2021 confirmed this trend with more and more hacks.
In 2021, we had the aftermath of the Solarwinds hack, which led to the compromise of thousands of U.S. agencies, Microsoft, FireEye ... :
- Confirmation of Qualys, MalwareBytes, Mime and Palo Alto Networks compromises (2021-02-09 review)
- Confirmation of NASA and FAA compromises (2021-03-09 review)
- "It's not our fault, it's the intern!" (2021-03-09 review)
In 2021, we had the hacks of:
- Stormshield with the leak of the source codes of the SNS and SNI firewalls, as well as the ANSSI putting under observation the qualifications and approvals of the said products (review of 2021-02-09)
- More than 30 000 American administrations with the ProxyLogon vulnerability, affecting Microsoft Exchange, that we will see just after (review of 2021-03-09)
- Many companies using Centreon, a network monitoring tool (reviewed on 2021-03-09)
- Codecov, code analysis tool, used by more than 9,000 open source projects (review of 2021-05-13)
In 2021, as in previous years, we had the deployments of rogue libraries:
- "pm run for your lives" with the release of packages spoofing the names of packages used internally at Apple, Amazon, Yelp, Microsoft, Slack... (review of 2021-03-09)
- More and more malicious libraries at PyPi (reviewed on 2021-12-12)
- Again and again backdoor libraries at npm, with this time the hacking of the maintainer's account (review of 2021-11-09)