Ermes Browser Security’s Post

View organization page for Ermes Browser Security, graphic

5,617 followers

🔒 Supply Chain Attack Alert: Polyfill.io Domain Compromise 🔒 In recent days, a significant web supply chain attack has impacted over 100,000 websites. The domain polyfill[.]io, previously used as a CDN to distribute JavaScript libraries, has changed ownership and started distributing malware. As Ermes Browser Security, we immediately took action to protect our clients by blocking access to the malicious domain. Key details: • Thanks to our Browser Security solution, we have been blocking over 20,000 connection attempts to this domain for thousands of Ermes Browser Security users. • We have identified lots of websites that are still fetching scripts and resources form the compromised domain. For more information, you can read the detailed reports here: • Sansec Research on Polyfill Supply Chain Attack (https://lnkd.in/dWd4SUKR) • The Hacker News Report (https://lnkd.in/gCrCEmEV) 🚨 Action Required: 1. Review and update your website’s dependencies to ensure they are not referencing the compromised polyfill[.]io domain. 2. Engage with us directly if you have any concerns about your site’s security. Let's stay vigilant and protect our web environments from such threats. #cybersecurity #browsersecurity #supplychainattack #malware #polyfill

  • No alternative text description for this image
Paolo Carlo Pomi

Group Chief Information Security Officer at Dumarey Group

3mo

Great advice!

To view or add a comment, sign in

Explore topics