Software supply chain security is broader than SolarWinds and Log4J
Here’s a comprehensive look at some of the lesser-known, but no less serious, types of software supply chain attacks.
Read moreA 360° view on tech world
Here’s a comprehensive look at some of the lesser-known, but no less serious, types of software supply chain attacks.
Read moreThe U.S. government’s cybersecurity agency says hackers backed by the Iranian government compromised a federal agency that failed to patch against Log4Shell, a vulnerability fixed almost a year ago. In an alert published Thursday, the Cybersecurity and Infrastructure Security Agency said that a federal civilian executive branch organization (FCEB) was breached by Iranian government hackers […]
Read moreAx Sharma Contributor Share on Twitter Ax Sharma is a security researcher and reporter. His areas of interest include open source software security, malware analysis, data breaches and scam investigations. If combating attacks and hijackings of legitimate software on open source registries like npm weren’t challenging enough, app makers are increasingly experiencing the consequences of […]
Read moreConsidering recent APT41 attacks, organizations that continue to leave the Log4Shell flaw unaddressed are hitting the snooze button when it comes to the wake-up calls from attackers.
Read more