// infrastructure vulnerability

All signals tagged with this topic

Attackers compromised multiple AsyncAPI npm packages in coordinated supply chain raid

Upwind's investigation reveals that threat actors exploited the npm release process itself rather than individual package vulnerabilities. They gained access to legitimate developer credentials and published malicious versions of widely-trusted AsyncAPI libraries that developers would naturally download without suspicion. The compromise targeted established projects with thousands of weekly downloads—core infrastructure that enterprise teams rely on, not marginal risk. Official package repositories lack sufficient verification mechanisms between credential compromise and code publication, making the npm release process an increasingly attractive target for attackers seeking scale.

Exposed Passport Database Highlights ID Verification Infrastructure Gaps

A misconfigured cloud storage bucket exposed nearly a million identity documents. The incident reflects a broader problem: biometric and identity verification vendors operating at the infrastructure layer of digital onboarding often treat security as secondary to deployment speed. Companies handling government-issued credentials apply less rigor than financial services would demand, even as digital identity becomes the gating layer for financial services, hiring platforms, and government access globally. The vulnerability isn't encryption or hacking—it's the proliferation of unvetted third-party identity platforms that enterprises trust without understanding their security posture.