
The Gigabyte firmware backdoor: Lessons learned about supply chain security
Firmware attacks can pose a substantial risk to the software supply chain. Here's what your software security team can learn from the latest compromise.

Freelance technology writer. John's work has appeared in the The Boston Globe and Boston Herald, as well as CFO, CIO, CSO, and Inc. magazines. He is a former managing editor of the Boston Business Journal and Boston Phoenix, as well as a staff writer for Government Security News.
find John P. Mello Jr. on:

Firmware attacks can pose a substantial risk to the software supply chain. Here's what your software security team can learn from the latest compromise.

Nvidia's tool is among the first to promise to manage the risk from generative AI. Here's what it can do — and an analysis of the scope of risk from AI.

The cost of attacks on software supply chains could exceed $80.6B by 2026, a 76% increase over the $45.8B expected in 2023, a market research firm finds.

OpenSSF's updated framework is an essential tool for dev teams, but experts say it's incomplete as a supply chain security solution

Here's what experts say about the CISA initiative's potential impact on software supply chain security — and security operations.

Here's what the Open Software Supply Chain Attack Reference (OSC&R) framework move means in the short run — and long term.

CPGs are now better aligned with NIST's Cybersecurity Framework (CSF), and supply chain goals have been added. MFA guidance is also new.

The vulnerabilities left the door open to malicious plug-in updates. Here's what you need to know.
.webp&w=3840&q=75)
While best practices adoption for AppSec is up, many supply chain security problems remain, the OpenSSF SLSA framework survey shows.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial