A cybersecurity startup is warning of a major, unattended weak link in the software supply chain: the vexing problem of valuable corporate secrets — API keys, usernames and passwords, and security certificates — publicly exposed in corporate repositories.
‘Serpent’ Backdoor Used in Malware Attacks on French Entities
French organizations in the construction, government, and real estate sectors have been targeted with a new backdoor in a string of malware attacks, according to a warning from Proofpoint.
Italy Investigates Russia’s Kaspersky Antivirus Software
Italy’s data privacy watchdog said Friday it was investigating the “potential risks” that Russian antivirus software Kaspersky could be used to launch cyberattacks.
High-Severity Vulnerabilities Patched in BIND Server
The Internet Systems Consortium (ISC) has released security updates to fix multiple high-severity vulnerabilities in the widely deployed Berkeley Internet Name Domain (BIND) server software.
SATCOM Cybersecurity Alert Issued as Authorities Probe Possible Russian Attack
Todyl Banks $28M Series A Investment
Security and networking platform start-up Todyl on Thursday announced the closing of a $28 million Series A funding round.
The new investment round was led by Anthos Capital with participation from previous investors Blu Ventures, StoneMill Ventures, and Tech Operators.
Software Supply Chain Weakness: Snyk Warns of ‘Deliberate Sabotage’ of NPM Ecosystem
Software supply chain security fears escalated again this week with the discovery of what’s being described as “deliberate sabotage” of code in the open-source npm package manager ecosystem.
SolarWinds Warns of Attacks Targeting Web Help Desk Users
SolarWinds this week issued an alert to warn customers of potential cyberattacks targeting unpatched Web Help Desk (WHD) instances.
The WHD helpdesk solution provides a ticketing system, service and asset management capabilities, a centralized knowledge base, Active Directory integration, and more.
Most NASA Systems at Risk From Insider Threats: Audit
Most of the IT systems at the National Aeronautics and Space Administration (NASA) are exposed to higher-than-necessary risks from internal threats, a recent audit has concluded.
NIST Releases ICS Cybersecurity Guidance for Manufacturers

NIST guide provides examples of commercial products that manufacturers can use to address specific security risks













