Advertisement
Python Supply Chain: Malicious Packages Targeting Developers
Malicious Python packages exploit trusted ecosystems like PyPI, enabling supply chain attacks on developer systems. Learn about the threat and mitigation.
AI's Transformative Impact on Threat Intelligence and Defenses
AI is rapidly accelerating the threat landscape, enabling machine-speed attacks and increasing defender challenges. Prioritizing intelligence is key.
CISA's Updated SBOM Guidance: Enhancing Software Supply Chain Transparency
CISA has released updated SBOM guidance, refining field definitions for greater software supply chain transparency. Debate continues on its impact on risk management.
GitHub Adjusts Bug Bounty: Impact on Vulnerability Disclosure
GitHub is halving public bug bounty payouts and shifting top rewards to an invite-only VIP program, impacting vulnerability research and disclosure.
FakeGit Campaign Exploits GitHub for SmartLoader Malware
Analysis of the FakeGit campaign leveraging 7,600 GitHub repositories, including AI/MCP lures, to distribute SmartLoader malware. Learn detection and mitigation.
AI-Assisted Vulnerability Management: Operational Guardrails & Risks
Implement robust guardrails for AI-assisted vulnerability management. Learn to safely deploy LLM agents, reduce architectural risks, and prioritize human-led threat…
Advertisement
Linux Foundation's Project Akrites: Bolstering Open Source Security
Project Akrites aims to streamline vulnerability management across open source projects, enhancing reporting, patching, and disclosure processes for critical software.
RevEng.AI Secures $15M for AI-Powered Software Binary Analysis
RevEng.AI raises $15 million to scale BinNet, a proprietary AI model designed to automate binary analysis and detect hidden backdoors in software assets.
TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks
The TrapDoor campaign targets npm, PyPI, and Crates.io with over 384 malicious versions designed to exfiltrate developer credentials and sensitive data.
Software Supply Chain Security: Addressing Visibility Gaps
An analysis of the growing software supply chain crisis, focusing on the acceleration of vulnerability exploitation and the lack of systemic visibility.
Compromised Checkmarx Jenkins Plugin Spreads Infostealer
Official Checkmarx Jenkins AST plugin version 2023.2.7 was compromised with an infostealer, risking credentials and system data.
DPRK's 'Contagious Interview' Spreads RATs via Dev Repositories
DPRK threat actors are employing a 'contagious interview' scam, weaponizing compromised developer repositories to propagate RATs and malware across the software supply…
AI's Impact on Software Supply Chain Security and Vulnerability Management
AI is set to revolutionize software development, enabling 'instant software' and advanced vulnerability detection, profoundly reshaping future cybersecurity strategies.
Risks of AI-Driven Dependency Resolution and Software Maintenance
AI models often hallucinate version numbers and ignore security fixes during dependency resolution, increasing technical debt and supply chain risks.
InstallFix Attacks: Malvertising Spreads Fake Claude AI Code
InstallFix attacks leverage malvertising and ClickFix-style techniques to spread fake Claude AI code, targeting users of coding assistants and CLI operations.
AI Code Generation Poses Supply Chain Risk to Developer Machines
Learn how AI-generated code, like from Anthropic's Claude, can introduce vulnerabilities and malicious payloads, compromising developer machines and software supply…