home.social

#supply-chain-security — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #supply-chain-security, aggregated by home.social.

fetched live
  1. `image: node:latest` in prod? That PR gets rejected instantly.

    Mutable tags = moving targets. Someone else controls what you deploy. Friday's perfect build becomes Monday's silent supply chain bomb.

    Learn how to lock down Docker images with immutable digests and stop gambling with your infra.

    valtersit.com/guides/docker/ru

    #Docker #DevSecOps #SupplyChainSecurity

  2. `image: node:latest` in prod? That PR gets rejected instantly.

    Mutable tags = moving targets. Someone else controls what you deploy. Friday's perfect build becomes Monday's silent supply chain bomb.

    Learn how to lock down Docker images with immutable digests and stop gambling with your infra.

    valtersit.com/guides/docker/ru

    #Docker #DevSecOps #SupplyChainSecurity

  3. Coder disclosed a compromise of its Cloudflare infrastructure for registry.coder.com, with unauthorized IPs added to serve malicious Terraform modules. The modules harvested cloud credentials and AI tokens, turning trusted workspace templates into a supply-chain attack vector. #SupplyChainSecurity #Terraform #CloudSecurity

    cyberworldops.eu/en/coder-regi

  4. Coder disclosed a compromise of its Cloudflare infrastructure for registry.coder.com, with unauthorized IPs added to serve malicious Terraform modules. The modules harvested cloud credentials and AI tokens, turning trusted workspace templates into a supply-chain attack vector. #SupplyChainSecurity #Terraform #CloudSecurity

    cyberworldops.eu/en/coder-regi

  5. Your container image may be secure—and still leave attackers hidden. Mohammad-Ali A'râbi explains why traditional SBOMs miss discarded build stages and how BuildKit and Cosign help secure every step of your Java supply chain. Learn how to build verifiable Java container images: javapro.io/2026/09/03/the-pois

    #Java #SBOM #SupplyChainSecurity

  6. Your container image may be secure—and still leave attackers hidden. Mohammad-Ali A'râbi explains why traditional SBOMs miss discarded build stages and how BuildKit and Cosign help secure every step of your Java supply chain. Learn how to build verifiable Java container images: javapro.io/2026/09/03/the-pois

    #Java #SBOM #SupplyChainSecurity

  7. Manifold Security found eight vulnerabilities in seven AI CLI coding agents that execute attacker code injected via a malicious .git/config when the agents automatically invoke Git. This turns cloning any untrusted repository into potential remote code execution and undermines trust in AI-assisted development. #AiSecurity #SupplyChainSecurity #DevSecOps

    cyberworldops.eu/en/git-turned

  8. Manifold Security found eight vulnerabilities in seven AI CLI coding agents that execute attacker code injected via a malicious .git/config when the agents automatically invoke Git. This turns cloning any untrusted repository into potential remote code execution and undermines trust in AI-assisted development. #AiSecurity #SupplyChainSecurity #DevSecOps

    cyberworldops.eu/en/git-turned

  9. Manifold Security found eight vulnerabilities in seven AI CLI coding agents that execute attacker code injected via a malicious .git/config when the agents automatically invoke Git. This turns cloning any untrusted repository into potential remote code execution and undermines trust in AI-assisted development. #AiSecurity #SupplyChainSecurity #DevSecOps

    cyberworldops.eu/en/git-turned

  10. Manifold Security found eight vulnerabilities in seven AI CLI coding agents that execute attacker code injected via a malicious .git/config when the agents automatically invoke Git. This turns cloning any untrusted repository into potential remote code execution and undermines trust in AI-assisted development. #AiSecurity #SupplyChainSecurity #DevSecOps

    cyberworldops.eu/en/git-turned

  11. Manifold Security found eight vulnerabilities in seven AI CLI coding agents that execute attacker code injected via a malicious .git/config when the agents automatically invoke Git. This turns cloning any untrusted repository into potential remote code execution and undermines trust in AI-assisted development. #AiSecurity #SupplyChainSecurity #DevSecOps

    cyberworldops.eu/en/git-turned

  12. 🛒 Retail cyber resilience needs more than technical metrics.

    How do you measure whether your retail CPS security program is actually reducing risk and protecting operational continuity?

    Our latest white paper outlines a 𝟒-stage roadmap to help retailers turn cybersecurity metrics into business outcomes, from improving asset visibility to reducing exposure and strengthening supply chain resilience.

    📄 Read it here: claroty.com/resources/white-pa

    #RetailCybersecurity #CyberResilience #OTSecurity #ExposureManagement #SupplyChainSecurity

  13. 🛒 Retail cyber resilience needs more than technical metrics.

    How do you measure whether your retail CPS security program is actually reducing risk and protecting operational continuity?

    Our latest white paper outlines a 𝟒-stage roadmap to help retailers turn cybersecurity metrics into business outcomes, from improving asset visibility to reducing exposure and strengthening supply chain resilience.

    📄 Read it here: claroty.com/resources/white-pa

    #RetailCybersecurity #CyberResilience #OTSecurity #ExposureManagement #SupplyChainSecurity

  14. 13 malicious Composer themes on Packagist are being used on Vietnamese streaming sites. Installed on OphimCMS or KKPhim, they inject JavaScript and a hidden iframe: mobile visitors may be redirected to ad-fraud and gambling pages, while vulnerable iPhones can be targeted through Safari with an exploit chain reaching the kernel.

    The campaign exploits CVE-2025-31277 and CVE-2025-43529, patched in iOS 18.6, 18.7.3…

    en.hacks.gr/13-kakovoyla-paket

    #iOS #MobileSecurity #SupplyChainSecurity #CyberSecurity

  15. 13 malicious Composer themes on Packagist are being used on Vietnamese streaming sites. Installed on OphimCMS or KKPhim, they inject JavaScript and a hidden iframe: mobile visitors may be redirected to ad-fraud and gambling pages, while vulnerable iPhones can be targeted through Safari with an exploit chain reaching the kernel.

    The campaign exploits CVE-2025-31277 and CVE-2025-43529, patched in iOS 18.6, 18.7.3…

    en.hacks.gr/13-kakovoyla-paket

    #iOS #MobileSecurity #SupplyChainSecurity #CyberSecurity

  16. 13 malicious Composer themes on Packagist are being used on Vietnamese streaming sites. Installed on OphimCMS or KKPhim, they inject JavaScript and a hidden iframe: mobile visitors may be redirected to ad-fraud and gambling pages, while vulnerable iPhones can be targeted through Safari with an exploit chain reaching the kernel.

    The campaign exploits CVE-2025-31277 and CVE-2025-43529, patched in iOS 18.6, 18.7.3…

    en.hacks.gr/13-kakovoyla-paket

    #iOS #MobileSecurity #SupplyChainSecurity #CyberSecurity

  17. 13 malicious Composer themes on Packagist are being used on Vietnamese streaming sites. Installed on OphimCMS or KKPhim, they inject JavaScript and a hidden iframe: mobile visitors may be redirected to ad-fraud and gambling pages, while vulnerable iPhones can be targeted through Safari with an exploit chain reaching the kernel.

    The campaign exploits CVE-2025-31277 and CVE-2025-43529, patched in iOS 18.6, 18.7.3…

    en.hacks.gr/13-kakovoyla-paket

    #iOS #MobileSecurity #SupplyChainSecurity #CyberSecurity

  18. JFrog Artifactory is affected by critical CVE-2026-82329 (CVSS 9.8) allowing unauthenticated remote attackers to create administrative tokens via default configurations. With reports of active exploitation, this enables full system takeover and severe software supply chain compromise. Immediate patching is essential. #JFrog #SupplyChainSecurity #VulnerabilityManagement

    cyberworldops.eu/en/jfrog-arti

  19. JFrog Artifactory is affected by critical CVE-2026-82329 (CVSS 9.8) allowing unauthenticated remote attackers to create administrative tokens via default configurations. With reports of active exploitation, this enables full system takeover and severe software supply chain compromise. Immediate patching is essential. #JFrog #SupplyChainSecurity #VulnerabilityManagement

    cyberworldops.eu/en/jfrog-arti

  20. JFrog Artifactory is affected by critical CVE-2026-82329 (CVSS 9.8) allowing unauthenticated remote attackers to create administrative tokens via default configurations. With reports of active exploitation, this enables full system takeover and severe software supply chain compromise. Immediate patching is essential. #JFrog #SupplyChainSecurity #VulnerabilityManagement

    cyberworldops.eu/en/jfrog-arti

  21. These companies are pure cartel and insanity.

    People in reply section said "just wait for the bubble to burst".

    No, when the bubble burst, they gonna force you to use Cloud based computer. You will not own anything anymore.

    What itch me are, that WE as tech user know this problem exist, but... there are lacks of collective action on forcing these AI companies to not mess with hardware availability. Like wth.

    #cybersecurity #supplychainsecurity #AI #Apple

  22. These companies are pure cartel and insanity.

    People in reply section said "just wait for the bubble to burst".

    No, when the bubble burst, they gonna force you to use Cloud based computer. You will not own anything anymore.

    What itch me are, that WE as tech user know this problem exist, but... there are lacks of collective action on forcing these AI companies to not mess with hardware availability. Like wth.

    #cybersecurity #supplychainsecurity #AI #Apple

  23. These companies are pure cartel and insanity.

    People in reply section said "just wait for the bubble to burst".

    No, when the bubble burst, they gonna force you to use Cloud based computer. You will not own anything anymore.

    What itch me are, that WE as tech user know this problem exist, but... there are lacks of collective action on forcing these AI companies to not mess with hardware availability. Like wth.

    #cybersecurity #supplychainsecurity #AI #Apple

  24. These companies are pure cartel and insanity.

    People in reply section said "just wait for the bubble to burst".

    No, when the bubble burst, they gonna force you to use Cloud based computer. You will not own anything anymore.

    What itch me are, that WE as tech user know this problem exist, but... there are lacks of collective action on forcing these AI companies to not mess with hardware availability. Like wth.

    #cybersecurity #supplychainsecurity #AI #Apple

  25. These companies are pure cartel and insanity.

    People in reply section said "just wait for the bubble to burst".

    No, when the bubble burst, they gonna force you to use Cloud based computer. You will not own anything anymore.

    What itch me are, that WE as tech user know this problem exist, but... there are lacks of collective action on forcing these AI companies to not mess with hardware availability. Like wth.

    #cybersecurity #supplychainsecurity #AI #Apple

  26. Executive Order 14420, signed August 26, 2026, declares a national emergency over foreign-sourced electrical equipment threatening the U.S. bulk power system. Transaction restrictions apply immediately for deals initiated after the signing date.

    #ExecutiveOrder14420 #BulkPowerSystem #SupplyChainSecurity #EnergyInfrastructure

    cyberworldops.eu/en/us-power-g

  27. Two factory implants discovered in routers by Shenzhen Zhibotong Electronics grant unauthenticated remote root access to any attacker with network reachability. Confirmed via IEEE MAC prefix database — these backdoors ship with the hardware, not added post-deployment.

    #FactoryImplants #SupplyChainSecurity #ZBTBackdoor #RouterSecurity

    cyberworldops.eu/en/zbt-two-ne

  28. NEC launches CyIOC-based supply chain security service in Japan

    KEY POINTSNEC and three partners launch NEC Cyber Secure Package powered by CyIOC for supply chain cybersecurityService combines…
    #EuropeSays #Japan #JP #Cybersecurity #CyIOC #DigitalArts #FFRISecurity #NEC #NECNetworks&SystemIntegration #Nihon #supplychainsecurity
    europesays.com/japan/81368/

  29. 🚀💥 Behold, the thrilling saga of pnpm 12.0, where supply chain attacks meet their match! 🌐🔒 Dive into a dazzling array of version numbers that will make your head spin faster than a broken npm install. 🤓🌀 Who knew package management could be this riveting? 🤔🎉
    pnpm.io/blog/releases/12.0 #pnpm12 #supplychainsecurity #packagemanagement #npmupdate #technews #HackerNews #ngated

  30. 🚀💥 Behold, the thrilling saga of pnpm 12.0, where supply chain attacks meet their match! 🌐🔒 Dive into a dazzling array of version numbers that will make your head spin faster than a broken npm install. 🤓🌀 Who knew package management could be this riveting? 🤔🎉
    pnpm.io/blog/releases/12.0 #pnpm12 #supplychainsecurity #packagemanagement #npmupdate #technews #HackerNews #ngated

  31. 🚀💥 Behold, the thrilling saga of pnpm 12.0, where supply chain attacks meet their match! 🌐🔒 Dive into a dazzling array of version numbers that will make your head spin faster than a broken npm install. 🤓🌀 Who knew package management could be this riveting? 🤔🎉
    pnpm.io/blog/releases/12.0 #pnpm12 #supplychainsecurity #packagemanagement #npmupdate #technews #HackerNews #ngated

  32. 🚀💥 Behold, the thrilling saga of pnpm 12.0, where supply chain attacks meet their match! 🌐🔒 Dive into a dazzling array of version numbers that will make your head spin faster than a broken npm install. 🤓🌀 Who knew package management could be this riveting? 🤔🎉
    pnpm.io/blog/releases/12.0 #pnpm12 #supplychainsecurity #packagemanagement #npmupdate #technews #HackerNews #ngated

  33. 🚀💥 Behold, the thrilling saga of pnpm 12.0, where supply chain attacks meet their match! 🌐🔒 Dive into a dazzling array of version numbers that will make your head spin faster than a broken npm install. 🤓🌀 Who knew package management could be this riveting? 🤔🎉
    pnpm.io/blog/releases/12.0 #pnpm12 #supplychainsecurity #packagemanagement #npmupdate #technews #HackerNews #ngated

  34. Opening a repo in Claude Code or Cursor can execute code before you read a line of it: SessionStart hooks in .claude/settings.json, folder-open tasks in .vscode/tasks.json. The keyv npm worm injected hooks that survived removing the bad dependency. Check both files first. go.fastruby.io/6p2 #SupplyChainSecurity #DevSecOps #npm

  35. Opening a repo in Claude Code or Cursor can execute code before you read a line of it: SessionStart hooks in .claude/settings.json, folder-open tasks in .vscode/tasks.json. The keyv npm worm injected hooks that survived removing the bad dependency. Check both files first. go.fastruby.io/6p2 #SupplyChainSecurity #DevSecOps #npm

  36. "When OT, IoT, and CPS power distribution centers, temperature-controlled cold chains, and high-tech storefronts, security decisions can directly impact operations, revenue, and customer trust.

    🤔 So how do you get IT and operational teams aligned?

    🛒 𝗧𝗵𝗲 𝗥𝗲𝘁𝗮𝗶𝗹 𝗢𝗧/𝗜𝗧 𝗧𝗿𝗲𝗮𝘁𝘆 is a strategic playbook designed to help you bridge the gap between IT security and operational reality. It provides the tools, language, and structured frameworks necessary to move beyond simple tool deployment and build a mature, governed security program that protects your organization's revenue, supply chain continuity, and customer trust.

    📄 Our latest white paper outlines a structured framework for winning internal buy-in and operationalizing a comprehensive CPS Protection Program across your retail infrastructure.

    Don't wait for a supply chain disruption or inventory loss to prove the need for protection. 🔗 claroty.com/resources/white-pa

    #RetailCybersecurity #CPSsecurity #OTSecurity #CyberResilience #RetailTechnology #OperationalResilience #SupplyChainSecurity"

  37. "When OT, IoT, and CPS power distribution centers, temperature-controlled cold chains, and high-tech storefronts, security decisions can directly impact operations, revenue, and customer trust.

    🤔 So how do you get IT and operational teams aligned?

    🛒 𝗧𝗵𝗲 𝗥𝗲𝘁𝗮𝗶𝗹 𝗢𝗧/𝗜𝗧 𝗧𝗿𝗲𝗮𝘁𝘆 is a strategic playbook designed to help you bridge the gap between IT security and operational reality. It provides the tools, language, and structured frameworks necessary to move beyond simple tool deployment and build a mature, governed security program that protects your organization's revenue, supply chain continuity, and customer trust.

    📄 Our latest white paper outlines a structured framework for winning internal buy-in and operationalizing a comprehensive CPS Protection Program across your retail infrastructure.

    Don't wait for a supply chain disruption or inventory loss to prove the need for protection. 🔗 claroty.com/resources/white-pa

    #RetailCybersecurity #CPSsecurity #OTSecurity #CyberResilience #RetailTechnology #OperationalResilience #SupplyChainSecurity"

  38. Wednesday night I'll be speaking at the NYC Open Source Security User Group meetup.

    If your release pipeline still has stored API tokens in it, come find out how to delete them for good.

    Wed Aug 26, 6-8 PM, pizza at 6, talk at 6:30
    Amazon office, 12 W 39th St, NYC

    Free, but you must register for building access - last chance: luma.com/5mwalp6p?tk=JivtHQ

    Already registered? See you soon! Bring a colleague, have them sign up first - building access requires photo ID.

    #Python #OpenSourceSecurity #SupplyChainSecurity #NYCTech #PyPI

  39. Wednesday night I'll be speaking at the NYC Open Source Security User Group meetup.

    If your release pipeline still has stored API tokens in it, come find out how to delete them for good.

    Wed Aug 26, 6-8 PM, pizza at 6, talk at 6:30
    Amazon office, 12 W 39th St, NYC

    Free, but you must register for building access - last chance: luma.com/5mwalp6p?tk=JivtHQ

    Already registered? See you soon! Bring a colleague, have them sign up first - building access requires photo ID.

    #Python #OpenSourceSecurity #SupplyChainSecurity #NYCTech #PyPI

  40. Wednesday night I'll be speaking at the NYC Open Source Security User Group meetup.

    If your release pipeline still has stored API tokens in it, come find out how to delete them for good.

    Wed Aug 26, 6-8 PM, pizza at 6, talk at 6:30
    Amazon office, 12 W 39th St, NYC

    Free, but you must register for building access - last chance: luma.com/5mwalp6p?tk=JivtHQ

    Already registered? See you soon! Bring a colleague, have them sign up first - building access requires photo ID.

  41. Wednesday night I'll be speaking at the NYC Open Source Security User Group meetup.

    If your release pipeline still has stored API tokens in it, come find out how to delete them for good.

    Wed Aug 26, 6-8 PM, pizza at 6, talk at 6:30
    Amazon office, 12 W 39th St, NYC

    Free, but you must register for building access - last chance: luma.com/5mwalp6p?tk=JivtHQ

    Already registered? See you soon! Bring a colleague, have them sign up first - building access requires photo ID.

    #Python #OpenSourceSecurity #SupplyChainSecurity #NYCTech #PyPI

  42. Wednesday night I'll be speaking at the NYC Open Source Security User Group meetup.

    If your release pipeline still has stored API tokens in it, come find out how to delete them for good.

    Wed Aug 26, 6-8 PM, pizza at 6, talk at 6:30
    Amazon office, 12 W 39th St, NYC

    Free, but you must register for building access - last chance: luma.com/5mwalp6p?tk=JivtHQ

    Already registered? See you soon! Bring a colleague, have them sign up first - building access requires photo ID.

    #Python #OpenSourceSecurity #SupplyChainSecurity #NYCTech #PyPI

  43. 🚗 𝗪𝗵𝗲𝗻 𝗮 𝗰𝘆𝗯𝗲𝗿𝗮𝘁𝘁𝗮𝗰𝗸 𝘀𝘁𝗼𝗽𝘀 𝘁𝗵𝗲 𝗽𝗿𝗼𝗱𝘂𝗰𝘁𝗶𝗼𝗻 𝗹𝗶𝗻𝗲, 𝘁𝗵𝗲 𝗶𝗺𝗽𝗮𝗰𝘁 𝗴𝗼𝗲𝘀 𝗳𝗮𝗿 𝗯𝗲𝘆𝗼𝗻𝗱 𝘁𝗵𝗲 𝗳𝗮𝗰𝘁𝗼𝗿𝘆.

    Connected IT/OT, just-in-time manufacturing and global suppliers can turn one incident into a major supply-chain disruption.

    𝘊𝘺𝘣𝘦𝘳 𝘳𝘦𝘴𝘪𝘭𝘪𝘦𝘯𝘤𝘦 𝘪𝘴 𝘯𝘰𝘸 𝘢𝘯 𝘪𝘯𝘥𝘶𝘴𝘵𝘳𝘪𝘢𝘭 𝘳𝘦𝘲𝘶𝘪𝘳𝘦𝘮𝘦𝘯𝘵.

    Our latest analysis explores how Zero Trust, segmentation and resilient infrastructure can help reduce the blast radius

    relianoid.com/blog/when-the-li

  44. 🚗 𝗪𝗵𝗲𝗻 𝗮 𝗰𝘆𝗯𝗲𝗿𝗮𝘁𝘁𝗮𝗰𝗸 𝘀𝘁𝗼𝗽𝘀 𝘁𝗵𝗲 𝗽𝗿𝗼𝗱𝘂𝗰𝘁𝗶𝗼𝗻 𝗹𝗶𝗻𝗲, 𝘁𝗵𝗲 𝗶𝗺𝗽𝗮𝗰𝘁 𝗴𝗼𝗲𝘀 𝗳𝗮𝗿 𝗯𝗲𝘆𝗼𝗻𝗱 𝘁𝗵𝗲 𝗳𝗮𝗰𝘁𝗼𝗿𝘆.

    Connected IT/OT, just-in-time manufacturing and global suppliers can turn one incident into a major supply-chain disruption.

    𝘊𝘺𝘣𝘦𝘳 𝘳𝘦𝘴𝘪𝘭𝘪𝘦𝘯𝘤𝘦 𝘪𝘴 𝘯𝘰𝘸 𝘢𝘯 𝘪𝘯𝘥𝘶𝘴𝘵𝘳𝘪𝘢𝘭 𝘳𝘦𝘲𝘶𝘪𝘳𝘦𝘮𝘦𝘯𝘵.

    Our latest analysis explores how Zero Trust, segmentation and resilient infrastructure can help reduce the blast radius

    relianoid.com/blog/when-the-li

    #Cybersecurity #CyberResilience #Automotive #OTSecurity #SupplyChainSecurity

  45. Security Tip: Visibility is the foundation of supply chain security. 🛡️ Implementing a Software Bill of Materials (SBOM) allows your team to quickly identify if a newly discovered vulnerability (like a Log4j-style event) affects your environment. Without an SBOM, you're hunting in the dark. Automate your SBOM generation during the build process to stay ahead. Track the latest threats at cvedatabase.com

  46. Fujitsu launches Japan supply-chain service using Exostar, NIST standard

    KEY POINTSFujitsu launches Trusted Supply Chain Service in Japan on Aug. 20, 2026 using Exostar technologyService complies with…
    #EuropeSays #Japan #JP #CUI #Cybersecurity #Exostar #Fujitsu #Japanese #Microsoft365 #NISTSP800-171 #supplychainsecurity
    europesays.com/japan/77701/