Tag: supply-chain
-
Stellar Cyber, Critical Insight Discuss Supply Chain Security
First seen on scmagazine.com Jump to article: www.scmagazine.com/native/stellar-cyber-critical-insight-discuss-supply-chain-security
-
Das Lieferkettensorgfaltspflichtengesetz und die deutsche Wirtschaft – Deutsche Unternehmen befürworten Verantwortung in der Lieferkette
Tags: supply-chainFirst seen on security-insider.de Jump to article: www.security-insider.de/lieferketten-sorgfaltspflichten-studie-a-07986c593f54aaccc6feb19e9cf8235b/
-
Supply Chain Breaches Up 68% Year Over Year, According to DBIR
As Verizon Business redefines supply chain breach, it could either help organizations address third-party risk holistically or just conflate and confu… First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/supply-chain-breaches-up-68-yoy-according-to-dbir
-
DHS funding breathes fresh life into SBOMs
Protobom, now an OpenSSF sandbox project, is the first of multiple software supply chain security efforts funded under the Silicon Valley Innovation P… First seen on techtarget.com Jump to article: www.techtarget.com/searchitoperations/news/366581277/DHS-funding-breathes-fresh-life-into-SBOMs
-
Defenders’ Dilemma: Can AI Bolster Cyber Resilience?
Visa’s Subra Kumaraswamy on Threat Detection, AI and Third-Party Supply Chain Risk. Subra Kumaraswamy, senior vice president and CISO at Visa, discuss… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/defenders-dilemma-ai-bolster-cyber-resilience-a-25186
-
CISOs not yet convinced to invest in AI
CISOs say their eyes are fixed firmly on threats like ransomware and supply chain attacks, and while AI is becoming a threat that needs to be dealt wi… First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366581134/CISOs-not-yet-convinced-to-invest-in-AI
-
BTS #29 Supply Chains, Firmware, And Patching Jason Kikta
Jason joins us to discuss the current enterprise landscape for defending against supply chain attacks, remediating firmware issues, and the current ch… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/bts-29-supply-chains-firmware-and-patching-jason-kikta/
-
New R Programming Vulnerability Exposes Projects to Supply Chain Attacks
A security vulnerability has been discovered in the R programming language that could be exploited by a threat actor to create a malicious RDS (R Data… First seen on thehackernews.com Jump to article: thehackernews.com/2024/04/new-r-programming-vulnerability-exposes.html
-
Press Release: OX Security and HCLSoftware Announce Strategic Partnership to Launch AppScan Supply Chain Security
New OEM Capabilities, Empower Organizations to Deliver a Modern Approach to Application Security New York, NY, and Tel Aviv, Israel May 7, 2024 To… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/press-release-ox-security-and-hclsoftware-announce-strategic-partnership-to-launch-appscan-supply-chain-security/
-
Supply chain attack abuses GitHub features to spread malware
Checkmarx warned developers to be cautious when choosing which repositories to use, as attackers are manipulating GitHub features to boost malicious c… First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366580379/Supply-chain-attack-abuses-GitHub-features-to-spread-malware
-
Eclypsium Supply Chain Security Platform Protects GenAI Infrastructure with Addition of Hardware and Training Model Assessment Capabilities
Eclypsium is extending its digital supply chain security to cover GenAI hardware and training models SAN FRANCISCO RSA Conference May 7, 2024 Eclyp… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/eclypsium-supply-chain-security-platform-protects-genai-infrastructure-with-addition-of-hardware-and-training-model-assessment-capabilities/
-
Securing Supply Chains for GenAI Hardware and Models
Today, at RSA Conference 2024, we’re announcing new capabilities to help secure the fundamental layers of the GenAI tech stack. First, we’re adding co… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/securing-supply-chains-for-genai-hardware-and-models/
-
R Programming Bug Exposes Orgs to Vast Supply Chain Risk
The CVE-2024-27322 security vulnerability in R’s deserialization process gives attackers a way to execute arbitrary code in target environments via sp… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/r-programming-language-exposes-orgs-to-supply-chain-risk
-
Eclypsium Supply Chain Security Platform Wins Global InfoSec Award
Platform named Market Leader for Software Supply Chain Security SAN FRANCISCO RSA Conference May 6, 2024 Eclypsium, the supply chain security compa… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/eclypsium-supply-chain-security-platform-wins-global-infosec-award/
-
Webinar: Learn Proactive Supply Chain Threat Hunting Techniques
In the high-stakes world of cybersecurity, the battleground has shifted. Supply chain attacks have emerged as a potent threat, exploiting the intricat… First seen on thehackernews.com Jump to article: thehackernews.com/2024/04/webinar-learn-proactive-supply-chain.html
-
Securing your organization’s supply chain: Reducing the risks of third parties
When Stephen Hawking said that we are all now connected by the internet, like neurons in a giant brain, very few people understood the gravity of his … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/05/02/supply-chain-third-parties-risks/
-
Software-Lieferketten absichern, Teil 2 – Risiken in der Software Supply Chain
First seen on security-insider.de Jump to article: www.security-insider.de/software-lieferkette-risiken-sicherheit-digital-transformation-a-92806ff4ebcdbf0f957f29f29ff9dcce/
-
Supply chain attacks likely with exploitation of novel R programing bug
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/supply-chain-attacks-likely-with-exploitation-of-novel-r-programing-bug
-
Attacker Social-Engineered Backdoor Code Into XZ Utils
Unlike the SolarWinds and CodeCov incidents, all that it took for an adversary to nearly pull off a massive supply chain attack was some slick social … First seen on darkreading.com Jump to article: www.darkreading.com/application-security/attacker-social-engineered-backdoor-code-into-xz-utils
-
Vulnerability in R Programming Language Could Fuel Supply Chain Attacks
A vulnerability (CVE-2024-27322) in the R programming language implementation can be exploited to execute arbitrary and be used as part of a supply ch… First seen on securityweek.com Jump to article: www.securityweek.com/vulnerability-in-r-programming-language-enables-supply-chain-attacks/
-
XZ backdoor discovery reveals Linux supply chain attack
A maintainer for XZ, a popular open source compression library for Linux distributions, compromised the open source project over the course of two yea… First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366577602/XZ-backdoor-discovery-reveals-Linux-supply-chain-attack
-
JFrog Software Supply Chain State of the Union 2024 – Risiken und Chancen für Software-Lieferketten in Deutschland
First seen on security-insider.de Jump to article: www.security-insider.de/software-supply-chain-risiken-und-potenziale-2024-a-3f333ba3d57d3dcab2be146c128702b3/
-
Top.gg supply chain attack highlights subtle risks
Threat actors used fake Python infrastructure and cookie-stealing to poison multiple GitHub code repositories, putting another spotlight on supply cha… First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366575534/Topgg-supply-chain-attack-highlights-subtle-risks
-
Lösungspaket für die Software Composition Analysis (SCA) – Synopsys nimmt Risiken in der Software-Lieferkette ins Visier
First seen on security-insider.de Jump to article: www.security-insider.de/synopsys-black-duck-supply-chain-edition-sicherheit-software-lieferkette-a-e29d2358ddc25d95f8514c9d9f4f9fc9/
-
Protobom: Open-source software supply chain tool
Protobom is an open-source software supply chain tool that enables all organizations, including system administrators and software development communi… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/04/19/protobom-open-source-software-supply-chain-tool/
-
Sisense Password Breach Triggers ‘Ominous’ CISA Warning
With stores of mega-corporate business intelligence, a Sisense compromise could potentially mushroom into supply chain cyberattack disaster, experts f… First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/sisense-breach-triggers-cisa-password-reset-advisory
-
Why MLBOMs Are Useful for Securing the AI/ML Supply Chain
A machine learning bill of materials (MLBOM) framework can bring transparency, auditability, control, and forensic insight into AI and ML supply chain… First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/mlboms-are-useful-for-securing-ai-ml-supply-chain
-
Cisco Duo customer MFA message logs stolen in supply chain hack
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/cisco-duo-customer-mfa-message-logs-stolen-in-supply-chain-hack
-
PyPI halted new users and projects while it fended off supply-chain attack
First seen on arstechnica.com Jump to article: arstechnica.com/
-
CISA software supply chain security form omits SBOMs
Federal suppliers now have a self-attestation deadline amid ongoing efforts to secure software supply chains. But SBOMs’ spotlight is fading and big r… First seen on techtarget.com Jump to article: www.techtarget.com/searchitoperations/news/366573974/CISA-software-supply-chain-security-form-omits-SBOMs

