Security News

REvil ransomware hits 1,000+ companies in MSP supply-chain attack
2021-07-02 19:56

A massive REvil ransomware attack affects multiple managed service providers and over a thousand of their customers through a reported Kaseya supply-chain attack. Starting this afternoon, the REvil ransomware gang, aka Sodinokibi, targeted MSPs with thousands of customers, through what appears to be a Kaseya VSA supply-chain attack.

REvil ransomware hits 200 companies in MSP supply-chain attack
2021-07-02 19:56

A massive REvil ransomware attack affects multiple managed service providers and their clients through a reported Kaseya supply-chain attack. Starting this afternoon, the REvil ransomware gang targeted approximately six large MSPs, with thousands of customers, through what appears to be a Kaseya VSA supply-chain attack.

Microsoft admits to signing rootkit malware in supply-chain fiasco
2021-06-26 09:16

Microsoft has now confirmed signing a malicious driver being distributed within gaming environments. Community in tracing and analyzing the malicious drivers bearing the seal of Microsoft.

Defense supply chain vulnerabilities creating security gaps
2021-06-23 03:30

A BlueVoyant report highlights critical vulnerabilities within the defense supply chain ecosystem. Cybersecurity gaps were identified in the subcontractors' security practices to garner a better understanding of the security posture of less visible members of the complex defense supply chain.

Unpatched Flaw in Linux Pling Store Apps Could Lead to Supply-Chain Attacks
2021-06-22 21:01

Cybersecurity researchers have disclosed a critical unpatched vulnerability affecting Pling-based free and open-source software marketplaces for Linux platform that could be potentially abused to stage supply-chain attacks and achieve remote code execution. The vulnerability stems from the manner the store's product listings page parses HTML or embedded media fields, thereby potentially allowing an attacker to inject malicious JavaScript code that could result in arbitrary code execution.

Cryptominers Slither into Python Projects in Supply-Chain Campaign
2021-06-22 19:27

A group of cryptominers was found to have infiltrated the Python Package Index, which is a repository of software code created in the Python programming language. It offers a place where coders can upload software packages for use by developers in building various applications, services and other projects.

Attacks Against Container Infrastructures Increasing, Including Supply Chain Attacks
2021-06-21 20:05

Attacks against the container infrastructure are continuing to increase in both frequency and sophistication. The attacks are becoming more evasive, while the supply chain is now targeted.

Google Releases New Framework to Prevent Software Supply Chain Attacks
2021-06-18 03:19

As software supply chain attacks emerge as a point of concern in the wake of SolarWinds and Codecov security incidents, Google is proposing a solution to ensure the integrity of software packages and prevent unauthorized modifications. Called "Supply chain Levels for Software Artifacts", the end-to-end framework aims to secure the software development and deployment pipeline - i.e., the source build publish workflow - and mitigate threats that arise out of tampering with the source code, the build platform, and the artifact repository at every link in the chain.

Google dishes out homemade SLSA, a recipe to thwart software supply-chain attacks
2021-06-18 00:05

Google has proposed a framework called SLSA for dealing with supply chain attacks, a security risk exemplified by the recent compromise of the SolarWinds Orion IT monitoring platform. SLSA - short for Supply chain Levels for Software Artifacts and pronounced "Salsa" for those inclined to add convenience vowels - aspires to provide security guidance and programmatic assurance to help defend the software build and deployment process.

Google Intros SLSA Framework to Enforce Supply Chain Integrity
2021-06-17 16:35

The U.S. tech giant this week unveiled SLSA, a new end-to-end framework the company hopes will drive the enforcement of standards and guidelines to ensuring the integrity of software artifacts throughout the software supply chain. "The goal of SLSA is to improve the state of the industry, particularly open source, to defend against the most pressing integrity threats. With SLSA, consumers can make informed choices about the security posture of the software they consume."