NSA to developers: Think about switching from C and C++ to a memory safe programming language

The National Security Agency (NSA) is urging developers to shift to memory safe languages – such as C#, Go, Java, Ruby, Rust, and Swift – to protect their code from remote code execution or other hacker attacks. Of the languages Read More …

Developer account body snatchers pose risks to the software supply chain

Software supply chain attacks, once the exclusive province of sophisticated state-sponsored attackers, have been gaining popularity recently among a broader range of cyber criminals. Attackers everywhere have realized that software supply chain attacks can be very effective, and can result Read More …

CISA, NSA, and ODNI Release Part One of Guidance on Securing the Software Supply Chain

CISA, the National Security Agency (NSA), and the Office of the Director of National Intelligence (ODNI), have published part one of a three-part joint publication series, Securing Software Supply Chain Series – Recommended Practices for Developers. This guidance—created by the Read More …

2022 CWE Top 25 Most Dangerous Software Weaknesses

The Homeland Security Systems Engineering and Development Institute, sponsored by CISA and operated by MITRE, has released the 2022 Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses list. The list uses data from the National Vulnerability Database to Read More …

Microsoft suspends new sales in Russia

Microsoft has now committed over $35 million to support humanitarian assistance and relief efforts for Ukraine. This includes more than $18 million worth of Microsoft technology to help organizations such as the Polish Humanitarian Action respond to critical needs and Read More …

The security dilemma of smart factories [Part 1] Specificity of the programming languages used to move industrial robots

Industrial robots are the core of the automation of manufacturing processes in smart factories, and are the most important components as they support the manufacture of all kinds of products such as automobiles, aircraft, processed foods, and pharmaceuticals. In addition, Read More …

Tesla sues ex-employee over alleged ‘brazen’ theft of confidential code

Tesla is suing a former member of staff for allegedly stealing confidential information and attempting to cover his tracks in the aftermath. The lawsuit, filed in the US Northern District of California Court, names Alex Khatilov as the alleged perpetrator, Read More …

Weaponizing Open Source Software for Targeted Attacks

Trojanized open-source software is tricky to spot. This is because it takes on the façade of legitimate, non-malicious software, making it especially stealthy and useful for targeted attacks. However, a closer investigation can reveal suspicious behavior that exposes their malicious Read More …