Dependency Confusion: How a Researcher Hacked Apple and Microsoft
No exploits, no stolen credentials — Alex Birsan's February 2021 research got code executed inside 35+ major companies by registering their internal package names on public registries and letting version arithmetic do the rest. The incident file on the cheapest supply-chain attack ever demonstrated.
