To tackle the growing threat of attacks on the software supply chain, Google has proposed the Supply chain Levels for Software Artifacts framework, or SLSA which is pronounced "salsa". Can Google's 'salsa' make life harder for supply chain attackers? Comment below - we want to hear what you think! . Sophisticated attackers have figured out that the software supply chain is the soft underbelly of the software industry. Beyond the game-changing SolarWinds hack, Google points to the recent Codecov supply chain attack, which stung cybersecurity firm Rapid7 via a tainted Bash uploader. While supply chain attacks aren't new, Google notes they've escalated in the past year, and has shifted the focus from exploits for known or zero-day software vulnerabilities. . Advanced threat actors are targeting the software development pipeline; Google's SLSA initiative strengthens defenses against these vulnerabilities.. Software Supply Chain, Google Security, SLSA Framework, Software Attacks, Open Source Security. . LinuxSecurity.com Team
Japanese mobile operator NTT DoCoMo, Intel and IBM have started promoting a jointly developed specification for increasing the security of mobile commerce applications. . . .. LONDON -- Japanese mobile operator NTT DoCoMo, Intel and IBM have started promoting a jointly developed specification for increasing the security of mobile commerce applications. The companies have released the specifications for industry review, and say the 'Trusted Mobile Platform' would make services such as electronic tickets and e-wallets for online purchases more secure and help protect against viruses and other software attacks. The link for this article located at John Walko is no longer available. . AT&T, Microsoft, and Oracle unveil privacy guidelines for digital transactions to bolster defense against cyber threats.. Mobile Security, Trusted Platform, Cybersecurity Innovations, E-Wallet Protection. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.