Incident Response
Rapid7 says unauthorized third-party accessed source code, customer data during Codecov supply chain breach
Hi, what are you looking for?
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
Rapid7 says unauthorized third-party accessed source code, customer data during Codecov supply chain breach
The massive blast radius from the Codecov supply chain attack remains shrouded in mystery as security teams continue to assess the fallout from the...
In a joint document published this week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST)...
It’s a bigger problem than is immediately apparent, and has the potential for hacks as big as Equifax and as widespread as SolarWinds.
The U.S. government is working to draw attention to supply chain vulnerabilities, an issue that received particular attention late last year after suspected Russian...
Join Intel on Wednesday, March 10, at SecurityWeek’s Supply Chain Security Summit, where industry leaders will examine the current state of supply chain attacks....
Ukraine’s National Security and Defense Council (NSDC) this week published two press releases describing cyberattacks aimed at the country.
Researchers at cybersecurity firm ESET say they have uncovered an espionage campaign that has targeted online gamers in Asia through a compromised software company.
The elite Russian hackers who gained access to computer systems of federal agencies last year didn’t bother trying to break one by one into...
CrowdStrike, one of the cybersecurity companies called in by IT management firm SolarWinds to investigate the recently disclosed supply chain attack, on Monday shared...
It is believed that the recently disclosed attack targeting Texas-based IT management solutions provider SolarWinds resulted in threat actors gaining access to the networks...
Organizations Need to Monitor and Manage IT Security Risks Downstream in the Supply Chain
U.S. Agency Says SolarWinds Orion Supply Chain Compromise is Not the Only Initial Infection Vector Leveraged by APT Actor
Tampered Versions of SolarWinds Orion IT Monitoring Software Used to Compromise Global Organizations
Dell Technologies on Thursday announced new security offerings designed to address threats targeting the supply chain, a device’s boot process, and sensitive data.
The North Korea-linked threat actor known as Lazarus has been targeting users in South Korea through a supply chain attack that involves software typically...
GitHub revealed on Thursday that tens of open source NetBeans projects hosted on its platform were targeted by a piece of malware as part...