Join Microsoft and Finite State for a webinar that will introduce a new strategy for securing the software supply chain.
The post Webinar Tomorrow: Unpacking the Secure Supply Chain Consumption Framework (S2C2F) appeared first on SecurityWeek.
Join Microsoft and Finite State for a webinar that will introduce a new strategy for securing the software supply chain.
The post Webinar Tomorrow: Unpacking the Secure Supply Chain Consumption Framework (S2C2F) appeared first on SecurityWeek.
A new APT group called Carderbee has been observed deploying the PlugX backdoor via a supply chain attack targeting organizations in Hong Kong.
The post New ‘Carderbee’ APT Targeted Chinese Security Software in Supply Chain Attack appeared first on SecurityWeek.
Google sprinkles magic of generative-AI into its open source fuzz testing infrastructure and finds immediate success with code coverage.
The post Google Brings AI Magic to Fuzz Testing With Eye-Opening Results appeared first on SecurityWeek.
The US government’s cybersecurity agency describes UEFI as “critical attack surface” that requires urgent security attention.
The post CISA Calls Urgent Attention to UEFI Attack Surfaces appeared first on SecurityWeek.
Endor Labs has closed a massive $70 million Series A round of financing to fuel ambitious plans to build a dependency lifecycle management platform.
The post Software Supply Chain Startup Endor Labs Scores Massive $70M Series A Round appeared first on SecurityWeek.
San Francisco startup Socket raises $20 million as investors continue to bet on companies in the open source software security category.
The post Socket Scores $20M as Investors Bet on Software Supply Chain Security Startups appeared first on SecurityWeek.
Signing code is very important to defend against supply chain attacks, but it’s also one of the most cumbersome to implement for internal development.
The post Verifying Software Integrity With Sigstore appeared first on SecurityWeek.
Infisical banks $2.8 million in seed funding as investors continue to bet on companies in the software supply chain security space.
The post Infisical Snags $2.8M Seed Funding for Secrets Sprawl Security Tech appeared first on SecurityWeek.
Rapid7 analyzes the Japan threat landscape and warns that attacks against the third-largest economy in the world have global consequences.
The post Rapid7: Japan Threat Landscape Takes on Global Significance appeared first on SecurityWeek.
HashiCorp acquires BluBracket secrets-scanning technology to help businesses block accidental leaks and fight secret sprawl.
The post HashiCorp Buys BluBracket for Secrets Scanning Tech appeared first on SecurityWeek.