Supply Chain Security
Self-hosted GitHub Actions runners could allow attackers to inject malicious code into repositories, leading to supply chain attacks.
Hi, what are you looking for?
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
Self-hosted GitHub Actions runners could allow attackers to inject malicious code into repositories, leading to supply chain attacks.
NSA has published guidance to help organizations incorporate SBOM to mitigate supply chain risks.
US, UK, and Poland warn of Russia-linked cyberespionage group’s broad exploitation of recent TeamCity vulnerability.
North Korean hackers breached a Taiwanese company and used its systems to deliver malware to the US, Canada, Japan and Taiwan in a supply...
Researchers at Aqua call urgent attention to the public exposure of Kubernetes configuration secrets, warning that hundreds of organizations are vulnerable to this “ticking...
CISA, NSA, and ODNI issue new guidance on managing open source software and SBOMs to maintain awareness on software security.
UK-based Risk Ledger has raised £6.25 million (~$7.65 million) in Series A funding to prevent supply chain attacks.
Washington startup Chainguard banks $61 million in new financing as investors make hefty wagers on software supply chain security companies.
Multiple North Korean hacking groups have exploited a recent TeamCity vulnerability and Microsoft warns of potential supply chain attacks.
Flaw poses a direct threat to the SOCKS5 proxy handshake process in cURL and can be exploited remotely in some non-standard configurations.
CISA, FBI, NSA, and US Treasury published new guidance on improving the security of open source software in OT and ICS.
Taiwan authorities are investigating four Taiwan-based companies suspected of helping China’s Huawei Technologies to build semiconductor facilities.
GitHub beefs up its secret scanning feature, now allowing users to check the validity of exposed credentials for major cloud services.
The Linux Foundation has announced OpenPubkey, an open source cryptographic protocol that should help boost supply chain security.
CISA unveils a new Hardware Bill of Materials (HBOM) framework for buyers and sellers to communicate about components in physical products.
Exposed data includes backup of employees workstations, secrets, private keys, passwords, and over 30,000 internal Microsoft Teams messages.
Join Microsoft and Finite State for a webinar that will introduce a new strategy for securing the software supply chain.
A new APT group called Carderbee has been observed deploying the PlugX backdoor via a supply chain attack targeting organizations in Hong Kong.
Google sprinkles magic of generative-AI into its open source fuzz testing infrastructure and finds immediate success with code coverage.
The US government's cybersecurity agency describes UEFI as "critical attack surface" that requires urgent security attention.