Software Supply Chain Security - Security Boulevard https://securityboulevard.com/category/editorial-calendar/software-supply-chain-security/ The Home of the Security Bloggers Network Fri, 29 Mar 2024 17:19:26 +0000 en-US hourly 1 https://wordpress.org/?v=6.4.3 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Software Supply Chain Security - Security Boulevard https://securityboulevard.com/category/editorial-calendar/software-supply-chain-security/ 32 32 133346385 PyPI Goes Quiet After Huge Malware Attack: 500+ Typosquat Fakes Found https://securityboulevard.com/2024/03/pypi-suspended-500-fakes-richixbw/ Fri, 29 Mar 2024 17:19:26 +0000 https://securityboulevard.com/?p=2013426 Closeup of person going “Shhh!”

Emergency stop button: The Python Package Index was drowning in malicious code again, so they had to shut down registration for cleanup.

The post PyPI Goes Quiet After Huge Malware Attack: 500+ Typosquat Fakes Found appeared first on Security Boulevard.

]]>
2013426
Revealed: Facebook’s “Incredibly Aggressive” Alleged Theft of Snapchat App Data https://securityboulevard.com/2024/03/ghostbusters-facebook-theft-snapchat-richixbw/ Wed, 27 Mar 2024 17:14:37 +0000 https://securityboulevard.com/?p=2013174 Smokey Bear / This-is-fine crossover

Meta MITM IAAP SSL bump: Zuck ordered “Project Ghostbusters”—with criminal consequences, says class action lawsuit.

The post Revealed: Facebook’s “Incredibly Aggressive” Alleged Theft of Snapchat App Data appeared first on Security Boulevard.

]]>
2013174
China Steals Defense Secrets ‘on Industrial Scale’ https://securityboulevard.com/2024/03/china-steals-secrets-f5-connectwise-richixbw/ Mon, 25 Mar 2024 17:08:40 +0000 https://securityboulevard.com/?p=2012892 a PRC flag flies in a stiff breeze

UNC5174 ❤ UNC302: CVSS 10 and 9.8 vulnerabilities exploited by Chinese threat actor for People’s Republic.

The post China Steals Defense Secrets ‘on Industrial Scale’ appeared first on Security Boulevard.

]]>
2012892
Apple M-Series FAIL: GoFetch Flaw Finds Crypto Keys https://securityboulevard.com/2024/03/apple-m-gofetch-richixbw/ Fri, 22 Mar 2024 18:56:32 +0000 https://securityboulevard.com/?p=2012710 A green worm on a juicy red apple

GoFAIL: Researchers worm their way into broken cache-filling microcode in most Macs and iPads.

The post Apple M-Series FAIL: GoFetch Flaw Finds Crypto Keys appeared first on Security Boulevard.

]]>
2012710
Google Splashes the Cash in Bug Bounty Bonanza: $59 Million to Date https://securityboulevard.com/2024/03/google-bug-bounty-vrp-richixbw/ Wed, 13 Mar 2024 16:57:09 +0000 https://securityboulevard.com/?p=2011800 Two stacks of money on top of a white table.

Wanna be a VRP VIP? Last year, $GOOG paid $10 million to ethical hackers for finding vulnerabilities.

The post Google Splashes the Cash in Bug Bounty Bonanza: $59 Million to Date appeared first on Security Boulevard.

]]>
2011800
Mitigating Lurking Threats in the Software Supply Chain https://securityboulevard.com/2024/03/mitigating-lurking-threats-in-the-software-supply-chain/ Tue, 12 Mar 2024 13:00:47 +0000 https://securityboulevard.com/?p=2011374 IONIX software supply chain, secure, Checkmarx Abnormal Security cyberattack supply chain cybersecurity

The first step to addressing software supply chain vulnerabilities and threats is to understand the most common attacks. Here's where to start.

The post Mitigating Lurking Threats in the Software Supply Chain appeared first on Security Boulevard.

]]>
2011374
Irony of Ironies: CISA Hacked — ‘by China’ https://securityboulevard.com/2024/03/cisa-ivanti-china-richixbw/ Mon, 11 Mar 2024 17:17:53 +0000 https://securityboulevard.com/?p=2011528 Director of the Cybersecurity and Infrastructure Security Agency, Jen Easterly

Free rides and traffic jams: U.S. Cybersecurity and Infrastructure Security Agency penetrated in February, via vuln in Ivanti.

The post Irony of Ironies: CISA Hacked — ‘by China’ appeared first on Security Boulevard.

]]>
2011528
Self-Replicating AI Malware is Here😱 #ComPromptMized https://securityboulevard.com/2024/03/compromptmized-ai-worm-malware-richixbw/ Tue, 05 Mar 2024 18:34:26 +0000 https://securityboulevard.com/?p=2010997 The Scream, by Edvard Munch

Skrik: Researchers worm themselves into your nightmares.

The post Self-Replicating AI Malware is Here😱 #ComPromptMized appeared first on Security Boulevard.

]]>
2010997
Cheap Video Doorbell Cams: Tools of Stalkers and Thieves https://securityboulevard.com/2024/03/video-doorbell-eken-richixbw/ Fri, 01 Mar 2024 16:43:56 +0000 https://securityboulevard.com/?p=2010690 An extreme closeup of a human eye

EKEN IoT FAIL: Amazon, Sears and Shein still sell security swerving stuff.

The post Cheap Video Doorbell Cams: Tools of Stalkers and Thieves appeared first on Security Boulevard.

]]>
2010690
GitHub Fights Forks — Millions of Them — Huge Software Supply Chain Security FAIL https://securityboulevard.com/2024/02/github-repo-confusion-supply-chain-richixbw/ Thu, 29 Feb 2024 16:37:11 +0000 https://securityboulevard.com/?p=2010508 A fork, wrapped in delicious pasta

Forking hell: Scrotebots clone thousands of projects, injecting malware millions of times.

The post GitHub Fights Forks — Millions of Them — Huge Software Supply Chain Security FAIL appeared first on Security Boulevard.

]]>
2010508