
The 3CX breach was targeted — but the plan was broader
The compromise was limited to their app. But there's a bigger lesson: Supply chain security complacency comes with a cost.

The compromise was limited to their app. But there's a bigger lesson: Supply chain security complacency comes with a cost.

Flaws quickly spread across the supply chain. Here's how researchers at Alpha Omega and beyond are automating fixes.

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond.

The vulnerabilities left the door open to malicious plug-in updates. Here's what you need to know.

Software secrets are in the crosshairs of malicious actors. Here are three key steps to mitigate risk — and best practices your team can take to prevent future breaches.
.webp&w=3840&q=75)
While best practices adoption for AppSec is up, many supply chain security problems remain, the OpenSSF SLSA framework survey shows.

GitHub just got a little safer, by finally forcing users into two-factor authentication. What took you so long, Microsoft?

The recent hacks at CircleCI and other organizations show that your software supply chain may be a grab bag of software secrets. Only an end-to-end security approach can solve the problem.

Why you need to upgrade to software supply chain security: Adversaries can compromise your organization without comprehensive malware identification.

Understanding supply chain security is critical in a software-driven society. Here's an overview of our upcoming book.

Teams are mired in CVEs, the NVD (which is fed by CVE data), and the CVSS. Experts explain why it's time to modernize.

In a first, the Biden administration will hold software developers accountable for vulnerabilities. Naturally, it’s dividing opinions

Modern software development is a primary target for supply chain attacks. Here's why traditional application security testing alone is not up to the job.

The CircleCI breach reveals a bigger story on secrets. Matt Rose and Chris Wilder discuss lessons learned in this webinar

The new CISA office could make a big difference — and even lead to a new discipline dedicated to software supply chain security
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial