product1 distinct publisher
The arrayref compromise turned cargo update into the delivery channel
Wiz says a compile-time payload reached builds through a typosquatted dependency, and the attacker yanked every clean arrayref release so the responsible fix resolved to the poisoned one.
Publishers:devops.com
Reality
- Evidence66
- Adoption74
- Hype gap+12
- Incentives62
- Confidence58