Third-party Cybersecurity Risks Surge: Attackers are increasingly targeting less secure partners and vendors to ultimately gain access to the real target’s internal systems and data. This happened recently — after the announcement of vulnerabilities in MOVEit Transfer, unsuspecting third-parties of victims found themselves affected. The fact that so many organizations continue to fail controls important for sound vulnerability management is cause for concern.
Google's updated Minimum Viable Secure Product (MVSP) program offers advice for working with researchers and warns against vendors charging extra for basic security features.
Since the compromise of the SolarWinds Orion update mechanism two years ago this month, governments and the IT industry have made strides in trying to reduce the attack surface of applications. However, Google believes software supply chain security is still one of the most critical security risks facing the world. "There is an urgent need