Supply Chain Security

Researchers Discover Dangerous Exposure of Sensitive Kubernetes Secrets

Researchers Discover Dangerous Exposure of Sensitive Kubernetes Secrets 22/11/2023 at 20:31 By Ryan Naraine Researchers at Aqua call urgent attention to the public exposure of Kubernetes configuration secrets, warning that hundreds of organizations are vulnerable to this “ticking supply chain attack bomb.” The post Researchers Discover Dangerous Exposure of Sensitive Kubernetes Secrets appeared first on […]

React to this headline:

Loading spinner

Researchers Discover Dangerous Exposure of Sensitive Kubernetes Secrets Read More »

US Government Issues Guidance on SBOM Consumption

US Government Issues Guidance on SBOM Consumption 10/11/2023 at 15:01 By Ionut Arghire CISA, NSA, and ODNI issue new guidance on managing open source software and SBOMs to maintain awareness on software security. The post US Government Issues Guidance on SBOM Consumption appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

React to this headline:

Loading spinner

US Government Issues Guidance on SBOM Consumption Read More »

Risk Ledger Raises £6.25 Million for Supply Chain Security Solution

Risk Ledger Raises £6.25 Million for Supply Chain Security Solution 09/11/2023 at 15:48 By Ionut Arghire UK-based Risk Ledger has raised £6.25 million (~$7.65 million) in Series A funding to prevent supply chain attacks. The post Risk Ledger Raises £6.25 Million for Supply Chain Security Solution appeared first on SecurityWeek. This article is an excerpt

React to this headline:

Loading spinner

Risk Ledger Raises £6.25 Million for Supply Chain Security Solution Read More »

Supply Chain Startup Chainguard Scores $61 Million Series B

Supply Chain Startup Chainguard Scores $61 Million Series B 01/11/2023 at 18:47 By Ryan Naraine Washington startup Chainguard banks $61 million in new financing as investors make hefty wagers on software supply chain security companies. The post Supply Chain Startup Chainguard Scores $61 Million Series B appeared first on SecurityWeek. This article is an excerpt

React to this headline:

Loading spinner

Supply Chain Startup Chainguard Scores $61 Million Series B Read More »

North Korean Hackers Exploiting Recent TeamCity Vulnerability

North Korean Hackers Exploiting Recent TeamCity Vulnerability 19/10/2023 at 14:01 By Ionut Arghire Multiple North Korean hacking groups have exploited a recent TeamCity vulnerability and Microsoft warns of potential supply chain attacks. The post North Korean Hackers Exploiting Recent TeamCity Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

React to this headline:

Loading spinner

North Korean Hackers Exploiting Recent TeamCity Vulnerability Read More »

Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk

Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk 11/10/2023 at 19:01 By Ryan Naraine Flaw poses a direct threat to the SOCKS5 proxy handshake process in cURL and can be exploited remotely in some non-standard configurations. The post Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk appeared first on SecurityWeek. This

React to this headline:

Loading spinner

Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk Read More »

US Government Releases Security Guidance for Open Source Software in OT, ICS

US Government Releases Security Guidance for Open Source Software in OT, ICS 11/10/2023 at 17:02 By Ionut Arghire CISA, FBI, NSA, and US Treasury published new guidance on improving the security of open source software in OT and ICS. The post US Government Releases Security Guidance for Open Source Software in OT, ICS appeared first

React to this headline:

Loading spinner

US Government Releases Security Guidance for Open Source Software in OT, ICS Read More »

Taiwan Probes Firms Suspected of Selling Chip Equipment to China’s Huawei Despite US Sanctions

Taiwan Probes Firms Suspected of Selling Chip Equipment to China’s Huawei Despite US Sanctions 07/10/2023 at 15:47 By Associated Press Taiwan authorities are investigating four Taiwan-based companies suspected of helping China’s Huawei Technologies to build semiconductor facilities. The post Taiwan Probes Firms Suspected of Selling Chip Equipment to China’s Huawei Despite US Sanctions appeared first

React to this headline:

Loading spinner

Taiwan Probes Firms Suspected of Selling Chip Equipment to China’s Huawei Despite US Sanctions Read More »

GitHub Improves Secret Scanning Feature With Expanded Token Validity Checks

GitHub Improves Secret Scanning Feature With Expanded Token Validity Checks 05/10/2023 at 19:02 By Ionut Arghire GitHub beefs up its secret scanning feature, now allowing users to check the validity of exposed credentials for major cloud services. The post GitHub Improves Secret Scanning Feature With Expanded Token Validity Checks appeared first on SecurityWeek. This article

React to this headline:

Loading spinner

GitHub Improves Secret Scanning Feature With Expanded Token Validity Checks Read More »

Linux Foundation Announces OpenPubkey Open Source Cryptographic Protocol

Linux Foundation Announces OpenPubkey Open Source Cryptographic Protocol 05/10/2023 at 15:31 By Eduard Kovacs The Linux Foundation has announced OpenPubkey, an open source cryptographic protocol that should help boost supply chain security.  The post Linux Foundation Announces OpenPubkey Open Source Cryptographic Protocol appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

React to this headline:

Loading spinner

Linux Foundation Announces OpenPubkey Open Source Cryptographic Protocol Read More »

CISA Unveils New HBOM Framework to Track Hardware Components

CISA Unveils New HBOM Framework to Track Hardware Components 27/09/2023 at 18:16 By Ryan Naraine CISA unveils a new Hardware Bill of Materials (HBOM) framework for buyers and sellers to communicate about components in physical products. The post CISA Unveils New HBOM Framework to Track Hardware Components appeared first on SecurityWeek. This article is an

React to this headline:

Loading spinner

CISA Unveils New HBOM Framework to Track Hardware Components Read More »

Microsoft AI Researchers Expose 38TB of Data, Including Keys, Passwords and Internal Messages

Microsoft AI Researchers Expose 38TB of Data, Including Keys, Passwords and Internal Messages 18/09/2023 at 21:18 By Ryan Naraine Exposed data includes backup of employees workstations, secrets, private keys, passwords, and over 30,000 internal Microsoft Teams messages. The post Microsoft AI Researchers Expose 38TB of Data, Including Keys, Passwords and Internal Messages appeared first on

React to this headline:

Loading spinner

Microsoft AI Researchers Expose 38TB of Data, Including Keys, Passwords and Internal Messages Read More »

Webinar Tomorrow: Unpacking the Secure Supply Chain Consumption Framework (S2C2F)

Webinar Tomorrow: Unpacking the Secure Supply Chain Consumption Framework (S2C2F) 06/09/2023 at 20:01 By SecurityWeek News Join Microsoft and Finite State for a webinar that will introduce a new strategy for securing the software supply chain. The post Webinar Tomorrow: Unpacking the Secure Supply Chain Consumption Framework (S2C2F) appeared first on SecurityWeek. This article is

React to this headline:

Loading spinner

Webinar Tomorrow: Unpacking the Secure Supply Chain Consumption Framework (S2C2F) Read More »

New ‘Carderbee’ APT Targeted Chinese Security Software in Supply Chain Attack

New ‘Carderbee’ APT Targeted Chinese Security Software in Supply Chain Attack 22/08/2023 at 14:33 By Ionut Arghire A new APT group called Carderbee has been observed deploying the PlugX backdoor via a supply chain attack targeting organizations in Hong Kong. The post New ‘Carderbee’ APT Targeted Chinese Security Software in Supply Chain Attack appeared first

React to this headline:

Loading spinner

New ‘Carderbee’ APT Targeted Chinese Security Software in Supply Chain Attack Read More »

Google Brings AI Magic to Fuzz Testing With Eye-Opening Results

Google Brings AI Magic to Fuzz Testing With Eye-Opening Results 17/08/2023 at 20:46 By Ryan Naraine Google sprinkles magic of generative-AI into its open source fuzz testing infrastructure and finds immediate success with code coverage. The post Google Brings AI Magic to Fuzz Testing With Eye-Opening Results appeared first on SecurityWeek. This article is an

React to this headline:

Loading spinner

Google Brings AI Magic to Fuzz Testing With Eye-Opening Results Read More »

CISA Calls Urgent Attention to UEFI Attack Surfaces

CISA Calls Urgent Attention to UEFI Attack Surfaces 04/08/2023 at 03:03 By Ryan Naraine The US government’s cybersecurity agency describes UEFI as “critical attack surface” that requires urgent security attention. The post CISA Calls Urgent Attention to UEFI Attack Surfaces appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

React to this headline:

Loading spinner

CISA Calls Urgent Attention to UEFI Attack Surfaces Read More »

Software Supply Chain Startup Endor Labs Scores Massive $70M Series A Round

Software Supply Chain Startup Endor Labs Scores Massive $70M Series A Round 03/08/2023 at 11:04 By Ryan Naraine Endor Labs has closed a massive $70 million Series A round of financing to fuel ambitious plans to build a dependency lifecycle management platform.   The post Software Supply Chain Startup Endor Labs Scores Massive $70M Series A

React to this headline:

Loading spinner

Software Supply Chain Startup Endor Labs Scores Massive $70M Series A Round Read More »

Socket Scores $20M as Investors Bet on Software Supply Chain Security Startups

Socket Scores $20M as Investors Bet on Software Supply Chain Security Startups 01/08/2023 at 17:34 By Ryan Naraine San Francisco startup Socket raises $20 million as investors continue to bet on companies in the open source software security category. The post Socket Scores $20M as Investors Bet on Software Supply Chain Security Startups appeared first

React to this headline:

Loading spinner

Socket Scores $20M as Investors Bet on Software Supply Chain Security Startups Read More »

Verifying Software Integrity With Sigstore

Verifying Software Integrity With Sigstore 11/07/2023 at 17:48 By Matt Honea Signing code is very important to defend against supply chain attacks, but it’s also one of the most cumbersome to implement for internal development. The post Verifying Software Integrity With Sigstore appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

React to this headline:

Loading spinner

Verifying Software Integrity With Sigstore Read More »

Infisical Snags $2.8M Seed Funding for Secrets Sprawl Security Tech

Infisical Snags $2.8M Seed Funding for Secrets Sprawl Security Tech 05/07/2023 at 19:47 By Ryan Naraine Infisical banks $2.8 million in seed funding as investors continue to bet on companies in the software supply chain security space. The post Infisical Snags $2.8M Seed Funding for Secrets Sprawl Security Tech appeared first on SecurityWeek. This article

React to this headline:

Loading spinner

Infisical Snags $2.8M Seed Funding for Secrets Sprawl Security Tech Read More »

Scroll to Top