mastodon.uno è uno dei tanti server Mastodon indipendenti che puoi usare per partecipare al fediverso.
Mastodon.Uno è la principale comunità mastodon italiana. Con 75.000 iscritti è il più grande nodo Mastodon italiano: anima ambientalista a supporto della privacy e del mondo Open Source.

Statistiche del server:

6,7K
utenti attivi

#supplychain

13 post11 partecipanti0 post oggi

🧠 BLOCKCHAIN
🔴 Watr Targets Tariffs with Blockchain

🔸 New Web3 startup Watr says it can pre-validate tariffs using blockchain before trades happen.
🔸 Led by ex-Shell and JPMorgan execs, platform is used by top miners & auto firms.
🔸 Now shifting focus from ESG to trade compliance, backed by Avalanche blockchain.
🔸 Could streamline $20T global commodity trade amid tariff hikes.

The EU hones in on Central Asia in race for raw materials.

The EU has raised billions for the region to diversify supply chains and reduce dependence on China.

Experts say the idea is to offer competitive deals and build local industry while encouraging sustainable mining.

mediafaro.org/article/20250402

A drilling vehicle in Kazakhstan. | Image: Jens Büttner/dpa/picture alliance
DW · The EU hones in on Central Asia in race for raw materials.Di Anchal Vohra
#EU#Minerals#Mining
Discussione continua

Bloomberg alerts sent on this:
*CANADA, MEXICO NOT SUBJECT TO RECIPROCAL TARIFFS FOR NOW
*US CONTINUES USMCA EXEMPTION FOR CANADA, MEXICO TARIFFS

BREAKING: Canada gets an exemption from Trump's baseline 10% tariffs, Bloomberg reports. At least for now, the existing tariff exemption for USMCA compliant goods will continue. (It's not immediately clear to me if Canadian autos will still get hit with the 25% tariff on foreign cars)

The list of tarifs announced today, for each country

Canada not listed, so likely 10%.
EDIT: Canada is exempted entirely beside what was announced already in the last few weeks

Unclear if it is the new baseline tariff or the extra on top of what exists already.

(No Alt text on the photos yet)

Average person will be 40% poorer if world warms by 4C
Experts say previous #economic models underestimated impact of #globalheating – as well as likely ‘cascading #supplychain disruptions’
Australian scientists study suggests average per person #GDP across the globe will be reduced by 16% even if warming is kept to 2C above pre-industrial levels. This is a much greater reduction than previous estimates, which found the reduction would be 1.4%.
theguardian.com/environment/20 #climate #climatechange

The Guardian · Average person will be 40% poorer if world warms by 4C, new research showsDi Graham Readfearn
Ha risposto nella discussione

So with an #crazyweirdo in command, that talks about new #tariffs on average once per week if not more often, do you want to rely on products from such a country in your #supplychain ?

Want to buy a billion dollar war plane from the #usa when #weirdoinchief might decide next week that your maintenance contract (these go over 30+ years) is suspended because of your countries #diversity policy? Or because it allows "X" in the sex field in the passport? 6/6

Man, npm and supply chain security... seriously a never-ending story. 🙄 Just caught an article about "ethers-provider2" and "ethers-providerz". Get this: these things are actually infecting packages you *already* have installed! 🤯

Speaking as a pentester, let me tell ya: you absolutely *have* to run regular checks. Your `package-lock.json`, `yarn.lock`... check 'em all! Trust me, SCA tools are worth their weight in gold in these situations. And listen up, people, MFA for your npm account? That's not some optional extra, it's a straight-up *MUST*!

I literally just had a client who thought, "Ah, npm's pretty safe, right?". Yeah, famous last words! 🤦‍♂️

So, what're your most insane supply chain attack stories? Lay 'em on me!

We're #hiring!

Two(!) full #professorships open in our department at WU Vienna (Vienna University of Economics and Business) under two complementary focus topics:

1) #Foundations of contemporary #InformationSystems, where we look for candidates who complement and strengthen the existing research at our department in areas such as:

· #ArtificialIntelligence: #AI Systems and Architectures
· #DataMining and #MachineLearning
· #DistributedSystems and #Decentralization
· #DistributedLedgers
· #Cloud and #Virtualisation
· #IoT and #EdgeComputing
· #DataGovernance for AI

2) #OperationsManagement with a focus on #DigitalTransformation, where the candidate’s expertise falls within one of the following research areas:

· #behavioural #operations
· AI application to #process improvements
· integrated #supplymanagement and #demandmanagement
· #ProductionPlanning and control
· #SupplyChain planning and control
· circular supply chains and sustainable supply chain management
· #tokenization in supply chains and new product development

Details at the link below... Please get in touch, if you want to know more!

wu.ac.at/en/isom/events/isom-n

www.wu.ac.atopen positions: 2 full professorships of Business Administration and Informaton SystemsWe are looking for applicants with an emphasis on either * contemporary information systems or * operations management and digital transformation.

AI-powered predictive risk analysis is revolutionizing supply chain management by reducing disruptions and optimizing efficiency. With machine learning and real-time insights, businesses can foresee potential risks and enhance logistics operations. Explore how AI is reshaping supply chain resilience.

Read more: amplework.com/blog/ai-reducing

Ugh, not *another* npm issue? 😩 Seeing crypto packages getting hacked and sensitive data swiped... again. Seriously!

As a pentester, running into these supply chain attacks is pretty much a regular Tuesday for me. And here's the kicker: they're often a nightmare to detect because they burrow so deep into your dependencies.

So, what can you actually *do*? My advice:
1. **Dig into your `package-lock.json` or `yarn.lock` files.** Spot any weird-looking versions hiding in there? That's a red flag.
2. **Use SCA (Software Composition Analysis) tools.** Let them do the heavy lifting and flag known vulnerabilities automatically.
3. **For the love of security, enable 2FA on your npm accounts!** Like, right now. It really makes a difference.
4. **Quick check:** Are the maintainers of the open-source packages you rely on still active? Sometimes abandonment is the first step towards compromise.

Funny story – had a client tell me just today, "But npm's secure, right?" ... Yeah, if only!

It really makes you wonder, doesn't it? What do you think – should npm just make 2FA mandatory for everyone publishing packages? Let me know below! 👇