Cybersecurity Funding
Software supply chain security startup Lineaje has raised $20 million in a Series A funding round that brings the total to $27 million.
Hi, what are you looking for?
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
Software supply chain security startup Lineaje has raised $20 million in a Series A funding round that brings the total to $27 million.
Software supply chain security startup Chainguard raises a $140 million Series C round that values the company at $1.2 billion.
Judge dismissed SEC lawsuit charging SolarWinds and CISO Timothy Brown with hiding security problems before and after the SUNBURST supply chain compromise.
GitLab issues an advisory for a critical-severity vulnerability that allows an attacker to trigger a pipeline as another user.
Namecheap shut down polyfill.io amid reports of malicious activity, but the Chinese owner claims it has good intentions.
More than 100,000 websites are affected by a supply chain attack injecting malware via a Polyfill domain.
Five WordPress plugins were injected with malicious code that creates a new administrative account.
Attackers are getting more sophisticated, better armed, and faster. Nothing in Rapid7's 2024 Attack Intelligence Report suggests that this will change.
The discovery of the XZ Utils backdoor reminds an F-Droid developer of a similar incident that occurred a few years ago.
Urgent security alerts issued as malicious code was found embedded in the XZ Utils data compression library used in many Linux distributions.
Maintainers of the Python Package Index (PyPI) repository were forced to suspend new project creation and new user registration to mitigate a malware upload...
Los Angeles firmware and software supply chain firm banks $10.5 million in seed-stage funding led by Two Bear Capital.
Join the fully immersive virtual event us as we explore the critical nature of software and vendor supply chain security issues. (Login Now)
SecurityWeek talks to hundreds of industry experts from dozens of companies covering seven primary topics.
Supply chain security insights: A successful attack against a supplier can lead to multiple opportunities against the supplier’s downstream customers.
AnyDesk is revoking certificates and passwords in response to a significant security breach impacting production systems.
Two new products aim to secure the traditional OSS supply chain, and the new AI model software supply chain.
Kusari has raised $8 million to help organizations gain visibility into and secure their software supply chain.
Quarkslab finds serious, remotely exploitable vulnerabilities in EDK II, the de-facto open source reference implementation of the UEFI spec.
Researchers detail a CI/CD attack leading to PyTorch releases compromise via GitHub Actions self-hosted runners.