New guidance on software supply chain attacks released

John Leonard
clock • 4 min read
NSA, CISA, OpenSSF release guides on preventing supply chain attacks
Image:

NSA, CISA, OpenSSF release guides on preventing supply chain attacks

Linux Foundation's OpenSFF releases npm security guide while US agencies NSA and CISA advise on hardening the component supply chain

The Linux Foundation's Open Source Security Foundation (OpenSSF) has released a best practices guide for developers using dependences from the package manager npm, and in the same week US security ...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now

 

Already a Computing member?

Login

You may also like
UK and South Korea unite against surging North Korean-linked threats

Security

Advisory emphasises ‘critical concern’

clock 24 November 2023 • 1 min read
SEC sues SolarWinds, CISO for fraud and security failures

Threats and Risks

The firm allegedly misled investors about its cybersecurity practices and vulnerabilities

clock 01 November 2023 • 2 min read
Hackers attempt to breach 1Password and Cloudflare using stolen Okta data

Hacking

Cloudflare has urged Okta to 'take any report of compromise seriously and act immediately to limit damage'

clock 25 October 2023 • 3 min read

More on Threats and Risks

Microsoft warns of new ransomware campaign by the Twisted Spider group

Microsoft warns of new ransomware campaign by Twisted Spider group

Uses malvertising to spread Danbot Trojan, then Cactus ransomware

John Leonard
clock 01 December 2023 • 2 min read
Google rushes out patch for Chrome zero-day with exploit available in the wild

Google rushes out patch for Chrome zero-day with exploit available in the wild

Other Chromium-based browsers are also vulnerable to the flaw in the Skia graphics library

clock 30 November 2023 • 3 min read
18,000 customers at risk of phishing attacks after security firm Otka hacked

Customers at risk of phishing attacks after hack, Okta warns

Software security firm Otka has warned that some of its 18,000 corporate and government customers have been left vulnerable to phishing attacks after hackers broke into its computer systems a month ago.

clock 30 November 2023 • 1 min read