Supply Chain Security
More details have come to light on the recent supply chain attack targeting GitHub Actions, including its root cause.
Hi, what are you looking for?
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
More details have come to light on the recent supply chain attack targeting GitHub Actions, including its root cause.
The websites of over 100 auto dealerships were found serving malicious ClickFix code in a supply chain compromise.
The tj-actions/changed-files GitHub Action, which is used in 23,000 repositories, has been targeted in a supply chain attack.
Report from the Department for Science, Innovation & Technology (DSIT) finds weaknesses in current practices.
Opengrep is a new consortium-backed fork of Semgrep, intended to be and remain a true genuine OSS SAST tool.
Join Us in Shaping the Future of Supply Chain Security - Don’t miss this chance to be part of the conversation addressing one of...
Open source software (OSS) is a prime target for supply chain cyberattacks and protecting it remains a major challenge.
The deal includes certain Phylum assets, including its malicious package analysis, detection, and mitigation technology.
The recent compromise of Cyberhaven’s Chrome extension appears to be part of a broad campaign that started over a year ago.
Cyberhaven and other Chrome extensions were compromised in a supply chain attack targeting Facebook advertising users.
Supply chain attack leads to decentralized application developers downloading backdoored versions of the Solana Web3.js library.
ESET warns of a new reality: “UEFI bootkits are no longer confined to Windows systems alone.”
Supply chain management software provider Blue Yonder has been targeted in a ransomware attack that caused significant disruptions for some customers.
LottieFiles has confirmed that Lottie-Player has been compromised in a supply chain attack whose goal is cryptocurrency theft.
Socket has raised $40 million in a Series B funding round to work on open source software supply chain security technology.
The SEC announces penalties against Unisys, Avaya, Check Point and Mimecast for downplaying the impact of the SolarWinds Orion hack.
A Pyongyang-aligned APT was caught exploiting a recent zero-day in Internet Explorer in a supply chain attack.
Entry points in packages across multiple programming languages are susceptible to exploitation in supply chain attacks.
A breach at Rackspace exposes the fragility of the software supply chain, triggering a blame game among vendors over an exploited zero-day.
As organizations have fortified their defenses against direct network attacks, hackers have shifted their focus to exploiting vulnerabilities in the supply chain to gain...