9 days agoSonatype Boosts SBOM Governance with New Features for DevSecOps
Sonatype's IQ Server version 203.2 enhances software supply chain governance with improved SBOM legal frameworks and automation tools. These innovations will support government and contractor compliance and security measures in the evolving software landscape.
23 days agoTeamPCP Exposes Malware Targeting Software Supply Chain Security
TeamPCP's release of the SHAI_HULUD malware source code raises alarm bells for procurement professionals. The incident highlights the urgent need for enhanced security measures in CI/CD pipelines and software development environments across government agencies and contractors.
24 days agoCISA and G7 Issue New Guidance on AI Software Bill of Materials
The CISA and G7 Cybersecurity Working Group have released guidance for a Software Bill of Materials (SBOM) for AI. This initiative aims to enhance security and transparency in AI software supply chains, impacting procurement strategies for contractors and agencies involved in AI technology.