Remove Malware Remove Open Source Remove SDLC Remove Survey
article thumbnail

To Boost Software Supply Chain Security, Stop the Finger-Pointing

Tenable

It’s further proof of the growing importance of protecting application development environments, which attackers increasingly target to stealthily deliver malware via legit software-release channels. Some of respondents’ most widely adopted SDLC security practices were: . High-trust, low-blame cultures focused on performance were 1.6x

article thumbnail

Cybersecurity Snapshot: 6 Things That Matter Right Now

Tenable

Here are major findings from the report, whose security survey questions were based on the defensive measures of the Supply Chain Levels for Software Artifacts (SLSA) framework and of the National Institute of Standards and Technology’s Secure Software Development Framework (SSDF.) . That’s not to say that technology is irrelevant.

article thumbnail

Don’t overlook insider threats—and more cybersecurity lessons

Coveros

It appears no data was stolen, nor malware, nor extortion. 96% of known-vulnerable open source downloads are avoidable. GitHub Octoverse 2022: The State of Open Source. 90% of companies use open source. 30% of Fortune 100 companies have Open Source Program Offices. What was the fallout?