<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SOFTWARE SUPPLY CHAIN SECURITY - Aqua</title>
	<atom:link href="https://www.aquasec.com/category/software-supply-chain-security/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Cloud Native Security, Container Security &#38; Serverless Security</description>
	<lastBuildDate>Tue, 09 Sep 2025 11:10:24 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>
	<item>
		<title>NPM Supply Chain: A Critical Threat to Cloud-Native</title>
		<link>https://www.aquasec.com/blog/npm-software-supply-chain-critical-threat/</link>
		
		<dc:creator><![CDATA[Aqua Security]]></dc:creator>
		<pubDate>Tue, 09 Sep 2025 11:12:35 +0000</pubDate>
				<category><![CDATA[SOFTWARE SUPPLY CHAIN SECURITY]]></category>
		<category><![CDATA[Security Threats]]></category>
		<category><![CDATA[Supply Chain Attacks]]></category>
		<guid isPermaLink="false">https://www.aquasec.com/?p=26541</guid>

					<description><![CDATA[<div class="hs-featured-image-wrapper"><a href="https://www.aquasec.com/blog/npm-software-supply-chain-critical-threat/" title="NPM Supply Chain: A Critical Threat to Cloud-Native" class="hs-featured-image-link"><img src="https://www.aquasec.com/wp-content/uploads/2025/09/Social-NPM-blog.jpg" alt="NPM Supply Chain: A Critical Threat to Cloud-Native" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"></a></div>A new software supply chain attack is targeting a series of highly popular open-source NPM packages unleashing malware across 18 foundational JavaScript packages that collectively accounted for a staggering 2.6 billion weekly downloads. This incident highlights how a compromised open-source package can quickly reach production environments, emphasizing the importance of visibility, security controls, and proactive&#160;&mldr;]]></description>
		
		
		
			</item>
		<item>
		<title>Combatting Phantom Secrets with Historical Secret Scanning</title>
		<link>https://www.aquasec.com/blog/combatting-phantom-secrets-with-historical-secret-scanning/</link>
		
		<dc:creator><![CDATA[Aqua Security]]></dc:creator>
		<pubDate>Thu, 26 Sep 2024 03:27:04 +0000</pubDate>
				<category><![CDATA[SOFTWARE SUPPLY CHAIN SECURITY]]></category>
		<guid isPermaLink="false">https://www.aquasec.com/?p=22743</guid>

					<description><![CDATA[<div class="hs-featured-image-wrapper"><a href="https://www.aquasec.com/blog/combatting-phantom-secrets-with-historical-secret-scanning/" title="Combatting Phantom Secrets with Historical Secret Scanning" class="hs-featured-image-link"><img src="https://www.aquasec.com/wp-content/uploads/2024/09/blog-main-Hidden-Secrets-1200x628-2024-final-1.jpg" alt="Combatting Phantom Secrets with Historical Secret Scanning" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"></a></div>You’ve likely heard of Schrödinger’s Cat from quantum mechanics—both alive and dead until the box is opened. This paradox mirrors a critical risk in modern development: the secrets embedded in your code. You might assume they’re long deleted, but until you examine the depths of commit history, you can’t be certain. Recently, Aqua Nautilus team&#160;&mldr;]]></description>
		
		
		
			</item>
		<item>
		<title>Lasting Legacy of Log4j: Lessons for Runtime Security</title>
		<link>https://www.aquasec.com/blog/lasting-legacy-of-log4j-lessons-for-runtime-security/</link>
		
		<dc:creator><![CDATA[Aqua Security]]></dc:creator>
		<pubDate>Wed, 13 Dec 2023 12:02:20 +0000</pubDate>
				<category><![CDATA[SOFTWARE SUPPLY CHAIN SECURITY]]></category>
		<category><![CDATA[Aqua Security]]></category>
		<guid isPermaLink="false">https://www.aquasec.com/?p=14178</guid>

					<description><![CDATA[<div class="hs-featured-image-wrapper"><a href="https://www.aquasec.com/blog/lasting-legacy-of-log4j-lessons-for-runtime-security/" title="Lasting Legacy of Log4j: Lessons for Runtime Security" class="hs-featured-image-link"><img src="https://www.aquasec.com/wp-content/uploads/2023/12/Log4j-lingering-legacy-blog-main-2023.jpg" alt="Lasting Legacy of Log4j: Lessons for Runtime Security" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"></a></div>Another December is upon us, stores are full of shoppers, lights are illuminating cities, towns and cul-de-sacs as radio stations bombard listeners with the continuous rotation of holiday music. Yet amongst all this merriment sits the IT security professional behind their screen completing their end of year tasks. Their eyes slowly twitch, and they fill&#160;&mldr;]]></description>
		
		
		
			</item>
		<item>
		<title>Combating Unknown Unknowns In Hybrid IT Environments</title>
		<link>https://www.aquasec.com/blog/combating-unknown-unknowns-in-hybrid-it-environments/</link>
		
		<dc:creator><![CDATA[Aqua Security]]></dc:creator>
		<pubDate>Wed, 08 Nov 2023 18:12:01 +0000</pubDate>
				<category><![CDATA[CLOUD SECURITY]]></category>
		<category><![CDATA[SOFTWARE SUPPLY CHAIN SECURITY]]></category>
		<guid isPermaLink="false">https://www.aquasec.com/?p=17498</guid>

					<description><![CDATA[<div class="hs-featured-image-wrapper"><a href="https://www.aquasec.com/blog/combating-unknown-unknowns-in-hybrid-it-environments/" title="Combating Unknown Unknowns In Hybrid IT Environments" class="hs-featured-image-link"><img src="" alt="Combating Unknown Unknowns In Hybrid IT Environments" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"></a></div>Recent years have seen a dramatic 1400% increase in unknown unknowns, zero-day and fileless attacks, representing one of the most serious threats in cybersecurity today. The financial services sector is especially vulnerable given its complex, hybrid cloud IT environments comprising both legacy systems and modern cloud native platforms.  Security teams operate with a false sense&#160;&mldr;]]></description>
		
		
		
			</item>
		<item>
		<title>Zero-Day Attack Prevention Through Supply Chain Security</title>
		<link>https://www.aquasec.com/blog/zero-day-attack-prevention-through-supply-chain-security/</link>
		
		<dc:creator><![CDATA[Aqua Security]]></dc:creator>
		<pubDate>Thu, 02 Mar 2023 14:46:13 +0000</pubDate>
				<category><![CDATA[SOFTWARE SUPPLY CHAIN SECURITY]]></category>
		<category><![CDATA[Supply Chain Attacks]]></category>
		<category><![CDATA[Vulnerability Management]]></category>
		<guid isPermaLink="false">https://www.aquasec.com/?p=14460</guid>

					<description><![CDATA[<div class="hs-featured-image-wrapper"><a href="https://www.aquasec.com/blog/zero-day-attack-prevention-through-supply-chain-security/" title="Zero-Day Attack Prevention Through Supply Chain Security" class="hs-featured-image-link"><img src="https://www.aquasec.com/wp-content/uploads/2023/03/Blog-Image-Remediate-Zero-Day-Attacks-Webinar-Teaser_280223.jpg" alt="Zero-Day Attack Prevention Through Supply Chain Security" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"></a></div>Supply chain security has made lots of headlines recently thanks to events like the SolarWinds breach. That and similar events highlight the importance of having a strategy in place to respond to zero-day attacks which can take advantage of vulnerable software components. I recently organized a webinar with and Teresa Pepper, our EMEA Partner Manager.&#160;&mldr;]]></description>
		
		
		
			</item>
		<item>
		<title>Software Supply Chain Security vs. SCA: What&#8217;s the Difference?</title>
		<link>https://www.aquasec.com/blog/software-compositio-analysis-vs-supply-chain-security/</link>
		
		<dc:creator><![CDATA[Aqua Security]]></dc:creator>
		<pubDate>Thu, 09 Feb 2023 15:15:08 +0000</pubDate>
				<category><![CDATA[SOFTWARE SUPPLY CHAIN SECURITY]]></category>
		<category><![CDATA[Code security]]></category>
		<category><![CDATA[shift Left security]]></category>
		<category><![CDATA[Software Supply Chain Security]]></category>
		<guid isPermaLink="false">https://www.aquasec.com/?p=14463</guid>

					<description><![CDATA[<div class="hs-featured-image-wrapper"><a href="https://www.aquasec.com/blog/software-compositio-analysis-vs-supply-chain-security/" title="Software Supply Chain Security vs. SCA: What&#8217;s the Difference?" class="hs-featured-image-link"><img src="https://www.aquasec.com/wp-content/uploads/2023/02/Blog-Image-Software-Supply-Chain-Security-vs-Software-Composition.jpg" alt="Software Supply Chain Security vs. SCA: What&#8217;s the Difference?" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"></a></div>As reliance on software increases in both personal and professional contexts, security of the software supply chain has become a critical concern. Ensuring the security and quality of software is essential for protecting against digital attacks, data breaches, and other cyber threats. Two practices that play a key role in ensuring software security are software&#160;&mldr;]]></description>
		
		
		
			</item>
		<item>
		<title>What To Know: A Summary of the Compliance Guide to SSDF</title>
		<link>https://www.aquasec.com/blog/summary-compliance-guide-to-ssdf/</link>
		
		<dc:creator><![CDATA[Aqua Security]]></dc:creator>
		<pubDate>Tue, 24 Jan 2023 11:00:00 +0000</pubDate>
				<category><![CDATA[SOFTWARE SUPPLY CHAIN SECURITY]]></category>
		<category><![CDATA[SBOMs]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[Software Supply Chain Security]]></category>
		<guid isPermaLink="false">https://www.aquasec.com/?p=14490</guid>

					<description><![CDATA[<div class="hs-featured-image-wrapper"><a href="https://www.aquasec.com/blog/summary-compliance-guide-to-ssdf/" title="What To Know: A Summary of the Compliance Guide to SSDF" class="hs-featured-image-link"><img src="https://www.aquasec.com/wp-content/uploads/2023/01/Blog-Image-Compliance-Guide-to-SSDF-teaser-blog.jpg" alt="What To Know: A Summary of the Compliance Guide to SSDF" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"></a></div>NIST has recently researched, defined, and released an entirely new standard for incorporating security into the software development lifecycle called The Secure Software Development Framework.  It was uniquely designed to help address the tremendous gaps in software supply chain security that expose organizations to methodical attacks on an organization&#8217;s code, infrastructure, development toolchain, and dependencies.&#160;&mldr;]]></description>
		
		
		
			</item>
		<item>
		<title>Should You Use SLSA or CIS Software Supply Chain Security Guidelines?</title>
		<link>https://www.aquasec.com/blog/slsa-or-cis-software-supply-chain-security-guidelines/</link>
		
		<dc:creator><![CDATA[Aqua Security]]></dc:creator>
		<pubDate>Thu, 12 Jan 2023 13:43:14 +0000</pubDate>
				<category><![CDATA[SOFTWARE SUPPLY CHAIN SECURITY]]></category>
		<category><![CDATA[Infrastructure-as-Code (IaC)]]></category>
		<category><![CDATA[SBOMs]]></category>
		<category><![CDATA[Software Supply Chain Security]]></category>
		<guid isPermaLink="false">https://www.aquasec.com/?p=14492</guid>

					<description><![CDATA[<div class="hs-featured-image-wrapper"><a href="https://www.aquasec.com/blog/slsa-or-cis-software-supply-chain-security-guidelines/" title="Should You Use SLSA or CIS Software Supply Chain Security Guidelines?" class="hs-featured-image-link"><img src="https://www.aquasec.com/wp-content/uploads/2023/01/Blog-Image-SLSA-and-CIS-Software-Supply-Chain.jpg" alt="Should You Use SLSA or CIS Software Supply Chain Security Guidelines?" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"></a></div>With recent software supply chain attacks on the rise, CISOs being held personally liable, and the United States government requiring minimum security software standards for any products and services they procure, the development industry is refocusing on software development strategies that make security a priority. But with so many reputable sources creating guidance, which is&#160;&mldr;]]></description>
		
		
		
			</item>
		<item>
		<title>Supply Chain Security: Shifting Left to the Golden Pipeline</title>
		<link>https://www.aquasec.com/blog/supply-chain-security-shifting-left-to-the-golden-pipeline/</link>
		
		<dc:creator><![CDATA[Aqua Security]]></dc:creator>
		<pubDate>Wed, 11 Jan 2023 11:00:00 +0000</pubDate>
				<category><![CDATA[SOFTWARE SUPPLY CHAIN SECURITY]]></category>
		<category><![CDATA[CI/CD]]></category>
		<category><![CDATA[Software Supply Chain Security]]></category>
		<category><![CDATA[Supply Chain Attacks]]></category>
		<guid isPermaLink="false">https://www.aquasec.com/?p=14493</guid>

					<description><![CDATA[<div class="hs-featured-image-wrapper"><a href="https://www.aquasec.com/blog/supply-chain-security-shifting-left-to-the-golden-pipeline/" title="Supply Chain Security: Shifting Left to the Golden Pipeline" class="hs-featured-image-link"><img src="https://www.aquasec.com/wp-content/uploads/2023/01/BLOG-I1-1.jpg" alt="Supply Chain Security: Shifting Left to the Golden Pipeline" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"></a></div>According to an article in Security Magazine, 98% of organizations have been negatively impacted by a cybersecurity breach in their supply chain. Aqua’s 2021 Software Supply Chain Security Review notes that “attackers focused heavily on open source vulnerabilities and poisoning, code integrity issues, exploiting the software supply chain process and supplier trust to distribute malware&#160;&mldr;]]></description>
		
		
		
			</item>
		<item>
		<title>Achieve Software Supply Chain Compliance with US Executive Order 14028</title>
		<link>https://www.aquasec.com/blog/achieve-software-supply-chain-compliance-with-us-executive-order-14028/</link>
		
		<dc:creator><![CDATA[Aqua Security]]></dc:creator>
		<pubDate>Tue, 06 Dec 2022 11:00:00 +0000</pubDate>
				<category><![CDATA[SOFTWARE SUPPLY CHAIN SECURITY]]></category>
		<category><![CDATA[Cloud compliance]]></category>
		<category><![CDATA[SBOMs]]></category>
		<category><![CDATA[Software Supply Chain Security]]></category>
		<guid isPermaLink="false">https://www.aquasec.com/?p=14537</guid>

					<description><![CDATA[<div class="hs-featured-image-wrapper"><a href="https://www.aquasec.com/blog/achieve-software-supply-chain-compliance-with-us-executive-order-14028/" title="Achieve Software Supply Chain Compliance with US Executive Order 14028" class="hs-featured-image-link"><img src="https://www.aquasec.com/wp-content/uploads/2022/12/Blog-Image-Achieve-Software-Supply-Chain-Compliance-with-US-Executive-Order-14028.jpg" alt="Achieve Software Supply Chain Compliance with US Executive Order 14028" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"></a></div>Thanks to many factors like the rise of the cloud infrastructure, the abundance of prebuilt open-source code, and process improvements in DevOps, innovating with software is happening faster than ever. The software supply chain is the assembly line for these technological innovations and can be thought of as any combination of code, tools, and processes&#160;&mldr;]]></description>
		
		
		
			</item>
	</channel>
</rss>
