software-supply-chain
40 articles with this tag
MEDIUM
INFO
MEDIUM
INFO
CRITICAL
MEDIUM
INFO
MEDIUM
INFO
INFO
CRITICAL
HIGH
INFO
HIGH
INFO
INFO
MEDIUM
INFO
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
INFO
MEDIUM
HIGH
INFO
HIGH
INFO
INFO
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
INFO
INFO
INFO
Top AIs invent same fake PyPl and npm package names
Open-source maintainers still work underfunded as sponsorship crosses $100 million
It's looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns
EU Cyber Resilience Act: Overview, Requirements, and Timelines
Hole in widely-used FFmpeg codec could crash media servers or enable RCE
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
OpenAI rolls out AI-led push to fix open-source software flaws
Novo Nordisk Breach Exposes Software Development Pipeline Risk
Software supply chains are heading for a transparency test
Docker joins the Athena coalition: a cross-industry collaboration for supply chain security
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
Prompt injection still drives most agentic AI security failures in production
OWASP Dependency-Track 5.0 Is Now Generally Available
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
What is Software Supply Chain Security?
Hardened Images Explained: Fewer CVEs, Smaller Attack Surface
depthfirst adds pre-install protection against malicious dependencies
IBM and Red Hat want to become the ‘security clearinghouse’ for open source applications in the enterprise
Attackers Move Past Typosquatting to Realistic Package Impersonation
Laravel-Lang Packages Poisoned for Malware Delivery
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
Laravel Lang packages hijacked to deploy credential-stealing malware
A hacker group is poisoning open source code at an unprecedented scale
Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise
SAP npm package attack highlights risks in developer tools and CI/CD pipelines
Emerging Enterprise Security Risks of AI
STARDUST CHOLLIMA Likely Compromises Axios npm Package
Are you thinking about software supply chain attacks? #hacker @endingwithali #cybersecurity
Legitify: Open-source scanner for security misconfigurations on GitHub and GitLab
Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign
Microsoft Abruptly Terminates VeraCrypt Account, Halting Windows Updates
Supply chain security is now a board-level issue: Here’s what CSOs need to know
Defending Your Software Supply Chain: What Every Engineering Team Should Do Now
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069
Breakdown: How TeamPCP hid malware inside WAV files using audio steganography
Telnyx package on PyPI compromised by TeamPCP. WAV steganography used for payload delivery
Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets
Open-source security debt grows across commercial software
Securing the Agentic Endpoint
Die besten DAST- & SAST-Tools