Hi, what are you looking for?
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
CrowdStrike is warning of a recently identified supply chain attack involving Canada-based customer engagement software provider Comm100.
The funding frenzy in the software supply chain space now includes Ox Security, an early-stage Israeli startup that just raised a whopping $34 million...
Chainguard this week announced Wolfi, a stripped-down Linux OS distribution designed to improve the security of the software supply chain.
Firmware security company Binarly has discovered another round of potentially serious firmware vulnerabilities that could allow an attacker to gain persistent access to any...
Researchers at threat detection and response company Trellix have resurrected a 15-year-old Python vulnerability, showing that it’s more serious than initially believed and that...
The White House has announced new guidance with the aim of ensuring that federal agencies only use secure software.
The non-profit Rust Foundation has scored funding to build a dedicated security team to proactively identify and address security defects in the popular Rust...
The European Union’s executive arm proposed new legislation Thursday that would force manufacturers to ensure that devices connected to the internet meet cybersecurity standards,...
The FBI has observed an increase in attacks targeting healthcare payment processors in an effort to divert significant amounts of money to accounts controlled...
Cybersecurity firm Bishop Fox has announced the release of CloudFox, an open source tool designed to help find exploitable attack paths in cloud infrastructure.The...
For the past several weeks, Magento stores have been injected with malware via a supply chain attack that targeted the FishPig distribution server.Specialized in...
Cybersecurity firm ESET has detailed a new cyberespionage group targeting high-profile private and public entities in Asia and Africa since 2020.
A cybercrime group has leaked files stolen earlier this year from Cisco, but the networking giant stands by its initial assessment of the incident...
Three U.S. government agencies -- Cybersecurity and Information Security Agency (CISA), the National Security Agency (NSA) and the Office of the Director of National...
Managed detection and response (MDR) platform provider Huntress on Thursday announced the closing of a $40 million debt financing round to speed up global...
Forty-one cybersecurity-related M&A deals were announced in August 2022.
Symantec has discovered hardcoded AWS credentials in more than 1,800 mobile applications and warned of the potential risks associated with poor security practices.While Symantec’s...