CriticalSecurity & Privacy
Kaspersky says Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates (Dan Goodin/Ars Technica)
Daemon Tools, a legitimate and widely-used disk image mounting application, was compromised for approximately one month and distributed malicious updates to users, representing a significant supply chain attack vector that could have affected thousands of organizations. This incident demonstrates the critical vulnerability of third-party software dependencies and the importance of application whitelisting and software integrity verification in enterprise environments. IT organizations must reassess their patch management strategies and vendor security assessment protocols to detect similar compromises across their software supply chains.

Dan Goodin / Ars Technica: Kaspersky says Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates — Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates …