Our Blog

Cyber RiskImage illustrating comparison
Barak Brudo SPDX vs. CycloneDX: SBOM Formats Compared

Despite the growing adoption of the Software Bill of Materials (SBOM) to serve as a vulnerability management and cybersecurity tool, many organizations still struggle to understand the two most popular SBOM formats in use today, SPDX and CycloneDX. In this article, we will compare these two formats to help you choose the right one for […]

Read more
UncategorizedAn image illustrating protection
Doron Peri From Application Security to Software Supply Chain Security: A Fresh Approach Is Needed

The traditional approach to securing software products focuses on eliminating vulnerabilities in custom code and safeguarding applications against known risks in third-party dependencies. However, this method is inadequate and fails to address the full scope of threats posed by the software supply chain. Neglecting to secure every aspect of this chain, from production to distribution […]

Read more
Cyber Risk
Barak Brudo GitHub vulnerabilities parallel research

Last month I came upon this article from Dark Reading. It looked very familiar. It didn’t take me long to realize that the GitHub cross-workflow artifact poisoning vulnerability discussed in the article bore a striking resemblance to the GitHub cross-workflow cache poisoning vulnerability we reported on in March 2022.  GitHub workflows—A key component of GitHub […]

Read more
Cyber Risk
Barak Brudo The rise of the SBOM—Our take on Gartner’s Innovation Insight report for SBOMs

With the growing use of third-party components and lengthy software supply chains, attackers can now compromise many software packages simultaneously via a single exploit. In response to this new attack vector, more development and DevOps teams, as well as security professionals, are looking to incorporate a Software Bill of Materials (SBOM). The software supply chain […]

Read more
Cyber RiskAn image of highlighted text
Barak Brudo Graph for Understanding Artifact Composition (GUAC): Key highlights

The risks faced by software supply chains have taken their place at the forefront of conversations in the cybersecurity ecosystem. This is partly due to the increased frequency of these supply chain attacks, but also because of the potentially far-reaching impacts they have when they do happen. Figures from 2021 showed software supply chain attacks […]

Read more
Cyber RiskAn image of a man struggling to meet deadlines
Barak Brudo Taking software supply chain security to the next level with the latest OMB memo

The global software supply chain is always under threat from cyber criminals who threaten to steal sensitive information or intellectual property and compromise system integrity. These issues may impact commercial companies as well as the government’s ability to securely and reliably deliver services to the public.  The United States Office of Management and Budget (OMB) […]

Read more
Cyber Risk
Barak Brudo Don’t be the weakest link: The role of developers in securing the software supply chain

When three U.S. government agencies get together to “strongly encourage” developers to adopt certain practices, you should pay attention. The CISA, NSA, and ODNI, in recognition of the threat of cyber-hackers and in the wake of the SolarWinds attack, announced that they will be  jointly publishing a collection of recommendations for securing the software supply […]

Read more
Cyber RiskAn image of a knock out
Barak Brudo How can you make sure your bottom line doesn’t get knocked out by the OMB Memo?

The US government is in the process of revamping its cybersecurity policies. This includes the release of Secure Software Development Framework (SSDF) version 1.1 by the National Institute of Standards and Technology (NIST), which aims to reduce security vulnerabilities across the Software Development Life Cycle (SDLC). The document provides software vendors and acquirers with “a […]

Read more
Cyber RiskIconBurst Article Image
Barak Brudo IconBust, a new NPM attack

A new software supply chain attack designed to extract data from applications and websites was found in over two dozen NPM packages.

Read more
Cyber Riskbanner
Barak Brudo Evaluate Your Source Control Security Posture with GitGat

GitGat is a set of self-contained OPA (Open Policy Agent) policies written in Rego. GitGat evaluates the security settings of your SCM account and provides you with a status report and actionable recommendations.

Read more
1 2 3 4 5