720-891-1663

Supply Chain Risk in the Software Process

I have been talking a lot about supply chain risk lately and there is a good reason. From open source products with backdoors like Webmin or Rubygems to NotPetya a few years ago which shut down many companies around the world to the recent attacks against SolarWinds or Centreon, supply chain attacks are running rampant. […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Bloomberg Says China Adds Spy chips to Computers

In 2018 Bloomberg ran a story that claimed that China had embedded tiny microchips on Supermicro computer server processor boards in 2015. Everyone denied it – Supermicro, the intelligence community (IC), China. Supply chain attacks seem to be everywhere these days and this is another one. I don’t know if it is true, but why […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News for the Week Ending February 12, 2021

Law Firm Goodwin Procter Hacked Goodwin Procter managing parnter Mark Bettencourt confirmed that some of their clients’ data was compromised. But not to worry; it only affected a small percentage of their clients. One more time, we have a “supply chain attack”. While the vendor was unnamed, I suspect it was Accellion. They suffered a […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Is $100 Million Enough of a Reason to Improve Security?

SIM swap attacks is a hacking technique where hackers socially engineer cell phone providers to steal a victim’s phone number. That means that hackers get the victim’s text messages and phone calls. While two factor authentication is not used by the majority of people, when it is used, the most common form of two factor […]

Continue reading → [DISPLAY_ACURAX_ICONS]