How a Texas student blew the whistle on a rogue AI hacking attempt
MSFT•Why supply-chain attacks worry security researchers
A supply-chain attack is when a piece of software is tampered with in the hope of compromising one or more of its users, and it is widely considered disturbing because, like poison dropped into a city reservoir, it can affect a potentially huge number of people downstream.
Many of the world’s most dramatic hacks were supply-chain attacks, including the NotPetya cyberattack that paralyzed institutions across Ukraine in 2017 and the SolarWinds-focused cyberespionage campaign that gave Russian spies sweeping access to U.S. government networks in 2020.
The consequences of such a compromise “can be extremely serious,” said Piergiorgio Ladisa, a security researcher who specializes in software supply-chain security. Ladisa noted there had been at least one previous attempt by hackers to trick an open-source maintainer into allowing malicious code into their projects.
“Autonomous agents could dramatically increase the scale at which such attempts can be conducted,” he said.




