Software Supply Chain Security - Security Boulevard https://securityboulevard.com/category/editorial-calendar/software-supply-chain-security/ The Home of the Security Bloggers Network Fri, 20 Oct 2023 15:10:39 +0000 en-US hourly 1 https://wordpress.org/?v=6.3.2 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Software Supply Chain Security - Security Boulevard https://securityboulevard.com/category/editorial-calendar/software-supply-chain-security/ 32 32 133346385 KeePass Malicious Ads: Google Goof Permits Punycode Attacks Again https://securityboulevard.com/2023/10/keepass-malicious-ads-punycode-richixbw/ Fri, 20 Oct 2023 15:10:39 +0000 https://securityboulevard.com/?p=1993030 ķ≠k

Mote below k: Not only malvertising, but also “verified by Google.”

The post KeePass Malicious Ads: Google Goof Permits Punycode Attacks Again appeared first on Security Boulevard.

]]>
1993030
iPhone/iPad Warning: Update Now to Avoid Zero-Day Pain https://securityboulevard.com/2023/10/ios-7-0-3-update-richixbw/ Fri, 06 Oct 2023 15:26:53 +0000 https://securityboulevard.com/?p=1991731 Three iPhone 15s sit on a wicker table, with the words “PATCH NOW!” macro’ed on top

Apple’s embarrassing regression: iOS 17.0.3 fixes yet more nasty zero-days (and the overheating bug).

The post iPhone/iPad Warning: Update Now to Avoid Zero-Day Pain appeared first on Security Boulevard.

]]>
1991731
Broken ARM: Mali Malware Pwns Phones https://securityboulevard.com/2023/10/arm-mali-gpu-richixbw/ Tue, 03 Oct 2023 15:51:43 +0000 https://securityboulevard.com/?p=1991291 A tailor’s dummy hand is separated from its arm

Exploited in the wild: Yet more use-after-free vulns in Arm’s Mali GPU driver.

The post Broken ARM: Mali Malware Pwns Phones appeared first on Security Boulevard.

]]>
1991291
More iOS Zero-Days, More Mercenary Spyware — This Time: Cytrox Predator https://securityboulevard.com/2023/09/ios-zero-cytrox-predator-richixbw/ Mon, 25 Sep 2023 17:01:38 +0000 https://securityboulevard.com/?p=1990217 Ahmed El-Tantawy

Apple Scrambled to Fix 3 More CVEs: Egyptian opposition presidential candidate Ahmed Eltantawy targeted “by the government.

The post More iOS Zero-Days, More Mercenary Spyware — This Time: Cytrox Predator appeared first on Security Boulevard.

]]>
1990217
Patch EVERYTHING: Widely Used ‘WebP’ Code has Critical Bug https://securityboulevard.com/2023/09/patch-everything-widely-used-webp-code-has-critical-bug/ Wed, 13 Sep 2023 17:10:18 +0000 https://securityboulevard.com/?p=1989037 The Google WebP logo

WebP FAIL. Critical vuln in libwebp: Go get updates to Chrome, Firefox, Edge, Slack and more.

The post Patch EVERYTHING: Widely Used ‘WebP’ Code has Critical Bug appeared first on Security Boulevard.

]]>
1989037
‘BLASTPASS’ iPhone Exploit — Apple Asleep at the Switch https://securityboulevard.com/2023/09/blastpass-apple-fail-richixbw/ Mon, 11 Sep 2023 16:58:41 +0000 https://securityboulevard.com/?p=1988758 A man has fallen asleep on top of his books and papers

Zero click, zero day, zero clue: Yet another iOS zero-day lets NSO’s Pegasus “mercenary spyware” cause chaos.

The post ‘BLASTPASS’ iPhone Exploit — Apple Asleep at the Switch appeared first on Security Boulevard.

]]>
1988758
This SUCKS: ‘Cars Are a Privacy Nightmare,’ Mozilla Fumes https://securityboulevard.com/2023/09/car-privacy-mozilla-richixbw/ Wed, 06 Sep 2023 15:42:10 +0000 https://securityboulevard.com/?p=1988334 Two old vehicles rust away in a junkyard

IoT cars considered harmful: Own a car? Care about your privacy? Mozilla Foundation has bad news for you.

The post This SUCKS: ‘Cars Are a Privacy Nightmare,’ Mozilla Fumes appeared first on Security Boulevard.

]]>
1988334
Sourcegraph’s Shocking Screwup: Private Secrets in Public Repo https://securityboulevard.com/2023/09/sourcegraph-secrets-ai-llm-richixbw/ Tue, 05 Sep 2023 15:55:49 +0000 https://securityboulevard.com/?p=1988189 A lemur stares back at you, with a shocked expression

Credentials create crisis: AI source code navigation LLM leaks PII after DevOps SNAFU.

The post Sourcegraph’s Shocking Screwup: Private Secrets in Public Repo appeared first on Security Boulevard.

]]>
1988189
BadBazaar: Chinese Spyware Shams Signal, Telegram Apps https://securityboulevard.com/2023/08/badbazaar-signal-telegram-gref-richixbw/ Thu, 31 Aug 2023 17:13:45 +0000 https://securityboulevard.com/?p=1987879 A phone home screen shows Signal and Telegram app icons

After sneaking into Google and Samsung app stores, “GREF” APT targets Uyghurs and other PRC minorities.

The post BadBazaar: Chinese Spyware Shams Signal, Telegram Apps appeared first on Security Boulevard.

]]>
1987879
Lapsus$ Jury Says Teen Duo Did Do Crimes https://securityboulevard.com/2023/08/lapsus-arion-kurtaj-richixbw/ Thu, 24 Aug 2023 17:13:11 +0000 https://securityboulevard.com/?p=1987021 a little teapot, short and stout

Arion Kurtaj and anon minor: Part of group that hacked Uber, Nvidia, Microsoft, Rockstar Games and many more.

The post Lapsus$ Jury Says Teen Duo Did Do Crimes appeared first on Security Boulevard.

]]>
1987021