
Breaking the Windows Authenticode security model
Blog 7 in series: Digital Certificates - Models for Trust and Targets for Misuse

Blog 7 in series: Digital Certificates - Models for Trust and Targets for Misuse

Blog 9 in series: Digital Certificates - Models for Trust and Targets for Misuse

Rocking the foundations of a trust-based digital code signing system

Enterprise software development graduated from the “waterfall” framework of development and operations - and became less linear, more complex and, in several ways, more difficult to secure. And while contemporary software supply chain practices allow developers to manage that complexity and deliver software efficiently at scale, unaddressed gaps and vulnerabilities within the process continue to be exploited by threat actors.

Blog 6: A new kind of certificate fraud: Executive impersonation

Implementing Processes and Controls to Disrupt Attackers

Detecting malware in package manager repositories

Last week the 22nd annual Black Hat conference hosted over 19,000 security professionals in Las Vegas.

Because of a critical lack of skilled security resources and because of an overload of potential cyberattack related events, efficient operations and accurate analysis are top of mind for savvy security teams everywhere.

...

Traditional supply chain attacks impact the production of physical goods. Your supply chain might include partners delivering raw materials, suppliers with component parts used in manufacturing, as well as trucks for distribution of finished goods.Disruption of that supply chain could result in production shutdowns, aging inventory, degraded partner relations, and financial loss.

Blog 5 of 5 part series on advanced research into modern phishing attacks
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial