<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Visual Studio Marketplace Archivi - Webbare</title>
	<atom:link href="https://www.webbare.it/tag/visual-studio-marketplace/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.webbare.it/tag/visual-studio-marketplace/</link>
	<description>Easy choise, easy way!</description>
	<lastBuildDate>Wed, 11 Jan 2023 13:58:39 +0000</lastBuildDate>
	<language>it-IT</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://www.webbare.it/wp-content/uploads/2020/02/jira-logo-scaled.png</url>
	<title>Visual Studio Marketplace Archivi - Webbare</title>
	<link>https://www.webbare.it/tag/visual-studio-marketplace/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Visual Studio Marketplace è l&#8217;ultima frontiera di attacco alla supply chain</title>
		<link>https://www.webbare.it/2023-01-visual-studio-marketplace-hacker/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=visual-studio-marketplace-hacker</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Wed, 11 Jan 2023 13:58:02 +0000</pubDate>
				<category><![CDATA[Dev]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Web Developer]]></category>
		<category><![CDATA[Web Marketing]]></category>
		<category><![CDATA[Aqua Security]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[Supply Chain]]></category>
		<category><![CDATA[Visual Studio Marketplace]]></category>
		<guid isPermaLink="false">https://www.webbare.it/?p=2067</guid>

					<description><![CDATA[<p>L'articolo <a href="https://www.webbare.it/2023-01-visual-studio-marketplace-hacker/">Visual Studio Marketplace è l&#8217;ultima frontiera di attacco alla supply chain</a> proviene da <a href="https://www.webbare.it">Webbare</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper" id="wpb-content-root"><div id="vc_row-6a9b31bfbedd5" class="vc_row wpb_row vc_row-fluid thegem-custom-6a9b31bfbedad4469"><div class="wpb_column vc_column_container vc_col-sm-12 thegem-custom-6a9b31bfcacca7769" ><div class="vc_column-inner thegem-custom-inner-6a9b31bfcacdc "><div class="wpb_wrapper thegem-custom-6a9b31bfcacca7769">
	
		<div class="wpb_text_column wpb_content_element  thegem-vc-text thegem-custom-6a9b31bfcb5454531"  >
			<div class="wpb_wrapper">
				<p>I ricercatori di <strong>Aqua Security</strong> hanno scoperto che gli hacker utilizzano <strong>Visual Studio Marketplace</strong> per condurre attacchi alla supply chain.</p>
<p>In un nuovo rapporto, i ricercatori hanno scoperto che gli aggressori potrebbero impersonare le popolari estensioni <strong>VS Code</strong> per indurre gli sviluppatori a scaricare versioni dannose.</p>
<p>VS Code è l&#8217;<strong>IDE</strong> più popolare, con circa il 74,48% degli sviluppatori che lo utilizza. La vasta gamma di estensioni disponibili per VS Code è in parte ciò che ne determina la popolarità.</p>
<p>Ecco alcune delle estensioni VS Code più popolari:</p>

			</div>
			<style>@media screen and (max-width: 1023px) {.thegem-vc-text.thegem-custom-6a9b31bfcb5454531{display: block!important;}}@media screen and (max-width: 767px) {.thegem-vc-text.thegem-custom-6a9b31bfcb5454531{display: block!important;}}@media screen and (max-width: 1023px) {.thegem-vc-text.thegem-custom-6a9b31bfcb5454531{position: relative !important;}}@media screen and (max-width: 767px) {.thegem-vc-text.thegem-custom-6a9b31bfcb5454531{position: relative !important;}}</style>
		</div>
	

	
	<div  class="wpb_single_image wpb_content_element vc_align_center" >
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper  "><img width="729" height="456" src="https://www.webbare.it/wp-content/uploads/2023/01/Schermata-2023-01-11-alle-14.54.12.png" class="vc_single_image-img attachment-large" alt="" title="Schermata 2023-01-11 alle 14.54.12" srcset="https://www.webbare.it/wp-content/uploads/2023/01/Schermata-2023-01-11-alle-14.54.12.png 729w, https://www.webbare.it/wp-content/uploads/2023/01/Schermata-2023-01-11-alle-14.54.12-300x188.png 300w" sizes="(max-width: 729px) 100vw, 729px" /></div>
		</figure>
	</div>
	
<div class="vc_empty_space"   style="height: 32px"><span class="vc_empty_space_inner"></span></div>
	
		<div class="wpb_text_column wpb_content_element  thegem-vc-text thegem-custom-6a9b31bfcd0b88726"  >
			<div class="wpb_wrapper">
				<p><em>&#8220;È una sfida anche per gli sviluppatori attenti alla sicurezza distinguere tra estensioni dannose e benigne&#8221;</em>, spiega Ilay Goldman, Security Researcher presso <strong>Aqua Security.</strong></p>
<p><em>&#8220;Se consideri che chiunque può creare un utente anche con un&#8217;e-mail temporanea, la verità è che chiunque può pubblicare un&#8217;estensione che potrebbe essere elencata nel Marketplace.&#8221;</em></p>
<p>Aqua Security ha caricato un proof of concept che si spaccia per un&#8217;estensione legittima:</p>

			</div>
			<style>@media screen and (max-width: 1023px) {.thegem-vc-text.thegem-custom-6a9b31bfcd0b88726{display: block!important;}}@media screen and (max-width: 767px) {.thegem-vc-text.thegem-custom-6a9b31bfcd0b88726{display: block!important;}}@media screen and (max-width: 1023px) {.thegem-vc-text.thegem-custom-6a9b31bfcd0b88726{position: relative !important;}}@media screen and (max-width: 767px) {.thegem-vc-text.thegem-custom-6a9b31bfcd0b88726{position: relative !important;}}</style>
		</div>
	
<div class="vc_empty_space"   style="height: 32px"><span class="vc_empty_space_inner"></span></div>
	
	<div  class="wpb_single_image wpb_content_element vc_align_center" >
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper  "><img width="718" height="216" src="https://www.webbare.it/wp-content/uploads/2023/01/Schermata-2023-01-11-alle-14.57.16.png" class="vc_single_image-img attachment-large" alt="" title="Schermata 2023-01-11 alle 14.57.16" srcset="https://www.webbare.it/wp-content/uploads/2023/01/Schermata-2023-01-11-alle-14.57.16.png 718w, https://www.webbare.it/wp-content/uploads/2023/01/Schermata-2023-01-11-alle-14.57.16-300x90.png 300w" sizes="(max-width: 718px) 100vw, 718px" /></div>
		</figure>
	</div>
	
<div class="vc_empty_space"   style="height: 32px"><span class="vc_empty_space_inner"></span></div>
	
		<div class="wpb_text_column wpb_content_element  thegem-vc-text thegem-custom-6a9b31bfce42e2117"  >
			<div class="wpb_wrapper">
				<p>Illegittima:</p>

			</div>
			<style>@media screen and (max-width: 1023px) {.thegem-vc-text.thegem-custom-6a9b31bfce42e2117{display: block!important;}}@media screen and (max-width: 767px) {.thegem-vc-text.thegem-custom-6a9b31bfce42e2117{display: block!important;}}@media screen and (max-width: 1023px) {.thegem-vc-text.thegem-custom-6a9b31bfce42e2117{position: relative !important;}}@media screen and (max-width: 767px) {.thegem-vc-text.thegem-custom-6a9b31bfce42e2117{position: relative !important;}}</style>
		</div>
	
<div class="vc_empty_space"   style="height: 32px"><span class="vc_empty_space_inner"></span></div>
	
	<div  class="wpb_single_image wpb_content_element vc_align_center" >
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper  "><img width="714" height="219" src="https://www.webbare.it/wp-content/uploads/2023/01/Schermata-2023-01-11-alle-14.57.26.png" class="vc_single_image-img attachment-large" alt="" title="Schermata 2023-01-11 alle 14.57.26" srcset="https://www.webbare.it/wp-content/uploads/2023/01/Schermata-2023-01-11-alle-14.57.26.png 714w, https://www.webbare.it/wp-content/uploads/2023/01/Schermata-2023-01-11-alle-14.57.26-300x92.png 300w" sizes="(max-width: 714px) 100vw, 714px" /></div>
		</figure>
	</div>
	
<div class="vc_empty_space"   style="height: 32px"><span class="vc_empty_space_inner"></span></div>
	
		<div class="wpb_text_column wpb_content_element  thegem-vc-text thegem-custom-6a9b31bfcf1e48809"  >
			<div class="wpb_wrapper">
				<p>L&#8217;app di mascheramento sfrutta anche il &#8220;typosquatting&#8221; (che crea un semplice errore di battitura) nell&#8217;URL.</p>
<p><em>&#8220;Quando si digita &#8216;pretier&#8217;,cosa che gli sviluppatori potrebbero benissimo fare inavvertitamente, la nostra estensione mascherata è l&#8217;unico risultato&#8221;</em>, aggiunge Goldman.</p>
<p>I ricercatori evidenziano anche preoccupazioni sulla procedura di verifica. Viene visualizzato un segno di spunta blu non per gli autori che sono verificati come chi dicono di essere, come ci si aspetterebbe, ma semplicemente che l&#8217;editore ha dimostrato la proprietà di qualsiasi dominio.</p>
<p>I pacchetti dannosi vengono regolarmente caricati su gestori di pacchetti come <strong>NPM</strong>. Aqua Security rileva la possibilità che gli sviluppatori di estensioni legittimi abbiano il proprio lavoro compromesso utilizzando un pacchetto dannoso come dipendenza.</p>
<p>I risultati di <strong>Aqua Security</strong> mostrano che è più importante che mai controllare tre volte le estensioni che installi e i pacchetti che stai utilizzando.</p>

			</div>
			<style>@media screen and (max-width: 1023px) {.thegem-vc-text.thegem-custom-6a9b31bfcf1e48809{display: block!important;}}@media screen and (max-width: 767px) {.thegem-vc-text.thegem-custom-6a9b31bfcf1e48809{display: block!important;}}@media screen and (max-width: 1023px) {.thegem-vc-text.thegem-custom-6a9b31bfcf1e48809{position: relative !important;}}@media screen and (max-width: 767px) {.thegem-vc-text.thegem-custom-6a9b31bfcf1e48809{position: relative !important;}}</style>
		</div>
	
</div></div></div></div>
</div><p>L'articolo <a href="https://www.webbare.it/2023-01-visual-studio-marketplace-hacker/">Visual Studio Marketplace è l&#8217;ultima frontiera di attacco alla supply chain</a> proviene da <a href="https://www.webbare.it">Webbare</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
