1 June 2023 · 964 words · 5 mins
A critical zero-day in Progress MOVEit Transfer is being actively exploited, and the scope of the damage is still emerging.
15 December 2022 · 969 words · 5 mins
A year after Log4Shell shook the software industry, we examine what’s improved in supply chain security — and what still keeps us up at night.
17 March 2022 · 946 words · 5 mins
A popular npm package was deliberately sabotaged by its own maintainer, raising urgent questions about supply chain trust in open source.
13 January 2022 · 955 words · 5 mins
The White House convened tech leaders to address open source security after Log4Shell. Here’s what was discussed and what it means for developers.
16 December 2021 · 1036 words · 5 mins
A week after Log4Shell, the patching chaos continues. But the bigger lesson is about software supply chain security and why we need SBOMs now.
9 December 2021 · 870 words · 5 mins
A critical remote code execution vulnerability in Apache Log4j has sent the entire industry scrambling. Here’s what you need to know and do right now.
11 November 2021 · 804 words · 4 mins
Popular npm packages coa and rc were hijacked to distribute malware, impacting thousands of projects and raising urgent questions about supply chain security.
21 October 2021 · 1114 words · 6 mins
The popular ua-parser-js npm package was hijacked to deliver cryptominers and credential stealers, affecting millions of weekly downloads.
8 July 2021 · 1166 words · 6 mins
The REvil ransomware group exploited Kaseya’s VSA platform to hit over 1,500 businesses simultaneously. This is what supply chain attacks look like at scale.
15 April 2021 · 1067 words · 6 mins
Codecov’s compromised Bash Uploader script exposed CI/CD secrets for thousands of organizations, highlighting a systemic weakness in how we trust third-party tools in our build pipelines.
1 April 2021 · 886 words · 5 mins
Attackers pushed malicious commits to PHP’s official Git repository, exposing the fragile trust model behind open-source supply chains.
4 March 2021 · 920 words · 5 mins
Four zero-day vulnerabilities in Microsoft Exchange Server are being actively exploited at scale, and the fallout is only beginning.