Many software manufacturers and service providers deploy software and configuration updates as part of their service offerings. These updates may enhance features and/or address security vulnerabilities to provide benefits and security to customers.
However, software and the systems that deploy software are highly complex and continually evolving, making it challenging to deploy secure updates. It is critical for all software manufacturers to implement a safe software deployment program supported by verified processes, including robust testing and measurements. The program should support and enhance both the security and quality of the product and deployment environment. This guide, authored by the Cybersecurity and Infrastructure Security Agency (CISA) and partners, encourages software manufacturers to establish a safe software deployment program as part of their software development lifecycle (SDLC).
Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division
Related:
- Chinese-made cargo equipment enables cyber, espionage risks in US ports
September 12, 2024
A year-long probe led by GOP members of two House panels found that numerous seaports around the U.S. contain technology originating from Chinese manufacturers that could enable espionage and sabotage. The study conducted by lawmakers and staff on the House Homeland Security Committee and Select Committee on the Chinese Communist Party said that it was an ...
- Thousands of US medical professionals have data exposed in major data breach
September 11, 2024
Researchers have found a database backup belonging to Florida-based recruitment company MNA Healthcare left unsecured online, leaving the details of thousands of workers open to anyone. The company offers staffing services for healthcare workers and matches them with hospitals and organizations across nine states. The leaked information included full names, addresses, phone numbers, job titles, work ...
- Nearly 1M Medicare beneficiaries potentially affected after data breach
September 10, 2024
Nearly 1 million Medicare beneficiaries are being warned that their personal information may have been compromised in a cybersecurity incident last year. The Centers for Medicare & Medicaid Services (CMS) and Wisconsin Physicians Service Insurance Corporation (WPS), the contractor that utilized the affected MOVEit software, said last week that 946,801 people on Medicare were notified that ...
- Japan: JMSDF set to establish a new “Fleet Information Warfare” command
September 9, 2024
The move would strengthen the JMSDF’s response capabilities to integrated information warfare, especially in the cognitive dimension. Most notably, the new reorganization process will abolish the current Fleet Intelligence Command (艦隊情報群), the only specialized intelligence unit in the JMSDF. The move came as part of a major organizational restructuring of the JMSDF. As Naval News reported ...
- US sanctions fail to deter Predator spyware utilization
September 6, 2024
Intellexa Group’s Predator spyware has experienced a resurgence in activity following a decline spurred by sanctions imposed by the Biden administration, reports The Record, a news site by cybersecurity firm Recorded Future. Angola and the Democratic Republic of Congo, which is a new Intellexa client, may have leveraged new Predator infrastructure to enable spyware staging and ...
- Serve your country through cyber, White House says
September 6, 2024
Earlier this week, the United States White House unveiled a new initiative, called Service for America. This initiative, created together with the Office of Management and Budget (OMB) and Office of Personnel Management (OPM), aims to get more people interested in cybersecurity, and thus help bolster the overall cybersecurity posture in both public, and private ...
