home.social

#supply-chain-security — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #supply-chain-security, aggregated by home.social.

fetched live
  1. Are you catching vulnerabilities early enough? 🔍 Integrating automated dependency scanning into your CI/CD workflow is essential for modern software supply chain security. Learn how to use tools like Trivy to identify and fix CVEs before production. Read the full tutorial: cvedatabase.com/blog/shift-lef

  2. 🔐 Attending USENIX in Baltimore? Join @steiza tomorrow for:

    Supply Chain Attacks on Open Source: What’s Happening, What Can We Do Today, and What’s Next

    📅 August 13, 2026
    🕟 4:30 PM
    📍 Baltimore, MD

    #USENIX #OpenSourceSecurity #SupplyChainSecurity

  3. 🔐 Attending USENIX in Baltimore? Join @steiza tomorrow for:

    Supply Chain Attacks on Open Source: What’s Happening, What Can We Do Today, and What’s Next

    📅 August 13, 2026
    🕟 4:30 PM
    📍 Baltimore, MD

    #USENIX #OpenSourceSecurity #SupplyChainSecurity

  4. Hey, hey, it's been a long time since the last huge supply chain attack (what about AUR? it's for nerds). NPM Supply Chain Attack returned again, this time infecting more than 444 packages with accumulation of 2B (yeah B for billion) downloads. The malware used is Shai-hulud again, but this time, the culprit is Copycat of TeamPCP.

    What should you do?
    - Check if you are affected, if so, downgrade your library version
    - Rotate your keys and do 2FA
    - Search for infected accounts in your system, if there is one, remove it... or kill it with cold blood.

    More details:
    ox.security/blog/a-new-infoste

    #cybersecurity #infosec #security #supplychainsecurity #supplychain #npm#shaihuludmalware

  5. Hey, hey, it's been a long time since the last huge supply chain attack (what about AUR? it's for nerds). NPM Supply Chain Attack returned again, this time infecting more than 444 packages with accumulation of 2B (yeah B for billion) downloads. The malware used is Shai-hulud again, but this time, the culprit is Copycat of TeamPCP.

    What should you do?
    - Check if you are affected, if so, downgrade your library version
    - Rotate your keys and do 2FA
    - Search for infected accounts in your system, if there is one, remove it... or kill it with cold blood.

    More details:
    ox.security/blog/a-new-infoste

    #cybersecurity #infosec #security #supplychainsecurity #supplychain #npm#shaihuludmalware

  6. You trust your dependencies? That’s the risk. From #Log4Shell to self-replicating worms, attacks don’t hit your code first — they hit your supply chain, often via packages.

    @MohammadAliEN explains what to watch: javapro.io/2026/04/23/the-whis

    #AppSec #Java #SupplyChainSecurity

  7. You trust your dependencies? That’s the risk. From #Log4Shell to self-replicating worms, attacks don’t hit your code first — they hit your supply chain, often via packages.

    @MohammadAliEN explains what to watch: javapro.io/2026/04/23/the-whis

    #AppSec #Java #SupplyChainSecurity

  8. The Spice Must Flow (Through a Trust Boundary)

    Supply chain attacks like npm's Shai-Hulud campaign exploited CI/CD credentials, not cryptography — here's why OIDC and provenance attestation actually fix it.

    islandinthenet.com/the-spice-m

  9. 🎉【COSCUP 開源政策軌 議程集錦!】🎉

    🔐【開源也有資安責任——企業治理與供應鏈安全專題】🔐

    你知道你部署的每一個容器映像檔,平均預裝了多少個你的應用程式根本用不到的套件嗎?你知道歐盟《網路韌性法》(CRA)的漏洞通報義務即將在 2026 年 9 月生效嗎?
    開源不是免費的午餐,它帶來自由,也帶來責任。🌐

    今年的開源政策軌,我們邀請到多位講者,從 AI 開源生態、電信雲供應鏈安全到企業開源治理框架,一次講清楚:

    ▸ From Code Contributor to Industry Power – How Open Source Becomes Taiwan’s AI Strategy
    👤 Marie Gigarel(英文議程)
    ▸ Securing the Open Source Telco Cloud: SBOMs, Supply Chains, and Compliance at Scale
    👤 Brian Su + Terry Shih(英文議程)
    ▸ 從 OpenSSF Scorecard 到 S2C2F,企業內部推動開源治理的實戰框架是什麼?
    👤 Ryan Hsieh 謝文豪
    ▸ 開源是免費的嗎?從 CNCF 大使視角看人才、企業、政策三方困境
    👤 梯口 tico88612
    ▸ 以 CRA 為例討論產品資安合規下的開源議題——法規來了,開源人準備好了嗎?
    👤 李婉萍
    ▸ Your Container Images Are a Liability: The Supply Chain Debt Nobody Is Paying Down
    👤 Hrittik Roy + Parth Goswami (英文議程)

    📅 8/8~8/9(日)10:00 起
    📍 研陽大樓 TR209 教室(二樓)
    完整議程:coscup.org/2026/track/526

    🌟 如果你在企業裡推動開源、負責資安合規、或關心 AI 生態系的未來,這天的場次是為你量身打造的!💬🤝

    #COSCUP2026 #OCF #OpenSourcePolicy #開源政策 #OpenSource #SBOM #SupplyChainSecurity #CRA #OpenSSF #S2C2F #CNCF #企業開源 #供應鏈安全 #資安合規 #AI #FOSS #FLOSS #開源人年會 #TechEvent #Taiwan

  10. I've been trying to stay quiet about it over vacation, but I'm damned impressed with how #atomdrift is showing up in the malware detection charts. Nothing comes close to it for #supplychainsecurity. Have a question? Leave a comment.

  11. I've been trying to stay quiet about it over vacation, but I'm damned impressed with how #atomdrift is showing up in the malware detection charts. Nothing comes close to it for #supplychainsecurity. Have a question? Leave a comment.

  12. Akrites is the open-source community’s new line of defense against AI-driven attacks. Stronger supply chain security can’t come soon enough. jpmellojr.blogspot.com/2026/07 #AI #Akrites #OpenSource #SupplyChainSecurity #AIsecurity

  13. Akrites is the open-source community’s new line of defense against AI-driven attacks. Stronger supply chain security can’t come soon enough. jpmellojr.blogspot.com/2026/07 #AI #Akrites #OpenSource #SupplyChainSecurity #AIsecurity

  14. CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈

    Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
    blog.packagist.com/securing-ou

    #php #phpc #composerphp #github #githubactions #supplychainsecurity

  15. CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈

    Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
    blog.packagist.com/securing-ou

    #php #phpc #composerphp #github #githubactions #supplychainsecurity

  16. Why You Need a Software Bill of Materials (SBOM) 🛡️

    Security Tip: You can't defend what you can't see. An SBOM provides a nested inventory of every component in your software stack. When a new CVE drops, an SBOM allows your team to instantly identify if you are affected, rather than hunting through codebases manually.

    Stay ahead of the latest threats by tracking vulnerabilities at cvedatabase.com

  17. 🎙️ New FIRST Impressions Podcast Episode: Chris Butera (CISA)

    Recorded live at #FIRSTCON26 in Denver, this episode features Chris Butera, acting Executive Assistant Director for Cybersecurity at CISA, the local host of the conference.

    Chris joins the podcast to discuss the future of the #CVEprogram, software supply chain security, AI-specific SBOMs, end-of-support risk management, and the importance of strong collaboration between government and industry.

    If you’re interested in vulnerability management, AI security, supply chain resilience, or the evolving cybersecurity ecosystem, this is an episode you won’t want to miss!

    🎧 Tune in to hear how CISA is helping shape the future of cyber defense and vulnerability coordination across the global community.

    #FIRSTCON26 #FIRSTImpressions #CISA #Cybersecurity #CVE #SBOM #AISecurity #SupplyChainSecurity #VulnerabilityManagement
    media.first.org/podcasts/FIRST

  18. 🎙️ New FIRST Impressions Podcast Episode: Chris Butera (CISA)

    Recorded live at #FIRSTCON26 in Denver, this episode features Chris Butera, acting Executive Assistant Director for Cybersecurity at CISA, the local host of the conference.

    Chris joins the podcast to discuss the future of the #CVEprogram, software supply chain security, AI-specific SBOMs, end-of-support risk management, and the importance of strong collaboration between government and industry.

    If you’re interested in vulnerability management, AI security, supply chain resilience, or the evolving cybersecurity ecosystem, this is an episode you won’t want to miss!

    🎧 Tune in to hear how CISA is helping shape the future of cyber defense and vulnerability coordination across the global community.

    #FIRSTCON26 #FIRSTImpressions #CISA #Cybersecurity #CVE #SBOM #AISecurity #SupplyChainSecurity #VulnerabilityManagement
    media.first.org/podcasts/FIRST

  19. Security Tip: Implement an SBOM workflow. 🛡️

    An SBOM is like an ingredient list for your code. In the event of a zero-day or a new supply chain vulnerability, an SBOM allows your security team to quickly identify affected assets without manual code audits.

    Tools like Syft or CycloneDX can automate this process in your CI/CD pipeline.

    Stay updated on the latest vulnerabilities: cvedatabase.com

  20. Making Rust supply chain attacks harder with Cackle

    Alex is a software engineer who has built a tool which she licences to her customers. She only has a small number of clients, but they like her tool. She built her tool using Rust, with about 20 direct dependencies from crates.io. When you count indirect dependencies, her tool has about 250 dependencies.
    — by @davidlattimore

    🦀 davidlattimore.github.io/posts

    #rust #rustlang #security #supplychain #attack #software #coding #dev #supplychainsecurity