software-supply-chain
58 articles with this tag
HIGH
HIGH
INFO
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
LOW
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
MEDIUM
INFO
MEDIUM
INFO
CRITICAL
MEDIUM
INFO
MEDIUM
INFO
INFO
CRITICAL
HIGH
INFO
HIGH
INFO
INFO
MEDIUM
INFO
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
INFO
HIGH
INFO
HIGH
INFO
INFO
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
INFO
INFO
INFO
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
AI Coding Tools Now a Prime Target for Threat Actors, Google Warns
[NEU] [mittel] Sonatype Nexus Repository Manager: Mehrere Schwachstellen ermöglichen Denial of Service
Exploited JFrog Artifactory bug puts software supply chain on alert
ATM Flaws Reveal Key Weaknesses in the Software Supply Chain
Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos
Two alleged TeamPCP hackers arrested over global supply chain attacks
Moving from Minimus to Docker Hardened Images
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
North Korean Hackers Tied to Rust Supply Chain Attack
JFrog Artifactory Flaws Enable Software Supply Chain Attacks
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
ChainDrop: Inside a Self-Propagating npm Worm
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
ChainDrop credential stealing worm infects over 400 npm packages
Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Hooks
Top AIs invent same fake PyPl and npm package names
Open-source maintainers still work underfunded as sponsorship crosses $100 million
It's looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns
EU Cyber Resilience Act: Overview, Requirements, and Timelines
Hole in widely-used FFmpeg codec could crash media servers or enable RCE
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
OpenAI rolls out AI-led push to fix open-source software flaws
Novo Nordisk Breach Exposes Software Development Pipeline Risk
Software supply chains are heading for a transparency test
Docker joins the Athena coalition: a cross-industry collaboration for supply chain security
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
Prompt injection still drives most agentic AI security failures in production
OWASP Dependency-Track 5.0 Is Now Generally Available
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
What is Software Supply Chain Security?
Hardened Images Explained: Fewer CVEs, Smaller Attack Surface
depthfirst adds pre-install protection against malicious dependencies
IBM and Red Hat want to become the ‘security clearinghouse’ for open source applications in the enterprise
Attackers Move Past Typosquatting to Realistic Package Impersonation
Laravel-Lang Packages Poisoned for Malware Delivery
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
Laravel Lang packages hijacked to deploy credential-stealing malware
A hacker group is poisoning open source code at an unprecedented scale
Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise
SAP npm package attack highlights risks in developer tools and CI/CD pipelines
Emerging Enterprise Security Risks of AI
Are you thinking about software supply chain attacks? #hacker @endingwithali #cybersecurity
Legitify: Open-source scanner for security misconfigurations on GitHub and GitLab
Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign
Microsoft Abruptly Terminates VeraCrypt Account, Halting Windows Updates
Supply chain security is now a board-level issue: Here’s what CSOs need to know
Defending Your Software Supply Chain: What Every Engineering Team Should Do Now
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069
Breakdown: How TeamPCP hid malware inside WAV files using audio steganography
Telnyx package on PyPI compromised by TeamPCP. WAV steganography used for payload delivery
Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets
Open-source security debt grows across commercial software
Securing the Agentic Endpoint
Die besten DAST- & SAST-Tools