmed responsible for the 3CX supply chain attack
3CX Supply Chain Attack (CVE-2023-29059): The First Cascading Software Compromise