Software Supply Chain Security Category - Security Boulevard https://securityboulevard.com/category/editorial-calendar/software-supply-chain-security/ The Home of the Security Bloggers Network Mon, 24 Jul 2023 17:05:36 +0000 en-US hourly 1 https://wordpress.org/?v=6.2.2 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Software Supply Chain Security Category - Security Boulevard https://securityboulevard.com/category/editorial-calendar/software-supply-chain-security/ 32 32 133346385 ‘China’ Azure Breach: MUCH Worse Than Microsoft Said https://securityboulevard.com/2023/07/azure-breach-worse-richixbw/ Mon, 24 Jul 2023 17:03:58 +0000 https://securityboulevard.com/?p=1982521 Satya Nadella and President Xi Jinping

Storm-0558 Breaks: Satya and Pooh, sitting in a tree, K.I.S.S.I.N.G.

The post ‘China’ Azure Breach: MUCH Worse Than Microsoft Said appeared first on Security Boulevard.

]]>
1982521
CISA Warning: MOVEit Has Yet Another Zero-Day SQL Injection RCE Bug [updated] https://securityboulevard.com/2023/06/moveit-yet-another-0day-richixbw/ Fri, 16 Jun 2023 16:01:55 +0000 https://securityboulevard.com/?p=1978738 Mark Quashie, a/k/a The Mad Stuntman

Once is happenstance. Twice is coincidence. Three times is sheer incompetence.

The post CISA Warning: MOVEit Has Yet Another Zero-Day SQL Injection RCE Bug [updated] appeared first on Security Boulevard.

]]>
1978738
Has the Altruism Model of Open Source Security Peaked? https://securityboulevard.com/2023/05/has-the-altruism-model-of-open-source-security-peaked/ Thu, 04 May 2023 13:00:36 +0000 https://securityboulevard.com/?p=1973622 OpenText OCSF WhiteSource Log4j window Proofpoint Open Source Security

With an executive order, the Biden administration attempted to address concerns around open source software’s security. In Section 4 of Executive Order 14028, Improving the Nation’s Cybersecurity, open source and the software supply chain was specifically mentioned, with a requirement for “ensuring and attesting, to the extent practicable, to the integrity and provenance of open..

The post Has the Altruism Model of Open Source Security Peaked? appeared first on Security Boulevard.

]]>
1973622
Companies scramble to cover software supply chain security gaps: 3 key survey takeaways https://securityboulevard.com/2023/04/companies-scramble-to-cover-software-supply-chain-security-gaps-3-key-survey-takeaways/ Thu, 20 Apr 2023 13:00:00 +0000 https://www.reversinglabs.com/blog/companies-scramble-to-cover-the-software-supply-chain-security-gaps-survey-takeaways Companies scramble to cover software supply chain security gaps: 3 key survey takeaways

The cyber risks posed by vulnerable internal, open-source and third-party software that make up a modern supply chain are a source of intense concern for both for development teams and security operations centers within enterprises, according to a recent Dimensional Research survey of more than 321 IT professionals commissioned by ReversingLabs.

The ReversingLabs Software Supply Chain Risk Survey polled executives and IT professionals responsible for software at enterprise-scale companies. Respondents were split between North America (67%) and Europe (33%), with a plurality working in technology (19%), financial services (13%), healthcare (9%) and telecommunications (8%). 

The post Companies scramble to cover software supply chain security gaps: 3 key survey takeaways appeared first on Security Boulevard.

]]>
1972549
Don’t Trust the Security of the Software Supply Chain https://securityboulevard.com/2023/04/dont-trust-the-security-of-the-software-supply-chain/ Thu, 06 Apr 2023 12:00:04 +0000 https://securityboulevard.com/?p=1970628 MOVEit supply chain cloud security manufacturing remote

Now more than ever, organizations are relying on the supply chain for basic business operations. According to Charlie Jones, director of product management with ReversingLabs, there are two reasons for this: The global trend of digitalization and the rapid move to remote work during the pandemic. What those trends did was increase the reliance enterprise..

The post Don’t Trust the Security of the Software Supply Chain appeared first on Security Boulevard.

]]>
1970628
White House Moves to Address Software Supply Chain Security https://securityboulevard.com/2023/04/white-house-moves-to-address-software-supply-chain-security/ Tue, 04 Apr 2023 12:00:28 +0000 https://securityboulevard.com/?p=1970626 white house supply chain

No one wants a repeat of the SUNBURST cyberattack, but without any action to improve cybersecurity within the software supply chain, another SUNBURST—or worse—attack is inevitable. And we still may see a devastating attack that takes down critical infrastructure or cripples major business systems, but at least there are steps being made to finally address..

The post White House Moves to Address Software Supply Chain Security appeared first on Security Boulevard.

]]>
1970626
Scams Lost US $10 BILLION in 2022 — Crypto Fraud Grows Fast https://securityboulevard.com/2023/03/fbi-ic3-scam-report-crypto-richixbw/ Thu, 16 Mar 2023 19:14:41 +0000 https://securityboulevard.com/?p=1968710

Ben is disappointed: FBI reports huge rise in cryptocurrency investment scams. Why am I not surprised?

The post Scams Lost US $10 BILLION in 2022 — Crypto Fraud Grows Fast appeared first on Security Boulevard.

]]>
1968710
White House to Regulate Cloud Security: Good Luck With That https://securityboulevard.com/2023/03/biden-regulate-cloud-security-richixbw/ Mon, 13 Mar 2023 18:33:34 +0000 https://securityboulevard.com/?p=1968238

Be careful what you wish for: Biden wants new regulations for cloud providers—but we’re not sure it’ll help.

The post White House to Regulate Cloud Security: Good Luck With That appeared first on Security Boulevard.

]]>
1968238
Voice-Clone AI Scams — it’s NOT ME on the Phone, Grandma https://securityboulevard.com/2023/03/voice-ai-scam-richixbw/ Mon, 06 Mar 2023 18:07:57 +0000 https://securityboulevard.com/?p=1966765

Voice AI tech being misused by scammers: Scrotes fake your voice and call your grandparents. Then “you” beg them for money.

The post Voice-Clone AI Scams — it’s NOT ME on the Phone, Grandma appeared first on Security Boulevard.

]]>
1966765
Microsoft FAIL: ‘BlackLotus’ Bootkit Breaks Secure Boot https://securityboulevard.com/2023/03/blacklotus-secure-boot-richixbw/ Fri, 03 Mar 2023 16:29:39 +0000 https://securityboulevard.com/?p=1966630

The BlackLotus malware targets UEFI Secure Boot. For a mere $5000, you too can own it.

The post Microsoft FAIL: ‘BlackLotus’ Bootkit Breaks Secure Boot appeared first on Security Boulevard.

]]>
1966630