#softwaresupplychainsecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #softwaresupplychainsecurity, aggregated by home.social.
-
With all the usual big-company hype in the news this week, it was easy to overlook the dramatic rescue of a relatively small player in the crucial #softwaresupplychainsecurity market, but my colleague Benjamin Lutkevich was on the case.
He covered the eleventh-hour acquisition of hardened-containers provider #Minimus and highlighted its implications for enterprises considering their next #DevSecOps purchase.
Check it out here: https://www.techtarget.com/it-infrastructure/news/366649818/Rival-buyout-aids-customers-after-DevSecOps-firm-shutters
-
With all the usual big-company hype in the news this week, it was easy to overlook the dramatic rescue of a relatively small player in the crucial #softwaresupplychainsecurity market, but my colleague Benjamin Lutkevich was on the case.
He covered the eleventh-hour acquisition of hardened-containers provider #Minimus and highlighted its implications for enterprises considering their next #DevSecOps purchase.
Check it out here: https://www.techtarget.com/it-infrastructure/news/366649818/Rival-buyout-aids-customers-after-DevSecOps-firm-shutters
-
With all the usual big-company hype in the news this week, it was easy to overlook the dramatic rescue of a relatively small player in the crucial #softwaresupplychainsecurity market, but my colleague Benjamin Lutkevich was on the case.
He covered the eleventh-hour acquisition of hardened-containers provider #Minimus and highlighted its implications for enterprises considering their next #DevSecOps purchase.
Check it out here: https://www.techtarget.com/it-infrastructure/news/366649818/Rival-buyout-aids-customers-after-DevSecOps-firm-shutters
-
With all the usual big-company hype in the news this week, it was easy to overlook the dramatic rescue of a relatively small player in the crucial #softwaresupplychainsecurity market, but my colleague Benjamin Lutkevich was on the case.
He covered the eleventh-hour acquisition of hardened-containers provider #Minimus and highlighted its implications for enterprises considering their next #DevSecOps purchase.
Check it out here: https://www.techtarget.com/it-infrastructure/news/366649818/Rival-buyout-aids-customers-after-DevSecOps-firm-shutters
-
With all the usual big-company hype in the news this week, it was easy to overlook the dramatic rescue of a relatively small player in the crucial #softwaresupplychainsecurity market, but my colleague Benjamin Lutkevich was on the case.
He covered the eleventh-hour acquisition of hardened-containers provider #Minimus and highlighted its implications for enterprises considering their next #DevSecOps purchase.
Check it out here: https://www.techtarget.com/it-infrastructure/news/366649818/Rival-buyout-aids-customers-after-DevSecOps-firm-shutters
-
#Rust supply-chain attack: the popular `arrayref` crate (245mln downloads) was compromised to run a remote payload at build time. Simply running `cargo build` was enough to get infected:
#SoftwareSupplyChainSecurity
👇
https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack -
#Rust supply-chain attack: the popular `arrayref` crate (245mln downloads) was compromised to run a remote payload at build time. Simply running `cargo build` was enough to get infected:
#SoftwareSupplyChainSecurity
👇
https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack -
#Rust supply-chain attack: the popular `arrayref` crate (245mln downloads) was compromised to run a remote payload at build time. Simply running `cargo build` was enough to get infected:
#SoftwareSupplyChainSecurity
👇
https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack -
#Rust supply-chain attack: the popular `arrayref` crate (245mln downloads) was compromised to run a remote payload at build time. Simply running `cargo build` was enough to get infected:
#SoftwareSupplyChainSecurity
👇
https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack -
#Rust supply-chain attack: the popular `arrayref` crate (245mln downloads) was compromised to run a remote payload at build time. Simply running `cargo build` was enough to get infected:
#SoftwareSupplyChainSecurity
👇
https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack -
#Snowflake’s GitHub Action introduced via #AI-assisted PR, contained an injection flaw that could be exploited to access sensitive data in Snowflake's internal Jira.
An example of AI-assisted coding creating real #SoftwareSupplyChainSecurity risk:
👇
https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug -
#Snowflake’s GitHub Action introduced via #AI-assisted PR, contained an injection flaw that could be exploited to access sensitive data in Snowflake's internal Jira.
An example of AI-assisted coding creating real #SoftwareSupplyChainSecurity risk:
👇
https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug -
#Snowflake’s GitHub Action introduced via #AI-assisted PR, contained an injection flaw that could be exploited to access sensitive data in Snowflake's internal Jira.
An example of AI-assisted coding creating real #SoftwareSupplyChainSecurity risk:
👇
https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug -
#Snowflake’s GitHub Action introduced via #AI-assisted PR, contained an injection flaw that could be exploited to access sensitive data in Snowflake's internal Jira.
An example of AI-assisted coding creating real #SoftwareSupplyChainSecurity risk:
👇
https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug -
#Snowflake’s GitHub Action introduced via #AI-assisted PR, contained an injection flaw that could be exploited to access sensitive data in Snowflake's internal Jira.
An example of AI-assisted coding creating real #SoftwareSupplyChainSecurity risk:
👇
https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug -
In meinem Vortrag (Samstag, 10:00 Uhr, Hörsaal 7) geht es um Supply Chain Security im PHP-Ökosystem:
https://phpunit.expert/presentations/supply-chain-security-in-the-php-ecosystem.html?ref=mastodon
-
In meinem Vortrag (Samstag, 10:00 Uhr, Hörsaal 7) geht es um Supply Chain Security im PHP-Ökosystem:
https://phpunit.expert/presentations/supply-chain-security-in-the-php-ecosystem.html?ref=mastodon
-
In meinem Vortrag (Samstag, 10:00 Uhr, Hörsaal 7) geht es um Supply Chain Security im PHP-Ökosystem:
https://phpunit.expert/presentations/supply-chain-security-in-the-php-ecosystem.html?ref=mastodon
-
In meinem Vortrag (Samstag, 10:00 Uhr, Hörsaal 7) geht es um Supply Chain Security im PHP-Ökosystem:
https://phpunit.expert/presentations/supply-chain-security-in-the-php-ecosystem.html?ref=mastodon
-
In meinem Vortrag (Samstag, 10:00 Uhr, Hörsaal 7) geht es um Supply Chain Security im PHP-Ökosystem:
https://phpunit.expert/presentations/supply-chain-security-in-the-php-ecosystem.html?ref=mastodon
-
Weitere Themenideen für #Fedicamp-Beiträge wären
* #Containerisierung und #SoftwareSupplyChainSecurity
* #Wikipedia/ #Wikidata-Spiele -
Weitere Themenideen für #Fedicamp-Beiträge wären
* #Containerisierung und #SoftwareSupplyChainSecurity
* #Wikipedia/ #Wikidata-Spiele -
Weitere Themenideen für #Fedicamp-Beiträge wären
* #Containerisierung und #SoftwareSupplyChainSecurity
* #Wikipedia/ #Wikidata-Spiele -
Weitere Themenideen für #Fedicamp-Beiträge wären
* #Containerisierung und #SoftwareSupplyChainSecurity
* #Wikipedia/ #Wikidata-Spiele -
The Software Supply Chain Is Under Siege. Devs Are Still the First Line of Defense
#Engineering #Security #AIAgent #AIML #Docker #ResearchInsights #SBOM #SecureSoftwareSupplyChain #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/software-supply-chain-security-omdia-2026-report/
-
The Software Supply Chain Is Under Siege. Devs Are Still the First Line of Defense
#Engineering #Security #AIAgent #AIML #Docker #ResearchInsights #SBOM #SecureSoftwareSupplyChain #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/software-supply-chain-security-omdia-2026-report/
-
The Software Supply Chain Is Under Siege. Devs Are Still the First Line of Defense
#Engineering #Security #AIAgent #AIML #Docker #ResearchInsights #SBOM #SecureSoftwareSupplyChain #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/software-supply-chain-security-omdia-2026-report/
-
The Software Supply Chain Is Under Siege. Devs Are Still the First Line of Defense
#Engineering #Security #AIAgent #AIML #Docker #ResearchInsights #SBOM #SecureSoftwareSupplyChain #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/software-supply-chain-security-omdia-2026-report/
-
The Software Supply Chain Is Under Siege. Devs Are Still the First Line of Defense
#Engineering #Security #AIAgent #AIML #Docker #ResearchInsights #SBOM #SecureSoftwareSupplyChain #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/software-supply-chain-security-omdia-2026-report/
-
Docker OIDC connections for GitHub Actions available for Docker Orgs
#Docker #Products #DockerHub #Githubactions #Oidcconnections #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/docker-oidc-connections-for-github-actions-available-for-docker-orgs/
-
Docker OIDC connections for GitHub Actions available for Docker Orgs
#Docker #Products #DockerHub #Githubactions #Oidcconnections #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/docker-oidc-connections-for-github-actions-available-for-docker-orgs/
-
Docker OIDC connections for GitHub Actions available for Docker Orgs
#Docker #Products #DockerHub #Githubactions #Oidcconnections #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/docker-oidc-connections-for-github-actions-available-for-docker-orgs/
-
Docker OIDC connections for GitHub Actions available for Docker Orgs
#Docker #Products #DockerHub #Githubactions #Oidcconnections #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/docker-oidc-connections-for-github-actions-available-for-docker-orgs/
-
Docker OIDC connections for GitHub Actions available for Docker Orgs
#Docker #Products #DockerHub #Githubactions #Oidcconnections #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/docker-oidc-connections-for-github-actions-available-for-docker-orgs/
-
Sios Technology signs Chainguard partnership for Japan OSS security
KEY POINTSSios Technology signs partnership with U.S.-based Chainguard from July 24, 2026Collaboration combines Sios OSS, API and cloud…
#EuropeSays #Japan #JP #Chainguard #ChainguardContainers #ChainguardLibraries #DevSecOps #OSS #SiosTechnology #softwaresupplychainsecurity
https://www.europesays.com/japan/63475/ -
#JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security:
#SoftwareSupplyChainSecurity
👇
https://jscrambler.com/blog/security-incident-postmortem-jscrambler -
#JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security:
#SoftwareSupplyChainSecurity
👇
https://jscrambler.com/blog/security-incident-postmortem-jscrambler -
#JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security:
#SoftwareSupplyChainSecurity
👇
https://jscrambler.com/blog/security-incident-postmortem-jscrambler -
#JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security:
#SoftwareSupplyChainSecurity
👇
https://jscrambler.com/blog/security-incident-postmortem-jscrambler -
#JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security:
#SoftwareSupplyChainSecurity
👇
https://jscrambler.com/blog/security-incident-postmortem-jscrambler -
#AsyncAPI packages were compromised with Miasama RAT #Malware on #NPM:
* @asyncapi/[email protected]
* @asyncapi/[email protected]
* @asyncapi/[email protected]#SoftwareSupplyChainSecurity
👇
https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm -
#AsyncAPI packages were compromised with Miasama RAT #Malware on #NPM:
* @asyncapi/[email protected]
* @asyncapi/[email protected]
* @asyncapi/[email protected]#SoftwareSupplyChainSecurity
👇
https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm -
#AsyncAPI packages were compromised with Miasama RAT #Malware on #NPM:
* @asyncapi/[email protected]
* @asyncapi/[email protected]
* @asyncapi/[email protected]#SoftwareSupplyChainSecurity
👇
https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm -
#AsyncAPI packages were compromised with Miasama RAT #Malware on #NPM:
* @asyncapi/[email protected]
* @asyncapi/[email protected]
* @asyncapi/[email protected]#SoftwareSupplyChainSecurity
👇
https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm -
#AsyncAPI packages were compromised with Miasama RAT #Malware on #NPM:
* @asyncapi/[email protected]
* @asyncapi/[email protected]
* @asyncapi/[email protected]#SoftwareSupplyChainSecurity
👇
https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm -
#NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs:
#SoftwareSupplyChainSecurity
👇
https://socket.dev/blog/jscrambler-supply-chain-attack -
#NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs:
#SoftwareSupplyChainSecurity
👇
https://socket.dev/blog/jscrambler-supply-chain-attack -
#NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs:
#SoftwareSupplyChainSecurity
👇
https://socket.dev/blog/jscrambler-supply-chain-attack -
#NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs:
#SoftwareSupplyChainSecurity
👇
https://socket.dev/blog/jscrambler-supply-chain-attack -
#NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs:
#SoftwareSupplyChainSecurity
👇
https://socket.dev/blog/jscrambler-supply-chain-attack -
#NPM: two hijacked npm packages:
* html-to-gutenberg
* fetch-page-assets
and a cluster of Go packages use VS Code Tasks to deploy #Python Infostealer #malware:
#SoftwareSupplyChainSecurity
👇
https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html -
#NPM: two hijacked npm packages:
* html-to-gutenberg
* fetch-page-assets
and a cluster of Go packages use VS Code Tasks to deploy #Python Infostealer #malware:
#SoftwareSupplyChainSecurity
👇
https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html -
#NPM: two hijacked npm packages:
* html-to-gutenberg
* fetch-page-assets
and a cluster of Go packages use VS Code Tasks to deploy #Python Infostealer #malware:
#SoftwareSupplyChainSecurity
👇
https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html -
#NPM: two hijacked npm packages:
* html-to-gutenberg
* fetch-page-assets
and a cluster of Go packages use VS Code Tasks to deploy #Python Infostealer #malware:
#SoftwareSupplyChainSecurity
👇
https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html -
#NPM: two hijacked npm packages:
* html-to-gutenberg
* fetch-page-assets
and a cluster of Go packages use VS Code Tasks to deploy #Python Infostealer #malware:
#SoftwareSupplyChainSecurity
👇
https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html -
EU Cyber Resilience Act: Overview, Requirements, and Timelines
#Docker #Products #Concepts #DockerHardenedImages #DockerScout #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/eu-cyber-resilience-act-overview/
-
EU Cyber Resilience Act: Overview, Requirements, and Timelines
#Docker #Products #Concepts #DockerHardenedImages #DockerScout #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/eu-cyber-resilience-act-overview/
-
EU Cyber Resilience Act: Overview, Requirements, and Timelines
#Docker #Products #Concepts #DockerHardenedImages #DockerScout #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/eu-cyber-resilience-act-overview/
-
EU Cyber Resilience Act: Overview, Requirements, and Timelines
#Docker #Products #Concepts #DockerHardenedImages #DockerScout #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/eu-cyber-resilience-act-overview/
-
EU Cyber Resilience Act: Overview, Requirements, and Timelines
#Docker #Products #Concepts #DockerHardenedImages #DockerScout #Security #Softwaresupplychainsecurityhttps://www.docker.com/blog/eu-cyber-resilience-act-overview/