"Google Supply Chain Bug Patched in Code-Testing Tool Bazel"
"Google Supply Chain Bug Patched in Code-Testing Tool Bazel"
A critical supply chain bug in Bazel, Google's open-source software development tool, allowed hackers to insert malicious code. The command injection vulnerability compromised the security of millions of Bazel-dependent projects, including Kubernetes, Angular, Uber, LinkedIn, Databricks, DropBox, Nvidia, and Google. Researchers at Cycode discovered the flaw in November 2023, and Google fixed it within seven days.