11 juillet 2024 | International, Sécurité

60 New Malicious Packages Uncovered in NuGet Supply Chain Attack

Discover how hackers are using sophisticated techniques to inject malware into NuGet packages, targeting developers and compromising software supply c

https://thehackernews.com/2024/07/60-new-malicious-packages-uncovered-in.html

Sur le même sujet

  • Northrop Grumman charges on with XM913 50 mm cannon deliveries to US Army

    8 septembre 2020 | International, Terrestre

    Northrop Grumman charges on with XM913 50 mm cannon deliveries to US Army

    by Ashley Roque Northrop Grumman remains under contract with the US Army to mature a critical component of its ground combat fleet ‒ the XM913 50 mm cannon ‒ even as the service weighs its cannon calibre requirements for the its future Bradley replacement fleet. As of late August the company had delivered four XM913 cannons to the service, with plans to deliver seven more by the end of October, Northrop Grumman spokesman Jarrod Krull told Janes. In addition to these weapons, he noted that the company is anticipating an “imminent order” for 10 additional cannons that would be delivered to the service in 2021 for qualification, testing, and integration activities. “The 50 mm cannon combines Bushmaster chain gun reliability with [a] next-generation effective range that will provide the warfighter with increased stand-off against near peer adversaries,” Krull wrote. The army is working with the company to further develop the cannon, in part, to support its Next-Generation Combat Vehicle (NGCV) portfolio and allow soldiers to fire quicker and reach farther distances. The XM913 cannon can fire two munitions ‒ the XM1204 High Explosive Airburst with Trace (HEAB-T) and XM1203 Armour-Piercing Fin-Stabilized Discarding Sabot with Trace (APFSDS-T) ‒ and is central to the army's Advanced Lethality and Accuracy System for Medium Caliber (ALAS-MC) effort. https://www.janes.com/defence-news/news-detail/northrop-grumman-charges-on-with-xm913-50-mm-cannon-deliveries-to-us-army

  • Production of one of the F-35′s most anticipated bombs has been on hold for almost a year

    15 juin 2020 | International, Aérospatial

    Production of one of the F-35′s most anticipated bombs has been on hold for almost a year

    By: Valerie Insinna WASHINGTON — Deliveries of a new precision-guided bomb under development by Raytheon for the F-35 and other fighter jets have been at a standstill for about a year as the company struggles to correct a technical problem involving a key component. A fix for the issue, which brought production of the Small Diameter Bomb II to a halt in July 2019, could be approved by the government as soon as July, said Air Force spokesman Capt. Jake Bailey in response to questions by Defense News. However, a June report by the Government Accountability Office pointed out that continued technical issues have already caused a delay in fielding the munition, with Raytheon forced to redesign a key component and retrofit all 598 bombs already delivered to the Air Force and Navy. The Small Diameter Bomb II — also known as the GBU-53 StormBreaker — was designed with a tri-mode seeker that includes a millimeter wave radar, imaging infrared and semi-active laser that allow the weapon to engage targets in all weather conditions and environments where visibility is obscured by dust and debris. The Air Force and Navy plan to integrate SDB II with a range of fighter aircraft including the F-15, F/A-18 Super Hornet and F-35 joint strike fighter, but the munition has been mired in development for more than a decade. This latest stoppage in production was prompted by internal audits by Raytheon, which found that the clips used to hold the bomb's fins in place “suffered vibration fatigue over long flight hours,” Bailey said. The clips serve “as the backup fin storage device” used to keep the fins in place in case other components fail, noted Bailey, who added that there have been no incidents during tests involving the SDB II fins inadvertently deploying. However, the GAO wrote that the premature deployment of the fins, which help guide the bomb in flight, could damage the weapon as well as cause a safety hazard for the aircraft carrying it. “While this problem could affect all aircraft carrying the bomb, officials said the greatest impact is to the F-35, because the bomb is carried in the aircraft's internal weapons bay and could cause serious damage if the fins deploy while the bomb is in the bay,” the GAO stated. Raytheon declined to comment on this story, directing questions to the Air Force. Raytheon plans on mitigating the issue with a newly designed clip that reduces the vibration of the fins, and will completely pay for developing the fix and retrofitting it on the bombs that have already been delivered, the GAO said. The Air Force confirmed that testing of the new device has already been completed and is going through final reviews. But while Raytheon and the Air Force had hoped to restart production in April, travel restrictions caused by the ongoing global COVID-19 pandemic contributed to further delays. The government now hopes to approve the fix in July, after which production will restart and the retrofit process for existing bombs will begin. “The fin clip failure is the sole reason production was partially halted; once final government approval is obtained, ‘all up round' production can resume,” Bailey said, using a phrase that describes a fully assembled weapon. The Air Force estimates that retrofits will be completed by August, as Raytheon's supplier has already begun manufacturing the replacement component, which are easily installed on the outside of the weapon. “Until production resumes, the total Lot 3 deliveries remain at 204 of the 312 assets on contract,” Bailey said. All this puts initial operational capability at least a year later than the service's original timeline, which predicted IOC would occur in September 2019. The Air Force declined to name a current estimate for when IOC would be achieved, but said it would happen after a separate milestone known as the “initial fielding decision,” which involves the approval of the head of Air Combat Command and is set for the third quarter of 2020. The issue with SDB II's fins is just one of several technical problems with which Raytheon is grappling. The program completed operational tests in 2019, but hardware and software changes are needed after 11 failures were reported. Two hardware fixes have already been put in place, and eight failures were related to software problems that will be addressed in future updates, the GAO said. The sole outstanding issue involves an anomaly with SDB II's guidance system. Fixing it could require Raytheon to redesign the component and conduct retrofits on all bombs already delivered, according to GAO. A review board of the problem is in the “final stages of analysis,” Bailey said. The Air Force and Raytheon plan to establish whether a replacement component is necessary no later than June 30. Although the weapon has not even been officially fielded, some components are already becoming obsolete. A Raytheon subcontractor that makes circuit cards used in the guidance system is expected to stop producing those components years sooner than anticipated. As a result, that the Defense Department may have to order all circuit cards needed for the program of record before December, according to the GAO. That timeline has now been extended to January 2022, “which provides ample time for program office action before the new deadline,” Bailey said. Despite the bomb's ongoing problems, Raytheon continues to rake in contracts for the program. In February, the Defense Department awarded a $15 million increase to a previous SDB II contract for additional technical support. In September, the company received a $200 million contract for lifecycle support during the bomb's engineering and manufacturing development phase. According to a Raytheon news release, the Navy recently completed the first guided release of SDB II from a F/A-18E/F Super Hornet. https://www.defensenews.com/air/2020/06/12/production-of-one-of-the-f-35s-most-anticipated-bombs-has-been-on-hold-for-almost-a-year

  • France-Parly satisfaite des nouvelles fonctionnalités de l'A400M

    7 septembre 2018 | International, Aérospatial

    France-Parly satisfaite des nouvelles fonctionnalités de l'A400M

    PARIS, 6 septembre (Reuters) - La ministre française de la Défense Florence Parly s'est déclarée jeudi satisfaite des nouvelles fonctionnalités en cours de test sur l'avion de transport militaire A400M d'Airbus. “Nous sommes dans une phase extrêmement positive”, a-t-elle observé lors d'une rencontre avec l'Association des journalistes professionnels de l'aéronautique et de l'espace (AJPAE), disant attendre l'intégralité des fonctionnalités en 2021. Les retards successifs du programme A400M ont conduit les pays clients, comme la France, à réceptionner des appareils n'ayant pas toutes les fonctionnalités contractuelles, comme le largage de parachutistes par les portes latérales, des équipements électroniques de défense et le ravitaillement en vol d'hélicoptères. En mars, Reuters avait révélé que l'armée allemande avait dit dans un rapport confidentiel voir un “risque important” que l'A400M n'ait pas toutes les capacités tactiques requises après 2021, au moment du retrait de sa flotte de C-160 Transall. “Chaque étape que nous passons est une étape qui se franchit avec succès et donc ceci aide chacun à être un peu patient”, a ajouté Florence Parly. L'armée française avait annoncé au printemps la réception de son 14e A400M, avec un objectif de 25 unités en 2025 et une cible de 50 à terme. Le président exécutif d'Airbus Tom Enders a fait état fin juillet d'avancées dans les négociations avec les pays clients de l'A400M pour parvenir à un amendement du contrat d'ici la fin 2018. https://fr.reuters.com/article/frEuroRpt/idFRL5N1VS3VA

Toutes les nouvelles