home.social

#softwaresupplychainsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #softwaresupplychainsecurity, aggregated by home.social.

fetched live
  1. With all the usual big-company hype in the news this week, it was easy to overlook the dramatic rescue of a relatively small player in the crucial #softwaresupplychainsecurity market, but my colleague Benjamin Lutkevich was on the case.

    He covered the eleventh-hour acquisition of hardened-containers provider #Minimus and highlighted its implications for enterprises considering their next #DevSecOps purchase.

    Check it out here: techtarget.com/it-infrastructu

  2. With all the usual big-company hype in the news this week, it was easy to overlook the dramatic rescue of a relatively small player in the crucial #softwaresupplychainsecurity market, but my colleague Benjamin Lutkevich was on the case.

    He covered the eleventh-hour acquisition of hardened-containers provider #Minimus and highlighted its implications for enterprises considering their next #DevSecOps purchase.

    Check it out here: techtarget.com/it-infrastructu

  3. With all the usual big-company hype in the news this week, it was easy to overlook the dramatic rescue of a relatively small player in the crucial market, but my colleague Benjamin Lutkevich was on the case.

    He covered the eleventh-hour acquisition of hardened-containers provider and highlighted its implications for enterprises considering their next purchase.

    Check it out here: techtarget.com/it-infrastructu

  4. With all the usual big-company hype in the news this week, it was easy to overlook the dramatic rescue of a relatively small player in the crucial #softwaresupplychainsecurity market, but my colleague Benjamin Lutkevich was on the case.

    He covered the eleventh-hour acquisition of hardened-containers provider #Minimus and highlighted its implications for enterprises considering their next #DevSecOps purchase.

    Check it out here: techtarget.com/it-infrastructu

  5. With all the usual big-company hype in the news this week, it was easy to overlook the dramatic rescue of a relatively small player in the crucial #softwaresupplychainsecurity market, but my colleague Benjamin Lutkevich was on the case.

    He covered the eleventh-hour acquisition of hardened-containers provider #Minimus and highlighted its implications for enterprises considering their next #DevSecOps purchase.

    Check it out here: techtarget.com/it-infrastructu

  6. #Rust supply-chain attack: the popular `arrayref` crate (245mln downloads) was compromised to run a remote payload at build time. Simply running `cargo build` was enough to get infected:
    #SoftwareSupplyChainSecurity
    👇
    stepsecurity.io/blog/arrayref-

  7. #Rust supply-chain attack: the popular `arrayref` crate (245mln downloads) was compromised to run a remote payload at build time. Simply running `cargo build` was enough to get infected:
    #SoftwareSupplyChainSecurity
    👇
    stepsecurity.io/blog/arrayref-

  8. #Rust supply-chain attack: the popular `arrayref` crate (245mln downloads) was compromised to run a remote payload at build time. Simply running `cargo build` was enough to get infected:
    #SoftwareSupplyChainSecurity
    👇
    stepsecurity.io/blog/arrayref-

  9. #Rust supply-chain attack: the popular `arrayref` crate (245mln downloads) was compromised to run a remote payload at build time. Simply running `cargo build` was enough to get infected:
    #SoftwareSupplyChainSecurity
    👇
    stepsecurity.io/blog/arrayref-

  10. #Rust supply-chain attack: the popular `arrayref` crate (245mln downloads) was compromised to run a remote payload at build time. Simply running `cargo build` was enough to get infected:
    #SoftwareSupplyChainSecurity
    👇
    stepsecurity.io/blog/arrayref-

  11. #Snowflake’s GitHub Action introduced via #AI-assisted PR, contained an injection flaw that could be exploited to access sensitive data in Snowflake's internal Jira.
    An example of AI-assisted coding creating real #SoftwareSupplyChainSecurity risk:
    👇
    wiz.io/blog/red-agent-snowflak

  12. #Snowflake’s GitHub Action introduced via #AI-assisted PR, contained an injection flaw that could be exploited to access sensitive data in Snowflake's internal Jira.
    An example of AI-assisted coding creating real #SoftwareSupplyChainSecurity risk:
    👇
    wiz.io/blog/red-agent-snowflak

  13. #Snowflake’s GitHub Action introduced via #AI-assisted PR, contained an injection flaw that could be exploited to access sensitive data in Snowflake's internal Jira.
    An example of AI-assisted coding creating real #SoftwareSupplyChainSecurity risk:
    👇
    wiz.io/blog/red-agent-snowflak

  14. #Snowflake’s GitHub Action introduced via #AI-assisted PR, contained an injection flaw that could be exploited to access sensitive data in Snowflake's internal Jira.
    An example of AI-assisted coding creating real #SoftwareSupplyChainSecurity risk:
    👇
    wiz.io/blog/red-agent-snowflak

  15. #Snowflake’s GitHub Action introduced via #AI-assisted PR, contained an injection flaw that could be exploited to access sensitive data in Snowflake's internal Jira.
    An example of AI-assisted coding creating real #SoftwareSupplyChainSecurity risk:
    👇
    wiz.io/blog/red-agent-snowflak

  16. Sios Technology signs Chainguard partnership for Japan OSS security

    KEY POINTSSios Technology signs partnership with U.S.-based Chainguard from July 24, 2026Collaboration combines Sios OSS, API and cloud…
    #EuropeSays #Japan #JP #Chainguard #ChainguardContainers #ChainguardLibraries #DevSecOps #OSS #SiosTechnology #softwaresupplychainsecurity
    europesays.com/japan/63475/

  17. #JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security:

    #SoftwareSupplyChainSecurity
    👇
    jscrambler.com/blog/security-i

  18. #JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security:

    #SoftwareSupplyChainSecurity
    👇
    jscrambler.com/blog/security-i

  19. #JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security:

    #SoftwareSupplyChainSecurity
    👇
    jscrambler.com/blog/security-i

  20. #JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security:

    #SoftwareSupplyChainSecurity
    👇
    jscrambler.com/blog/security-i

  21. #JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security:

    #SoftwareSupplyChainSecurity
    👇
    jscrambler.com/blog/security-i

  22. #NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs:
    #SoftwareSupplyChainSecurity
    👇
    socket.dev/blog/jscrambler-sup

  23. #NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs:
    #SoftwareSupplyChainSecurity
    👇
    socket.dev/blog/jscrambler-sup

  24. #NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs:
    #SoftwareSupplyChainSecurity
    👇
    socket.dev/blog/jscrambler-sup

  25. #NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs:
    #SoftwareSupplyChainSecurity
    👇
    socket.dev/blog/jscrambler-sup

  26. #NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs:
    #SoftwareSupplyChainSecurity
    👇
    socket.dev/blog/jscrambler-sup