6 ms·
It's possible, but not likely. Targeting proprietary, commercial vendors is probably a lot easier than open source, as it's much easier to hide what you're doin
by lambda 13y ago
It's possible, but not likely. Targeting proprietary, commercial vendors is probably a lot easier than open source, as it's much easier to hide what you're doing. And many more of the targets they are trying to attack are likely buying fully supported solutions from commercial vendors, not COTS hardware and installing open-source software themselves.
Even for open source software, it would be easier to just target the integrator, such as the binary packages provided by the distro or preinstalled on hardware by a system integrator, rather than introducing vulnerabilities or causing problems in the upstream open source project.