Tag: supply-chain
-
Linux Malware liefert Beweis: Lazarus steckt hinter der 3CX Supply Chain Attacke
eiten mit neu entdeckter Linux-Malware, die bei der Operation DreamJob verwendet wurde, bestätigen die Theorie, dass die berüchtigte, mit Nordkorea ve… First seen on welivesecurity.com Jump to article: www.welivesecurity.com/deutsch/2023/04/20/linux-malware-liefert-beweis-lazarus-steckt-hinter-der-3cx-supply-chain-attacke/
-
NullBulge threat actor targets software supply chain, AI tech
SentinelOne published new research detailing NullBulge, an emerging ransomware actor that recently claimed to have stolen data from Disney’s internal … First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366596133/NullBulge-threat-actor-targets-software-supply-chain-AI-tech
-
Cyber Supply Chain Security and Third-Party Risk Management
Sujit Christy on Why Their Intersection Requires a Paradigm Shift The intersection of cyber supply chain security and third/fourth-party risk manageme… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/blogs/cyber-supply-chain-security-third-party-risk-management-p-3680
-
SBOMs Critical to Software Supply Chain Security
By Deb Radcliff, DevSecOps analyst and editor of CodeSecure’s TalkSecure educational content (syndicated at Security Boulevard & YouTube)LAS VEGAS… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/sboms-critical-to-software-supply-chain-security/
-
SEC Investigation into Progress MOVEit Hack Ends Without Charges
After months of investigation, the SEC decided not to recommend any enforcement action against software provider Progress regarding the supply chain a… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/sec-progress-moveit-no-charges/
-
Firmware Guide for Pen Testers
Contributions from Mathew Mullins, Supply Chain Security Consultant here at Eclypsium. Introduction Penetration tests come in many different varieties… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/firmware-guide-for-pen-testers/
-
ISMG Editors: Is Russia Waging War Through Ransomware?
Also: Lone-Wolf Operators, Attacks on Medical Supply Chains What’s Next?. In the latest weekly update, ISMG editors explore evolving ransomware threat… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ismg-editors-russia-waging-war-through-ransomware-a-25996
-
Lineaje raises $20M to help organizations combat software supply chain threats
The software supply chain faces threats from all sides. A 2024 report by the Ponemon Institute found that over half of organizations have experienced … First seen on techcrunch.com Jump to article: techcrunch.com/2024/07/30/lineaje-raises-20m-to-help-organizations-combat-software-supply-chain-threats/
-
Understanding and reducing supply chain risk and software vulnerability risks
First seen on scmagazine.com Jump to article: www.scmagazine.com/resource/understanding-and-reducing-supply-chain-risk-and-software-vulnerability-risks
-
1 in 5 companies say state-sponsored attacks try to penetrate supply chain
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/one-in-five-companies-claim-state-sponsored-attacks
-
Report: Large number of software supply chains have critical vulnerabilities
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/report-large-number-of-software-supply-chains-have-critical-vulnerabilities
-
North Korea-linked hackers target construction and machinery sectors with watering hole and supply chain attacks
South Korea’s National Cyber Security Center (NCSC) reported that North Korea-linked hackers hijacked VPN software updates to deploy malware. South Ko… First seen on securityaffairs.com Jump to article: securityaffairs.com/166628/apt/north-korea-targets-construction-machinery-sectors.html
-
#BHUSA: Nation-State Attacks Target Hardware Supply Chains
New report warns of escalating hardware supply chain attacks, with 19% of organizations impacted and nearly all IT leaders expecting nation-state invo… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/nationstate-attacks-target/
-
OpenWrt dominates, but vulnerabilities persist in OT/IoT router firmware
Forescout has published a new report examining the current state of the software supply chain in OT/IoT routers. The study uncovered that OT and IoT c… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/08/07/ot-iot-router-firmware-vulnerabilities/
-
Cybercriminals Target OneBlood: Blood Supply Chain Threatened
The nonprofit organization OneBlood, which supplies donor blood to over 250 hospitals in the United States, finds itself in a challenging situation. H… First seen on securityonline.info Jump to article: securityonline.info/cybercriminals-target-oneblood-blood-supply-chain-threatened/
-
Kimsuky and Andariel Target Seoul’s Construction Industry
Espionage Groups Exploited Software Supply Chain Vulnerabilities to Widen Reach. Prominent North Korean hacker groups Kimsuky and Andariel have been t… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/kimsuky-andariel-target-seouls-construction-industry-a-25961
-
Attacks on Blood Suppliers Trigger Supply Chain Warning
Blood Shortage After Ransomware Attack Underscores Rising Threats to Patient Safety. The American Hospital Association and Health Information Sharing … First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/attacks-on-blood-suppliers-trigger-supply-chain-warning-a-25944
-
Airlines are flying blind on third-party risks
The aviation industry has traditionally focused on physical security threats, but recent revelations about risks on Boeing’s supply chain have spotlig… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/08/01/airlines-third-party-risks/
-
Malware Exploiting IoT Devices on the Rise, SonicWall Warns
SonicWall has published its mid-year Cyber Threat Report for 2024. In the first half of the year, there was a significant increase in supply chain att… First seen on securityonline.info Jump to article: securityonline.info/malware-exploiting-iot-devices-on-the-rise-sonicwall-warns/
-
Microsoft Remains Top Phishing Target, Adidas and WhatsApp Join Top 10
Phishing attacks remain one of the most prevalent cyber threats and often serve as the precursor to larger-scale supply chain campaigns. Recently, Che… First seen on securityonline.info Jump to article: securityonline.info/microsoft-remains-top-phishing-target-adidas-and-whatsapp-join-top-10/
-
Supply chain attacks conducted through Polyfill.io service
In February, a Chinese company named Funnell bought the Polyfill.io domain, which sparked concerns in the infosec community about potential supply cha… First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366592015/Supply-chain-attacks-conducted-through-Polyfillio-service
-
Three ways to mitigate AI-based supply chain attacks
First seen on scmagazine.com Jump to article: www.scmagazine.com/perspective/three-ways-to-mitigate-ai-based-supply-chain-attacks
-
Software Supply Chain Security Firm Lineaje Raises $20M in Series A Funding
Software supply chain security startup Lineaje has raised $20 million in a Series A funding round that brings the total to $27 million. The post Soft… First seen on securityweek.com Jump to article: www.securityweek.com/software-supply-chain-security-firm-lineaje-raises-20m-in-series-a-funding/
-
PKfail Secure Boot bypass lets attackers install UEFI malware
Hundreds of UEFI products from 10 vendors are susceptible to compromise due to a critical firmware supply-chain issue known as PKfail, which allows at… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/pkfail-secure-boot-bypass-lets-attackers-install-uefi-malware/
-
Chainguard Raises $140 Million, Expands Tech to Secure AI Workloads
Software supply chain security startup Chainguard raises a $140 million Series C round that values the company at $1.2 billion. The post Chainguard Ra… First seen on securityweek.com Jump to article: www.securityweek.com/chainguard-raises-140-million-expands-tech-to-secure-ai-workloads/
-
Networking Equipment Riddled With Software Supply Chain Risks
First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/networking-equipment-riddled-with-software-supply-chain-risks/
-
First Annual OSCR Report Reveals 95% of Organizations Have at Least One Severe Security Risk Within their Software Supply Chain
OX Security, the pioneer in Active Application Security Posture Management (Active ASPM), today issued the OSC&R community’s inaugural software su… First seen on itsecurityguru.org Jump to article: www.itsecurityguru.org/2024/07/17/first-annual-oscr-report-reveals-95-of-organizations-have-at-least-one-severe-security-risk-within-their-software-supply-chain
-
Chainguard Raises $140M to Drive AI Support, Global Growth
Company Seeks to Expand Globally and Grow Its US Public Sector Presence. A supply chain security firm led by an ex-Google Cloud engineer closed a Seri… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chainguard-raises-140m-to-drive-ai-support-global-growth-a-25854
-
3 million iOS and macOS apps were exposed to potent supply-chain attacks
First seen on arstechnica.com Jump to article: arstechnica.com/

