Tag: supply-chain
-
‘Almost every Apple device’ vulnerable to CocoaPods supply chain attack
First seen on theregister.com Jump to article: www.theregister.com/2024/07/02/cocoapods_vulns_supply_chain_potential/
-
A Top-Ten List You Don’t Want to Be On
OX Research Maps Most Common Supply Chain Vulnerabilities to Attacker TTPs For our recent threat research report, OSC&R in the Wild: A New Look at… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/a-top-ten-list-you-dont-want-to-be-on/
-
Supply-chain ransomware attack cripples thousands of car dealerships
First seen on exponential-e.com Jump to article: www.exponential-e.com/blog/supply-chain-ransomware-attack-cripples-thousands-of-car-dealerships
-
How Amazon’s decision to ditch Active Directory paid off
Amazon’s decision to build its own identity and access management system was an expensive one, but an infamous supply chain attack validated the move…. First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366589442/How-Amazons-decision-to-ditch-Microsoft-Active-Directory-paid-off
-
Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack
First seen on arstechnica.com Jump to article: arstechnica.com/
-
Eclypsium for Data Centers
Security frameworks and standards are increasingly emphasizing supply chain and firmware security, and for good reason. Attackers are actively targeti… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/eclypsium-for-data-centers/
-
Tensions rise over China’s control of critical materials
While there is disagreement in Congress over how to diversify the critical materials supply chain, there is bipartisan agreement that China’s dominanc… First seen on techtarget.com Jump to article: www.techtarget.com/searchcio/news/366589035/Tensions-rise-over-Chinas-control-of-critical-materials
-
Empower Your Developers with Software Supply Chain Security
Gartner names OX Security as representative vendor in Emerging Tech Impact Radar: DevOps report The historical friction between software developers an… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/empower-your-developers-with-software-supply-chain-security/
-
Supply Chain Cyberattacks are on the Rise Here’s How U.S. Businesses can Fortify Their Defenses
First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/supply-chain-cyberattacks-are-on-the-rise-heres-how-u-s-businesses-can-fortify-their-defenses/
-
SoftwareChain-Angriff auf JavaScript-Projekt Polyfill.io – Fast 400.000 Webseiten verbreiten Malware
First seen on security-insider.de Jump to article: www.security-insider.de/software-supply-chain-angriff-polyfill-io-sicherheitswarnung-a-fef8177e85b5a000cc616cb5e41dab17/
-
Firmware, Supply Chain, and Frameworks NIST SP 800-53
NIST Special Publication 800-53 rev 5, Security and Privacy Controls for Information Systems and Organizations, is one of the most important and influ… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/firmware-supply-chain-and-frameworks-nist-sp-800-53/
-
60 New Malicious Packages Uncovered in NuGet Supply Chain Attack
Threat actors have been observed publishing a new wave of malicious packages to the NuGet package manager as part of an ongoing campaign that began in… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/60-new-malicious-packages-uncovered-in.html
-
CodeSecDays 2024: A Deep Dive in Software Supply Chain Security
Explore key insights from CodeSecDays 2024 on software supply chain security. Learn about AI in DevSecOps, SLSA frameworks, developer-security collabo… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/codesecdays-2024-a-deep-dive-in-software-supply-chain-security/
-
Building A Simple Neural Network Backdoor
Vulnerabilities in supply chains aren’t a new topic and have quite a bit of focus from both a hardware and software perspective. With this post, … First seen on research.kudelskisecurity.com Jump to article: research.kudelskisecurity.com/2020/10/29/building-a-simple-neural-network-backdoor/
-
Judge Dismisses Major SEC Charges Against SolarWinds and CISO
Judge dismissed SEC lawsuit charging SolarWinds and CISO Timothy Brown with hiding security problems before and after the SUNBURST supply chain compro… First seen on securityweek.com Jump to article: www.securityweek.com/judge-dismisses-major-sec-charges-against-solarwinds-and-ciso/
-
Malicious NuGet Campaign Exploits Homoglyphs and Code Injection to Fool Developers
ReversingLabs, a leading software supply chain security firm, has uncovered a sophisticated malicious campaign targeting the NuGet package manager, a … First seen on securityonline.info Jump to article: securityonline.info/malicious-nuget-campaign-exploits-homoglyphs-and-code-injection-to-fool-developers/
-
Cyber-Sicherheit entlang der Lieferkette: Unternehmen müssen sich wieder auf Grundlagen besinnen
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/cyber-sicherheit-lieferkette-unternehmen-muss-grundlagen-besinnung
-
‘NullBulge’ threat actor targets software supply chain, AI tech
SentinelOne published new research detailing NullBulge, an emerging ransomware actor that recently claimed to have stolen data from Disney’s internal … First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366596133/NullBulge-threat-actor-targets-software-supply-chain-AI-tech
-
Dark Web Monitoring: Wie Darknet Crawling die Lieferkette schützt
Damit es erst gar nicht zur Störung der Lieferkette kommt, sollten Unternehmen die Cyber-Gefährdung ihrer Lieferanten kennen. Nicht jeder Lieferant is… First seen on csoonline.com Jump to article: www.csoonline.com/de/a/wie-darknet-crawling-die-lieferkette-schuetzt
-
OSCR Report Exposes Software Supply Chain Security Vulnerabilities
First Annual Report Analyzes Millions of Vulnerabilities Against the Industry’s First Supply-Chain Specific Attack Matrix Software is the foundation o… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/oscr-report-exposes-software-supply-chain-security-vulnerabilities/
-
Schwachstelle in Cocoapods aufgedeckt – Millionen iOS-Apps verwundbar für Supply-Chain-Attacke
First seen on security-insider.de Jump to article: www.security-insider.de/cocoapods-sicherheitsluecke-ios-macos-apps-a-9cfb5272ebf1664d7d6cab007968df74/
-
Researchers Warn of Widespread Polyfill Supply Chain Attack
First seen on duo.com Jump to article: duo.com/decipher/researchers-warn-of-widespread-polyfill-supply-chain-attack
-
Trojanized jQuery Packages Spread via ‘Complex’ Supply Chain Attack
The campaign, which distributes dozens of malicious jQuery variants across npm, GitHub, and jsDelivr, appears to be a manual effort, and lacks the typ… First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/trojanized-jquery-packages-complex-supply-chain-attack
-
Polyfill[.]io Attack Impacts Over 380,000 Hosts, Including Major Companies
The supply chain attack targeting widely-used Polyfill[.]io JavaScript library is wider in scope than previously thought, with new findings from Censy… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/polyfillio-attack-impacts-over-380000.html
-
Ongoing NuGet supply chain attack involves dozens new malicious packages
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/ongoing-nuget-supply-chain-attack-involves-dozens-new-malicious-packages
-
Supply chain attack spreads trojanized jQuery packages
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/supply-chain-attack-spreads-trojanized-jquery-packages
-
Critical Flaws in CocoaPods Expose iOS and macOS Apps to Supply Chain Attacks
A trio of security flaws has been uncovered in the CocoaPods dependency manager for Swift and Objective-C Cocoa projects that could be exploited to st… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/critical-flaws-in-cocoapods-expose-ios.html
-
Eclypsium and Everfox Partner to Deliver Enhanced Security for the Technology Supply Chain of the U.S. Government
Portland, OR July 11, 2024 Eclypsium, the leader in digital supply chain security for enterprise hardware, firmware and software infrastructure, today… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/eclypsium-and-everfox-partner-to-deliver-enhanced-security-for-the-technology-supply-chain-of-the-u-s-government/
-
97 FTSE 100 firms exposed to supply chain breaches
Between March 2023 and March 2024, 97 out of 100 companies on the UK’s FTSE 100 list were put at risk of compromise following supply chain breaches at… First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366587593/97-FTSE-100-firms-exposed-to-supply-chain-breaches
-
Polyfill.io Supply Chain Attack: Malicious JavaScript Injection Puts Over 100k Websites At Risk
Polyfill.io helps web developers achieve cross-browser compatibility by automatically managing necessary polyfills. By adding a script tag to their HT… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/polyfill-io-supply-chain-attack-malicious-javascript-injection-puts-over-100k-websites-at-risk/

