Practical Guidance For Securing Your Software Supply ChainThe Hacker News·Jun 26, 09:52 UTC · Jun 26, 2024Exploit / PoC60
Proactive software supply chain security becoming critical as threats riseHelp Net Security·Jan 26, 00:00 UTC · Jan 26, 2022Exploit / PoC60
Aqua Security strengthens software supply chain security with pipeline integrity scanningHelp Net Security·May 10, 00:00 UTC · May 10, 2023Exploit / PoC60
GrammaTech CodeSentry 3.0 improves software supply chain securityHelp Net Security·Jan 20, 00:00 UTC · Jan 20, 2022Exploit / PoC60
Google announces GUAC open source project on software supply chainsThe Record·Jan 4, 00:00 UTC · Jan 4, 2023Exploit / PoC60
Phylum integrates with Sumo Logic to identify software supply chain attacksHelp Net Security·Dec 7, 00:00 UTC · Dec 7, 2023Exploit / PoC60
Surge in cyber attacks targeting open source software projectsHelp Net Security·Aug 13, 00:00 UTC · Aug 13, 2020Exploit / PoC in the wild60
Downloads of known vulnerable open source components increase 120%Help Net Security·Sep 27, 00:00 UTC · Sep 27, 2018Exploit / PoC60
Anchore SBOM tracks software supply chain issuesHelp Net Security·May 21, 00:00 UTC · May 21, 2025Exploit / PoC60
The Unknown Risks of The Software Supply Chain: A DeepThe Hacker News·Feb 17, 07:04 UTC · Feb 17, 2024Exploit / PoC60
Microsoft uncovers hacking operation aimed at software supply chainCyberScoop·May 5, 20:58 UTC · May 5, 2017Exploit / PoC in the wild60
North Korean Supply Chain Threat is Booming, UK and South Korea WarnInfosecurity Magazine·Nov 23, 12:30 UTC · Nov 23, 2023Exploit / PoC60
Projecting the next decade of software supply chain securityCyberScoop·Feb 10, 15:44 UTC · Feb 10, 2025Exploit / PoC in the wild60
Five Core Tenets Of Highly Effective DevSecOps PracticesThe Hacker News·May 21, 11:33 UTC · May 21, 2024Exploit / PoC60
Open Source Supply Chain Attacks Surge 430%Infosecurity Magazine·Aug 13, 09:53 UTC · Aug 13, 2020Exploit / PoC in the wild60
3CX supply chain attack was the result of a previous supply chain attack, Mandiant saysCyberScoop·Apr 20, 13:10 UTC · Apr 20, 2023Exploit / PoC in the wild60
PyPI Revival Hijack Puts Thousands of Applications at RiskInfosecurity Magazine·Sep 5, 17:00 UTC · Sep 5, 2024Exploit / PoC in the wild60
Suppliers, logins, and AI tools are all becoming attack pathsHelp Net Security·Aug 6, 00:00 UTC · Aug 6, 2026Exploit / PoC in the wild160
OpenAI's rogue AI agent shows why we need federal rules for autonomous systemsCyberScoop·Jul 29, 10:00 UTC · Jul 29, 2026Exploit / PoC in the wild60
White House: U.S. agencies have 90 days to create inventory of all softwareThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Exploit / PoC60
Eclypsium raises $25 million to protect businesses from breaches through supply chainsHelp Net Security·Jan 11, 11:58 UTC · Jan 11, 2024Exploit / PoC in the wild60
Week in review: Google fixes exploited Chrome zero-day, Patch Tuesday forecastHelp Net Security·Jun 8, 00:00 UTC · Jun 8, 2025Exploit / PoC in the wildCVE-2025-541960
CISA guide seeks a unified approach to software ‘ingredients lists’CyberScoop·Sep 3, 19:20 UTC · Sep 3, 2025Exploit / PoC in the wild60
CISA urges vendors to get rid of default passwordsCyberScoop·Dec 15, 19:55 UTC · Dec 15, 2023Exploit / PoC in the wild60
Week in review: MOVEit Transfer critical zero-day vulnerability, Kali Linux 2023.2 releasedHelp Net Security·Jun 4, 00:00 UTC · Jun 4, 2023Exploit / PoC in the wildCVE-2023-28771CVE-2023-2868CVE-2023-2798860
CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AIThe Hacker News·May 26, 12:07 UTC · May 26, 2026Exploit / PoC in the wild60
Week in review: IE zero-day, S3 bucket security, rise of RDP as a target vectorHelp Net Security·Sep 29, 00:00 UTC · Sep 29, 2019Exploit / PoC in the wildCVE-2019-1675960
GrammaTech unveils new versions of its CodeSentry binary SCA platformHelp Net Security·Mar 9, 00:00 UTC · Mar 9, 2023Exploit / PoC60
Researchers Find Over 22,000 Removed PyPI Packages at Risk of Revival HijackThe Hacker News·Sep 5, 09:14 UTC · Sep 5, 2024Exploit / PoC in the wild60
Tj-actions Supply Chain Attack Traced Back to GitHub Token CompromiseInfosecurity Magazine·Apr 4, 12:00 UTC · Apr 4, 2025Exploit / PoC in the wildCVE-2025-3006660
CISOs struggle to manage risk due to DevSecOps inefficienciesHelp Net Security·Apr 27, 00:00 UTC · Apr 27, 2023Exploit / PoC60
Tanium strengthens threat identification capabilities and enhances endpoint reachHelp Net Security·Jun 23, 00:00 UTC · Jun 23, 2023Exploit / PoC60
Most Commercial Code Contains HighInfosecurity Magazine·Feb 27, 13:00 UTC · Feb 27, 2024Exploit / PoC in the wild60
Hands-on Review: Myrror Security Code-Aware and AttackThe Hacker News·Feb 17, 07:01 UTC · Feb 17, 2024Exploit / PoC60
ArmorCode gives security teams AI workers for exposure and remediationHelp Net Security·May 20, 00:00 UTC · May 20, 2026Exploit / PoC60
Mend.io enhances application security with AI runtime protection and faster zero-day responseHelp Net Security·Jul 31, 08:25 UTC · Jul 31, 2026Exploit / PoC60
Finite State hires Larry Pesce as Product Security Research and Analysis DirectorHelp Net Security·Nov 10, 00:00 UTC · Nov 10, 2022Exploit / PoC60
When ‘minimal impact’ isn’t reassuring: lessons from the largest npm supply chain compromiseCyberScoop·Sep 15, 13:21 UTC · Sep 15, 2025Exploit / PoC in the wild60
Unverified code is the next national security threatCyberScoop·Jun 9, 15:56 UTC · Jun 9, 2025Exploit / PoC in the wild60