Since this is a supply chain attack on software downloads, I think it's interesting to consider the implications for the security posture of a cloud-native organization. While cloud-native is commonly recognized as less secure (because the cloud provider could be hacked!), there are a few categories of attacks exclusive to onprem software deployments: 1. You misconfigure the onprem software, making it more insecure t…
Misconfigured, insecure AWS configurations are a dime a dozen. Not sure this point tracks.