software supply chain attacks
Microsoft Expands its Bug Bounty Program to Include Third-Party Code
Jeffrey Burt | | Artificial Intelligence (AI), Cloud computing security, log4jShell, Microsoft, microsoft bug bounty, open source software supply chain, React2Shell Attack, software supply chain attacks, SolarWinds Attacks, Third Party Risk
In a nod to the evolving threat landscape that comes with cloud computing and AI and the growing supply chain threats, Microsoft is broadening its bug bounty program to reward researchers who ...
Security Boulevard
SEC Dismisses Remains of Lawsuit Against SolarWinds and Its CISO
Jeffrey Burt | | Securities and Exchange Commission, software supply chain attacks, SolarWinds cybersecurity breach, Sunburst malware
The SEC dismissed the remain charges in the lawsuit filed in 2023 against software maker SolarWinds and CISO Timothy Brown in the wake of the massive Sunburst supply chain attack, in which ...
Security Boulevard
#Pixnapping: Android Timing Attack Sends Google Back to the Drawing Board
Richi Jennings | | android, Android 16, Android Application Hacking, Android attack, CVE-2025-48561, google, Pixnapping, Rowhammer, SB Blogwatch, Side-Channel, side-channel attack, side-channel attacks, software supply chain, software supply chain attack, software supply chain attacks
If at first you don’t succeed: Researchers discover a new way to steal secrets from Android apps ...
Security Boulevard
The New Perimeter is Your Supply Chain
Alan Shimel | | CI/CD pipeline compromise, Cloud-Native Application Security, cloud-native perimeter security, CNAPP security, DevOps Security, SBOM security, Sigstore provenance, SLSA Framework, software supply chain attacks, supply chain risk management
Alan examines why the software supply chain has become the new perimeter in cloud-native security. From SBOMs to SLSA and Sigstore, discover how leaders can defend against attacks that target dependencies, pipelines ...
Security Boulevard
Imperva’s Wildest 2025 AppSec Predictions
David Holmes | | AI, API security, Application Security, AppSec, GenAI, predictions, software supply chain attacks
Humans are spectacularly bad at predicting the future. Which is why, when someone appears to be able to do it on a regular basis, they are hailed as visionaries, luminaries and celebrated ...
‘Polyfill’ Supply Chain Threat: 4x Worse Than We Thought
Richi Jennings | | App Sec & Supply Chain Security, AppSec & Supply Chain Security, CloudFlare, Funnull, Javascript, Modern Software Supply Chains, Open Source and Software Supply Chain Risks, open source software supply chain, open source software supply chain security, polyfill, SB Blogwatch, secure software supply chain, software supply chain attack, software supply chain attacks, software supply chain hygiene, software supply chain risk, Software Supply Chain risks, Supply-Chain Insecurity
Spackle attack: Chinese company takes over widely used free web service—almost 400,000 websites at risk ...
Security Boulevard
Imperva Client-Side Protection Mitigates the Polyfill Supply Chain Attack
Erez Hasson | | Application Security, Client-Side Protection, imperva, polyfill, software supply chain attacks
The recent discovery of a website supply chain attack using the cdn.polyfill.io domain has left many websites vulnerable to malicious code injection. Once a trusted resource for adding JavaScript polyfills to websites, ...
WordPress Plugin Supply Chain Attack Gets Worse
Richi Jennings | | hacked WordPress, hacking wordpress, plug-in, plug-in vulnerability, plug-ins, rogue plug-in, SB Blogwatch, software supply chain, software supply chain attack, software supply chain attacks, software supply chain risk, Software Supply Chain risks, Supply-Chain Insecurity, Themes and Plug-ins, wordpress, WordPress plug-in, wordpress plugin update, Wordpress Plugin Vulnerability, WordPress Plugin Vulnerability Exploitation, WordPress Plugins, WordPress Plugins and Themes
30,000 websites at risk: Check yours ASAP! (800 Million Ostriches Can’t Be Wrong.) ...
Security Boulevard
GitLab ‘Perfect 10’ Bug Gets a CISA Warning: PATCH NOW
Richi Jennings | | cisa, CISA Advisories, CISA Advisory, CISA Alert, CISA KEV, cisa known exploited vulnerabilities, cisa known exploited vulnerabilities catalog, CISA Threat Update, CISA warning, CISA.gov, CVE-2023-7028, CVSS10, Cybersecurity Infrastructure Security Administration, GitLab, GitLab Community Edition, GitLab CVE-2023-7028 CVE-2023-5356, GitLab Enterprise Edition, GitLab Patches, GitLab Security, GitLab Vulnerability, NSA/CISA, Password reset, Password reset protection, SB Blogwatch, software supply chain, software supply chain attack, software supply chain attacks, software supply chain risk, Software Supply Chain risks, Supply-Chain Insecurity
Password reset FAILURE: The U.S. Cybersecurity and Infrastructure Security Agency warns GitLab users of a 100-day-old, maximum severity vulnerability ...
Security Boulevard
PyPI Goes Quiet After Huge Malware Attack: 500+ Typosquat Fakes Found
Richi Jennings | | code reuse, open source software supply chain security, PyPI, PyPI malicious packages, pypi vuln, pypi vulnerability, python, Python Malware, Python Packages, Python vulnerability, SB Blogwatch, secure software supply chain, software supply chain, software supply chain attack, software supply chain attacks, software supply chain hygiene, Software supply chain management, software supply chain risk, Software Supply Chain risks, software supply chain security, Software Supply Chain Security Risks, Software Supply Chain Security Weaknesses, typosquat, Typosquatting, typosquatting attacks
Emergency stop button: The Python Package Index was drowning in malicious code again, so they had to shut down registration for cleanup ...
Security Boulevard

