What is the attack?Over 100,000+ sites have been impacted by a supply chain attack involving the Polyfill.io service. Polyfill is a popular tool used for enhancing browser capabilities by hundreds of thousands of sites to ensure that all website visitors can use the same codebase for unsupported functionality. Earlier this year, the polyfill.io domain was purchased, and the script was modified to redirect users to malicious and scam sites.What is the recommended Mitigation?Given the confirmed malicious operations, owners of websites using polyfill.io are advised to remove it immediately and search their code repositories for instances of polyfill.io. Users are also advised to consider using alternate services provided by Cloudflare and Fastly.What FortiGuard Coverage is available?FortiGuard Labs’ research team is investigating the coverage and has blocked all the known Indicators of compromise (IoCs).
More Stories
jpegxl-0.8.3-1.fc40
FEDORA-2024-d1c276c860 Packages in this update: jpegxl-0.8.3-1.fc40 Update description: update to 0.8.3 Read More
jpegxl-0.8.3-1.fc39
FEDORA-2024-35ce4d5a74 Packages in this update: jpegxl-0.8.3-1.fc39 Update description: update to 0.8.3 Read More
mingw-python-certifi-2024.7.4-1.fc40
FEDORA-2024-599bb2cb73 Packages in this update: mingw-python-certifi-2024.7.4-1.fc40 Update description: Update to 2024.7.4. Read More
caddy-2.8.4-1.fc41
FEDORA-2024-bd8fe42929 Packages in this update: caddy-2.8.4-1.fc41 Update description: Automatic update for caddy-2.8.4-1.fc41. Changelog * Fri Jul 5 2024 Carl George...