Tag: supply-chain
-
Developers Hacked In Sophisticated Supply Chain Attack
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/35694/Developers-Hacked-In-Sophisticated-Supply-Chain-Attack.html
-
75% of third-party breaches target software, IT supply chains
First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366571699/75-of-third-party-breaches-target-software-IT-supply-chains
-
Binarly Attracts $10.5M to Tackle Software Supply Chain Security
Los Angeles firmware and software supply chain firm banks $10.5 million in seed-stage funding led by Two Bear Capital. The post les firmware and softw… First seen on securityweek.com Jump to article: www.securityweek.com/binarly-attracts-10-5m-to-tackle-software-supply-chain-security/
-
Top.gg, others targeted by software supply chain attack
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/top-gg-others-targeted-by-software-supply-chain-attack
-
Hackers poison source code from largest Discord bot platform
The Top.gg Discord bot community with over 170,000 members has been impacted by a supply-chain attack aiming to infect developers with malware that st… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-poison-source-code-from-largest-discord-bot-platform/
-
Eclypsium Announces New Global Partnership Program
Tags: supply-chainFollowing record results in FY23, company prioritizes channel momentum Portland, OR March 26, 2024 Eclypsium, the digital supply chain security comp… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/03/eclypsium-announces-new-global-partnership-program/
-
Top Python Developers Hacked in Sophisticated Supply Chain Attack
Multiple Python developers get infected after downloading malware-packed clone of the popular tool Colorama. The post Python developers get infected … First seen on securityweek.com Jump to article: www.securityweek.com/top-python-developers-hacked-in-sophisticated-supply-chain-attack/
-
Finite State Raises $20 Million to Grow Software Supply Chain Security Business
Software risk management firm Finite State has raised a $20 million growth round led by Energy Impact Partners (EIP). The post risk management firm F… First seen on securityweek.com Jump to article: www.securityweek.com/finite-state-raises-20-million-to-grow-software-supply-chain-security-business/
-
ML Model Repositories: The Next Big Supply Chain Attack Target
Machine-learning model platforms like Hugging Face are suspectible to the same kind of attacks that threat actors have executed successfully for years… First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/ml-model-repositories-next-big-supply-chain-attack-target
-
Watch Now: Supply Chain & Third-Party Risk Summit 2024
Join the fully immersive virtual event us as we explore the critical nature of software and vendor supply chain security issues. (Login Now) The post … First seen on securityweek.com Jump to article: www.securityweek.com/virtual-event-today-supply-chain-third-party-risk-summit-2024/
-
Linux Supply Chain Validation Cheat Sheet
Linux provides several tools and techniques that allow users to query systems for information about hardware and firmware (This post builds on our pre… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/03/linux-supply-chain-validation-cheat-sheet/
-
Virtual Event Today: Supply Chain & Third-Party Risk Summit 2024
Join the fully immersive virtual event us as we explore the critical nature of software and vendor supply chain security issues The post fully immers… First seen on securityweek.com Jump to article: www.securityweek.com/virtual-event-today-supply-chain-third-party-risk-summit-2024/
-
Israeli Universities Hit by Supply Chain Cyberattack Campaign
Iranian hacktivist group known as Lord Nemesis and Nemesis Kitten targeted an academic sector software firm in Israel to gain access to its customers…. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/israeli-universities-hit-by-supply-chain-cyberattack-campaign
-
Japan Blames North Korea for PyPI Supply Chain Cyberattack
First seen on darkreading.com Jump to article: www.darkreading.com/application-security/japan-blames-north-korea-for-pypi-supply-chain-cyberattack
-
Strategien für eine sichere Software-Lieferkette – So funktionieren Supply-Chain-Attacks
First seen on security-insider.de Jump to article: www.security-insider.de/so-funktionieren-supply-chain-attacks-a-ae6851a064dcdefd55312926b507f5f1/
-
China-Linked Cyber Spies Blend Watering Hole, Supply Chain Attacks
First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/china-linked-cyber-spies-blend-watering-hole-supply-chain-attacks
-
Chinese State Hackers Target Tibetans with Supply Chain, Watering Hole Attacks
The China-linked threat actor known as;Evasive Panda;orchestrated both watering hole and supply chain attacks targeting Tibetan users at least since S… First seen on thehackernews.com Jump to article: thehackernews.com/2024/03/chinese-state-hackers-target-tibetans.html
-
Southern Company Builds SBOM for Electric Power Substation
The utility’s software bill of materials (SBOM) experiment aims to establish stronger supply chain security ” and tighter defenses against potential c… First seen on darkreading.com Jump to article: www.darkreading.com/ics-ot-security/southern-company-builds-a-power-substation-sbom
-
Critical TeamCity Bugs Endanger Software Supply Chain
Customers should immediately patch critical vulnerabilities in on-prem deployments of the CI/CD pipeline tool JetBrains TeamCity that could allow thre… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/critical-teamcity-bugs-endanger-software-supply-chain
-
New Hugging Face Vulnerability Exposes AI Models to Supply Chain Attacks
Cybersecurity researchers have found that it’s possible to compromise the Hugging Face Safetensors conversion service to ultimately hijack the models … First seen on thehackernews.com Jump to article: thehackernews.com/2024/02/new-hugging-face-vulnerability-exposes.html
-
NIST Releases Cybersecurity Framework 2.0
New guidance expands the framework to consider organizations beyond critical infrastructure; it also addresses governance and supply chain cybersecuri… First seen on darkreading.com Jump to article: www.darkreading.com/ics-ot-security/nist-releases-cybersecurity-framework-2-0
-
Australian data breach report highlights supply chain risks
First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366570859/Australian-data-breach-report-highlights-supply-chain-risks
-
KI und Supply Chain Security: Jetzt noch Tickets für Frühjahrs-devSec sichern
First seen on heise.de Jump to article: heise.de/news/KI-und-Supply-Chain-Security-Jetzt-noch-Tickets-fuer-Fruehjahrs-devSec-sichern-9633530.html
-
New Malicious PyPI Packages Use DLL Sideloading In A Supply Chain Attack
Researchers have discovered that threat actors have been using open-source platforms and codes for several purposes, such as hosting C2 infrastructure… First seen on gbhackers.com Jump to article: gbhackers.com/malicious-pypi-packages-dll-sideloading/
-
Hacked Iraqi Voter Information Found For Sale Online
A 21.58 GB database of stolen personal voter data from Iraq’s Independent High Electoral Commission (IHEC) may have been the result of a supply chain … First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/hacked-iraqi-voter-information-found-for-sale-online
-
Ransomware Groups, Targeting Preferences, and the Access Economy
The cybercrime ecosystem has created a supply chain of stolen accounts and breached networks that are used to fuel ransomware attacks and data breache… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ransomware-groups-targeting-preferences-and-the-access-economy/
-
North Korean hackers linked to defense sector supply-chain attack
Tags: advisory, attack, cyber, defense, germany, hacker, intelligence, korea, north-korea, service, supply-chainIn an advisory today Germany’s federal intelligence agency (BfV) and South Korea’s National Intelligence Service (NIS) warn of an ongoing cyber-espion… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/north-korean-hackers-linked-to-defense-sector-supply-chain-attack/
-
Complexity and software supply chain security: 5 key survey takeaways
ss=hs-featured-image-wrapper> ss=hs-featured-image-wrapper> ss=hs-featured-image-wrapper> ss=hs-featured-ima… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/02/complexity-and-software-supply-chain-security-5-key-survey-takeaways/
-
The Principles for Package Repository Security: An Overview
Tags: supply-chainWhat are the Principles for Package Repository Security, and how can organizations effectively protect their code supply chain? The U.S. Cybersecurit… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/02/the-principles-for-package-repository-security-an-overview/
-
Cyber gaps in the supply chain ” Bank of America breached in another vendor cyberattack
Third-party cyber-attacks remain one of the most significant threats facing organisations across the globe. Most recently, Bank of America, a multinat… First seen on itsecurityguru.org Jump to article: www.itsecurityguru.org/2024/02/14/cyber-gaps-in-the-supply-chain-bank-of-america-breached-in-another-vendor-cyberattack

