Malicious package detection: Sonatype secures software supply chains

Malicious packages present a growing danger to software supply chains. From typosquatting attacks to sophisticated malware hidden within open source components, detecting and preventing malicious packages has become essential for ensuring the ...
Sonatype customers leading with innovation in the new year

Sonatype customers leading with innovation in the new year

As we kick off 2025, software's role in our daily lives has never been more apparent, and the integrity of our open source components has never been more important. We have the ...
Checkmarx Report Surfaces Software Supply Chain Compromises

Checkmarx Report Surfaces Software Supply Chain Compromises

A Checkmarx report found 56% of attacks against software supply chains resulted in thefts of credential and confidential data ...
Security Boulevard

Mastering SBOMs: Best practices

In our recent webinar, Mastering SBOMs: Best Practices, speakers, including Ilkka Turunen, Field CTO, Sonatype, Roger Smith, Global Testing and Digital Assurance Lead, DXC Technology, and Marc Luescher, Solution Architect, AWS, shed ...

Alert: NuGet Package SeroXen RAT Threat to .NET Developers

In a recent security issue, a deceptive NuGet package threatens .NET developers with the deployment of the SeroXen RAT, a harmful remote access trojan. Because the .NET framework is no longer limited ...

Software Supply Chain Risks for Low- and No-Code Application Development

Supply chain attacks occur when a third-party vendor or partner with less robust security measures is breached, allowing attackers to indirectly gain access to an organization. This can happen through backdoors planted ...

What is the W4SP Information Stealer?

Since mid-October, W4SP malware is attacking software supply chains; in this case, it's using Python packages to launch an information stealer. The post What is the W4SP Information Stealer? appeared first on ...
Keynote: 25 Years in AppSec: Looking Back, Looking Forward - Adam Shostack

OWASP® Global AppSec US 2021 Virtual – Ronen Slavin’s ‘Analyzing Google’s SLSA Framework For Securing Software Supply Chains’

Our thanks to both the OWASP® Foundation and the OWASP Global AppSec US 2021 Virtual Conference Presenters for publishing their well-crafted application security videos on the organization’s’ YouTube channel. Permalink ...
‘Trojan Source’ Makes Scary Headlines—But it’s Not New

‘Trojan Source’ Makes Scary Headlines—But it’s Not New

Trojan Source “threatens the security of all code,” screams a widely shared article. Poppycock. There’s nothing new here ...
Security Boulevard
Consumer Confidence in Data Security Plummets

Consumer Confidence in Data Security Plummets

Organizations’ increasing use of contractors, freelancers and other third-party workers is weakening consumers’ trust in their data security, according to a study by SecZetta. The survey of more than 2,000 U.S. adults ...
Security Boulevard