Aqua News
VSCode Marketplace can be abused to host malicious extensions
Aqua researchers have found it surprisingly easy to upload malicious Visual Studio Code extensions to the VSCode Marketplace, and discovered signs of threat actors already exploiting this weakness.
PyTorch Machine Learning Framework Compromised with Malicious Dependency
Aqua Security, in its own analysis of the bogus torchtriton module, said the package is almost 100% identical to its legitimate counterpart except for one crucial change that enables it to run a malicious binary called triton for harvesting the sensitive data.
Software Supply Chain Threats Will Grow and Evolve in 2023
Eilon Elhadad, Aqua’s Senior Director of Supply Chain, shared his predictions on software supply chain security.
With cloud native-attacks on the rise, it’s vital that developers are able to automate security scans
Itay Shakury, VP Open Source, conducted a Q&A sharing details on Trivy, the all-in-one, open source security scanner that helps teams incorporate security into their workflow.
Accelerating Vulnerability Identification and Remediation
Eylam Milner, Aqua’s Senior Director of Software Supply Chain, contributed an article on how SBOM and automation will help better detect, prevent, and remediate security issues throughout the software development life cycle.
#HowTo: Strengthen Supply Chain Security
Eilon Elhadad, Aqua’s Senior Director of Supply Chain, contributed an article on the increase of software supply chain attacks and how bad actors are focusing on source code to generate weaknesses and open backdoors to critical applications.
Optus, Medibank – and supply chains flying under the radar
Eilon Elhadad, Aqua’s Senior Director of Supply Chain, contributed an article on software supply chain risks and the critical actions the industry needs to take to remedy the issue.
Advancing Cloud-Native Cybersecurity Using eBPF – Matt Richards, Aqua Security
Matt Richards, chief marketing officer for Aqua Security, explains how eBPF in the Linux kernel will advance the state of cloud-native cybersecurity.