Danger: Researchers exploit gaps in connected vehicle software supply chain
Researchers compromised source code and development infrastructure for Mercedes-Benz and SiriusXM Connected Vehicle Services, raising security concerns. A group of researchers probing the security of applications and infrastructure that supports connected vehicles discovered they could access the development environments and raw application source code of German automaker Mercedes Benz and ... Read More
After hack, CircleCI tells devs to update secrets now
In this latest attack on software development environments, the CircleCI platform may have exposed secrets used by millions of software developers ... Read More
New supply chain mandates: Uncle Sam wants you (to secure your software)!
Here are the key elements of Executive Order 14028, and software supply chain security guidance from the Enduring Security Framework working group. ... Read More
New supply chain mandates: Uncle Sam wants you (to secure your software)!
Here are the key elements of Executive Order 14028, and software supply chain security guidance from the Enduring Security Framework working group. ... Read More
National Cyber Director: Higher bar for software supply chain security is key to cyber resilience
Chris Inglis said the government is setting a new bar for supply chain security as the national cybersecurity focus shifts from incident response to cyber resilience ... Read More
National Cyber Director: Higher bar for software supply chain security is key to cyber resilience
Chris Inglis said the government is setting a new bar for supply chain security as the national cybersecurity focus shifts from incident response to cyber resilience ... Read More
Gaps in the NVD increase U.S. cyber threat
Discrepancies in reports to the national vulnerability databases (NVD) show the U.S. lags behind China, exposing U.S. firms to cyber attacks ... Read More
The pandemic turned out to be a boon for public-private cybersecurity cooperation
The shift to remote work punched holes in government networks. But it also fostered a transformation in public-private cooperation, one NSA official noted at LABScon. ... Read More