GitHub Confirms Another Major NPM Security Defect

Microsoft-owned GitHub is again flagging major security problems in the npm registry, warning that a pair of newly discovered vulnerabilities continue to expose the soft underbelly of the open-source software supply chain.
read more

Continue reading GitHub Confirms Another Major NPM Security Defect

SolarWinds Outlines ‘Triple Build’ Software Development Model to Secure Supply Chain

When FireEye (now Mandiant) disclosed the SolarWinds breach in December 2020, the security world was forced to accept the reality that given the motivation, time and resources, an advanced attacker can breach any organization. And if the breached organ… Continue reading SolarWinds Outlines ‘Triple Build’ Software Development Model to Secure Supply Chain

Mozilla Blocks Malicious Firefox Add-Ons Abusing Proxy API

The open-source Mozilla Foundation says it blocked a series of malicious Firefox add-ons that misused the proxy API that extensions use to proxy web requests.
The API allows add-ons to control the manner in which the browser connects to the Internet, a… Continue reading Mozilla Blocks Malicious Firefox Add-Ons Abusing Proxy API

Endpoint Security Platform Kolide Banks $17 Million Investment

Endpoint security platform Kolide on Thursday announced that it has raised $17 million in Series B funding, for a total of $27 million raised to date.
read more

Continue reading Endpoint Security Platform Kolide Banks $17 Million Investment

CISA, FBI Warn of Increase in Ransomware Attacks on Holidays

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) are warning that ransomware actors are deliberately launching attacks during the holidays and weekends.
read more

Continue reading CISA, FBI Warn of Increase in Ransomware Attacks on Holidays

Webinar: Practical steps to build a risk-based application security program

Your executives don’t care about security – they care about risk! Join to hear the latest research from a guest speaker, Sandy Carielli, Principal Forrester Analyst, on the role of the security team in building secure products. This will be… Continue reading Webinar: Practical steps to build a risk-based application security program