Many software manufacturers and service providers deploy software and configuration updates as part of their service offerings. These updates may enhance features and/or address security vulnerabilities to provide benefits and security to customers.
However, software and the systems that deploy software are highly complex and continually evolving, making it challenging to deploy secure updates. It is critical for all software manufacturers to implement a safe software deployment program supported by verified processes, including robust testing and measurements. The program should support and enhance both the security and quality of the product and deployment environment. This guide, authored by the Cybersecurity and Infrastructure Security Agency (CISA) and partners, encourages software manufacturers to establish a safe software deployment program as part of their software development lifecycle (SDLC).
Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division
Related:
- Wikileaks Unveils CIA’s Man-in-the-Middle Attack Tool
May 5, 2017
Wikileaks has published a new batch of the Vault 7 leak, detailing a man-in-the-middle (MitM) attack tool allegedly created by the United States Central Intelligence Agency (CIA) to target local networks. Since March, WikiLeaks has published thousands of documents and other secret tools that the whistleblower group claims came from the CIA. This latest batch is the ...
- Air Force knocking down stovepipes to shore up space cybersecurity
May 3, 2017
Cybersecurity is a growing concern for everyone who relies computers. The U.S. Air Force Space and Missile Systems Center (SMC) faces unique challenges, however, because it uses an extensive array of ground systems that in some cases are decades old to communicate with the individual satellites and constellations the U.S. military relies on during peacetime ...
- Pentagon Challenges White Hats with New “Hack the Air Force” Bug Bounty Program
April 27, 2017
The Pentagon is launching its largest bug bounty project thus far, this time asking hackers to find flaws in the Air Force’s platforms. “Hack the Air Force” will be open not only to experts in the United States but also from the United Kingdom, Canada, Australia, and New Zealand, or, in other words, what we’ve come ...
- DOE releases results of energy cybersecurity emergency exercise
April 25, 2017
The U.S. Department of Energy (DOE) recently released the findings and recommendations from Liberty Eclipse, a multi-state cyber-energy preparedness exercise hosted by DOE and the National Association of State Energy Officials (NASEO) in December 2016. The exercise simulated a cyber attack on the energy infrastructure, including electricity, gasoline, jet fuel, heating oil, and other energy services, ...
- NSA’s DoublePulsar Kernel Exploit In Use Internet-Wide
April 24, 2017
If you’re on a red team or have been on the receiving end of a pen-test report from one, then you’ve almost certainly encountered reports of Windows servers vulnerable to Conficker (MS08-067), which has been in the wild now for nearly 10 years since the bug was patched. A little more than two weeks after the ...
- US Court Sentences Russian Lawmaker’s Son to 27 Years in Jail for Hacking
April 21, 2017
The son of a prominent Russian lawmaker was sentenced on Friday by a US federal court to 27 years in prison after being convicted of stealing millions of US credit card numbers and causing some $170 million in damages to businesses and individuals. This sentence is so far the longest sentence ever imposed in the United ...

