A cybersecurity startup is warning of a major, unattended weak link in the software supply chain: the vexing problem of valuable corporate secrets — API keys, usernames and passwords, and security certificates — publicly exposed in corporate repositories.
‘Serpent’ Backdoor Used in Malware Attacks on French Entities
French organizations in the construction, government, and real estate sectors have been targeted with a new backdoor in a string of malware attacks, according to a warning from Proofpoint.
Demystifying Zero Trust

While many vendors use terms that include “zero trust,” they often use it to mean different things
High-Severity Vulnerabilities Patched in BIND Server
The Internet Systems Consortium (ISC) has released security updates to fix multiple high-severity vulnerabilities in the widely deployed Berkeley Internet Name Domain (BIND) server software.
Software Supply Chain Weakness: Snyk Warns of ‘Deliberate Sabotage’ of NPM Ecosystem
Software supply chain security fears escalated again this week with the discovery of what’s being described as “deliberate sabotage” of code in the open-source npm package manager ecosystem.
NIST Releases ICS Cybersecurity Guidance for Manufacturers

NIST guide provides examples of commercial products that manufacturers can use to address specific security risks
SentinelOne to Acquire Attivo Networks for $616M
Enterprise cybersecurity powerhouse SentinelOne on Tuesday announced plans to spend $616 million to acquire Attivo Networks, a Silicon Valley startup that sells breach detection technology.
OneLayer Emerges From Stealth With $8.2M to Build Security for Private 5G Networks
Tel Aviv-based OneLayer emerged from stealth mode with $8.2 million in funding to build security for private 5G networks
HD Moore’s Rumble Raises $15M Series A Investment
Less than a year after emerging from stealth $5 million in seed funding, HD Moore’s Rumble asset management startup is attracting heavy interest from venture capital investors.
Mitel Devices Abused for DDoS Vector With Record-Breaking Amplification Ratio
Mitel enterprise collaboration products have been abused for distributed denial-of-service (DDoS) attacks that employ a new vector with a massive potential amplification ratio.












