Why Open Source Is the Easiest Target for Supply Chain Attacks
Attackers targeting open source dependencies already have all the code they need. Curtis Koenig, Head of Application Security at Gen, explains the fundamental asymmetry and why building quality fixes at speed is the real challenge for defenders. "An attacker can produce very fast, very ugly code that propagates through as an attack. When we're trying to fix something, the challenge we have is we're always trying to build for quality.".