Blog Tamir Ben Ari

Tamir Ben Ari
Tamir Ben Ari

Tamir Ben Ari is a malware researcher at Mend.io specializing in software supply chain. Previously, he held the role of security researcher at Mend.io, which included detailed vulnerability research in open source libraries.
unseen risks of open source dependencies case of an abandoned name e1685538190274

The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name

Mend.io research discovered a threat actor takeover of the name β€˜gemnasium-gitlab-service’, a retired Ruby gem with two million+ downloads.

Read More
Yandex Data Leak Triggers Malicious Package Publication 1

Yandex Data Leak Triggers Malicious Package Publication

Discover how the Yandex data leak triggered malicious package publication, leading to supply chain security risks.

Read More
blog image

Malicious Code Deletes Directories If You Do Not Have a License

Discover how malicious code can delete directories if you don’t have a license. Learn about supply chain security and license compliance.

Read More
Todays Security Tidbit An Encrypted JSON File Containings Malicious Code

Today’s Security Tidbit: An Encrypted JSON File Containing Malicious Code

Discover how encrypted JSON files are being used to hide malicious code. Learn about the latest security findings and how to protect your apps.

Read More
npm Massive Dependency Confusion Attack

Single Author Uploaded 168 Packages to npm as Part of a Massive Dependency Confusion Attack

Discover how a single author uploaded 168 malicious npm packages in a dependency confusion attack. Learn how Mend blocked these threats.

Read More
Blog

New Typosquatting Attack on npm Package ’colors’ Using Cross language Technique Explained

Discover the latest typosquatting attack on the npm package ‘colors’ using a cross-language technique.

Read More
news AWS target

AWS Targeted by a Package Backfill Attack

Discover how AWS was targeted by a malicious package backfill attack, the methods used by attackers, and how to protect against such attacks.

Read More
Automated Software Supply Chain Attacks

Automated Software Supply Chain Attacks: Should You be Worried?

Learn why automated software supply chain attacks are a growing threat. Discover how to protecting your org from malicious NPM packages.

Read More

Subscribe to our Newsletter

Join our subscriber list to get the latest news and updates

Thanks for signing up!Β