home.social

#softwaresupplychainsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #softwaresupplychainsecurity, aggregated by home.social.

  1. A new article is live on Cyfinoid Research:

    AppSec in the New Security Cost Model

    https://cyfinoid.com/appsec-in-the-new-security-cost-model/

    The core argument is simple. AppSec is still reacting to AI by improving the vulnerability queue. Better reachability, exploitability scoring, CVE enrichment, and prioritization help, but they were designed around an older cost model.

    AI changes attacker iteration cost. The defender bottleneck is increasingly verification capacity.

    Can we safely validate, fix, test, deploy, and monitor changes at the required pace?

    That changes how we should think about AppSec programs. Smaller stacks matter. Attack surface reduction matters. Bug-class elimination matters. Compensating controls need expiry and replacement plans. Test coverage becomes a security capability. Safe remediation throughput becomes a useful metric.

    I also connect this to Goldratt’s Theory of Constraints and the SaaS vs in-house ownership tradeoff, especially for SMBs.

    The question is no longer only which vulnerability should be fixed first. The question is how much verified remediation an organization can safely produce.

    #AI #appsec #softwaresupplychainsecurity

  2. Malicious updates were published to official #dYdX trading packages on #npm and #PyPI, delivering a wallet stealer and remote access malware.

    Malware was published via compromised maintainer accounts:
    #SoftwareSupplyChainSecurity
    👇
    thehackernews.com/2026/02/comp

  3. Brett Smith, distinguished software developer at #AI and #datamanagement software and services company SAS, has spent nine of his 13 years with the company focused on #softwaresupplychainsecurity, managing #DevSecOps and compliance for a 3,000-developer organization. He shares the good, the bad and the ugly of the journey to date, and his outlook for the future in this week's episode of the #ITOps Query #vodcast:

    youtu.be/Qw1QONTpJok?si=rPq3SV

  4. Believe it or not, things got a little spicy in #softwaresupplychainsecurity this week, with #Docker, Inc calling out Chainguard as it made its catalog of #DockerHardenedImages free under an #Apache2 license (to which Chainguard had some answers).

    In the meantime, #Chainguard launched EmeritOSS, a new support option for deprecated #OSS projects. #opensourcesecurity

    My writeup: techtarget.com/searchitoperati

  5. Believe it or not, things got a little spicy in #softwaresupplychainsecurity this week, with #Docker, Inc calling out Chainguard as it made its catalog of #DockerHardenedImages free under an #Apache2 license (to which Chainguard had some answers).

    In the meantime, #Chainguard launched EmeritOSS, a new support option for deprecated #OSS projects. #opensourcesecurity

    My writeup: techtarget.com/searchitoperati

  6. Believe it or not, things got a little spicy in this week, with , Inc calling out Chainguard as it made its catalog of free under an license (to which Chainguard had some answers).

    In the meantime, launched EmeritOSS, a new support option for deprecated projects.

    My writeup: techtarget.com/searchitoperati

  7. Believe it or not, things got a little spicy in #softwaresupplychainsecurity this week, with #Docker, Inc calling out Chainguard as it made its catalog of #DockerHardenedImages free under an #Apache2 license (to which Chainguard had some answers).

    In the meantime, #Chainguard launched EmeritOSS, a new support option for deprecated #OSS projects. #opensourcesecurity

    My writeup: techtarget.com/searchitoperati

  8. Believe it or not, things got a little spicy in #softwaresupplychainsecurity this week, with #Docker, Inc calling out Chainguard as it made its catalog of #DockerHardenedImages free under an #Apache2 license (to which Chainguard had some answers).

    In the meantime, #Chainguard launched EmeritOSS, a new support option for deprecated #OSS projects. #opensourcesecurity

    My writeup: techtarget.com/searchitoperati

  9. #VSCode: 24 malicious VS Code and #OpenVSX extensions are stealing developer credentials - spreading through popular names like Flutter, React, and Tailwind.

    Full list of malicious VSCode extensions in the article below:
    #SoftwareSupplyChainSecurity
    👇
    thehackernews.com/2025/12/glas

  10. Sometimes I wonder what would happen if

    oss developers simply list out every single bug report they receive on their website and clearly note we don’t have resources to fix it.

    And then list every single mega corp that uses that OSS library and clearly send out message informing the world we don’t fix bugs and since all of these orgs don’t like helping anyone using them is vulnerable.

    May be just may be that would give people an idea about putting pressure on wrong set of individuals.

    But most importantly it will make it clear for people where the responsibility of security for your customers lie with you or with third party.

    #softwaresupplychainsecurity #supplychaincompromise #opensource

  11. It's the first on-location episode of #ITOps Query! At #GitHubUniverse, Katie Norton, Research Manager for IDC's #DevSecOps and #softwaresupplychainsecurity practice, explains how a new extension to GitHub's #CodeQL reflects increased awareness of security as a dimension of code quality and much more! youtu.be/eCU3OKgOTWY?si=ndH9I3

  12. ⚠️#GitHub: Critical security incident involving the popular tj-actions/changed-files GitHub Action which contained credentials/secrets exfiltration malware! ☣️ (CVE-2025-30066)
    #SoftwareSupplyChainSecurity
    #tjactions
    👇
    stepsecurity.io/blog/harden-ru

  13. Timely for #Halloween - Joshua Corman and I discuss the scariest story I know of in IT - the mounting threats to the #cybersecurity of critical infrastructure.


    "We live in glass houses. And people are about to start throwing rocks."#ITOps #podcast #SBOM #softwaresupplychainsecurity #volttyphoon #secops #undisruptable27

    podbean.com/ew/pb-cuyq2-1724bf