Delivering Malware Through Abandoned Amazon S3 Buckets

Here’s a supply-chain attack just waiting to happen. A group of researchers searched for, and then registered, abandoned Amazon S3 buckets for about $400. These buckets contained software libraries that are still used. Presumably the projects don’t realize that they have been abandoned, and still ping them for patches, updates, and etc.

The TL;DR is that this time, we ended up discovering ~150 Amazon S3 buckets that had previously been used across commercial and open source software products, governments, and infrastructure deployment/update pipelines—and then abandoned…

February 12, 2025
Read More >>

サプライチェーンマネジメントの認定資格トップ15

サプライチェーンマネジメントとは

サプライチェーンマネジメント(SCM)とは、企業が提供するソフトウェア、ハードウェア、その他のITおよび技術サービスなど、最終ユーザーに提供される完成品となる原材料を調達する全体的なプロセスである。そして、ほぼすべての業界にわたる企業にとって、グローバルなサプライチェーンは依然として重要な関心事であり、特にITが分析やその他のデータ関連の対策に目を向け、企業がサプライチェーンで直面する問題の緩和に役立てようとしてい…

September 12, 2024
Read More >>

Cyber Insights 2024: Supply Chain 

Supply chain security insights: A successful attack against a supplier can lead to multiple opportunities against the supplier’s downstream customers.
The post Cyber Insights 2024: Supply Chain  appeared first on SecurityWeek.

February 20, 2024
Read More >>

Enhancing trust for SGX enclaves

By Artur Cygan Creating reproducible builds for SGX enclaves used in privacy-oriented deployments is a difficult task that lacks a convenient and robust solution. We propose using Nix to achieve reproducible and transparent enclave builds so that anyone can audit whether the enclave is running the source code it claims, thereby enhancing the security of […]

January 26, 2024
Read More >>

How CISA can improve OSS security

By Jim Miller The US government recently issued a request for information (RFI) about open-source software (OSS) security. In this blog post, we will present a summary of our response and proposed solutions. Some of our solutions include rewriting widely used legacy code in memory safe languages such as Rust, funding OSS solutions to improve […]

November 20, 2023
Read More >>