Parasoft announces the opening of its new office in Northeast Ohio.
Checkmarx announced the immediate availability of Supply Chain Threat Intelligence, which delivers detailed threat intelligence on hundreds of thousands of malicious packages, contributor reputation, malicious behavior and more.
Based on proprietary research by Checkmarx Labs, Supply Chain Threat Intelligence offers:
- Identification of malicious packages by attack type such as dependency confusion, typosquatting, chainjacking and more
- Analysis of contributor reputation through identification of anomalous activity within open source packages
- Intelligence on the malicious behavior of packages, including static and dynamic analysis to understand how the code runs
- A data lake that allows the ongoing analysis of packages long after they have been deleted from package managers, with over one million packages scanned per month
"In 2022, Checkmarx researchers exposed some of the most prolific open source attack groups, including RED-LILI and Lofygang," said Checkmarx CEO Emmanuel Benzaquen.
Checkmarx Supply Chain Threat Intelligence is delivered as an application programming interface (API) that is simple to integrate into many dashboards and development environments. Users obtain a unique token from Checkmarx, send in a package name and version and receive threat intelligence on the package.
The API helps developers and security professionals:
- Quickly and easily identify potential threats in open source packages
- Better understand the threat actor's decision-making process
- Perform bulk queries to efficiently receive intel on large numbers of packages at once
- Stay ahead of cyber threats with real-time updates and alerts on new and emerging risks
- Gain valuable insights and context on detected threats to inform security decisions
"Our Checkmarx Labs supply chain security team discovered 150,878 unique malicious packages in 2022 alone," said Erez Yalon, VP of Security Research at Checkmarx. "We're seeing attackers continue to strike and publish malicious packages even after they've been reported. They simply create new sock-puppet accounts and nothing stops them from doing so. Their relentless malicious behavior and the increasing velocity of new malicious package releases have led us to share our threat intelligence to help keep the open source ecosystem safe."
Industry News
Postman released v11, a significant update that speeds up development by reducing collaboration friction on APIs.
Sysdig announced the launch of the company’s Runtime Insights Partner Ecosystem, recognizing the leading security solutions that combine with Sysdig to help customers prioritize and respond to critical security risks.
Nokod Security announced the general availability of the Nokod Security Platform.
Drata has acquired oak9, a cloud native security platform, and released a new capability in beta to seamlessly bring continuous compliance into the software development lifecycle.
Amazon Web Services (AWS) announced the general availability of Amazon Q, a generative artificial intelligence (AI)-powered assistant for accelerating software development and leveraging companies’ internal data.
Red Hat announced the general availability of Red Hat Enterprise Linux 9.4, the latest version of the enterprise Linux platform.
ActiveState unveiled Get Current, Stay Current (GCSC) – a continuous code refactoring service that deals with breaking changes so enterprises can stay current with the pace of open source.
Lineaje released Open-Source Manager (OSM), a solution to bring transparency to open-source software components in applications and proactively manage and mitigate associated risks.
Synopsys announced the availability of Polaris Assist, an AI-powered application security assistant on the Synopsys Polaris Software Integrity Platform®.
Backslash Security announced the findings of its GPT-4 developer simulation exercise, designed and conducted by the Backslash Research Team, to identify security issues associated with LLM-generated code. The Backslash platform offers several core capabilities that address growing security concerns around AI-generated code, including open source code reachability analysis and phantom package visibility capabilities.
Azul announced that Azul Intelligence Cloud, Azul’s cloud analytics solution -- which provides actionable intelligence from production Java runtime data to dramatically boost developer productivity -- now supports Oracle JDK and any OpenJDK-based JVM (Java Virtual Machine) from any vendor or distribution.
F5 announced new security offerings: F5 Distributed Cloud Services Web Application Scanning, BIG-IP Next Web Application Firewall (WAF), and NGINX App Protect for open source deployments.
Code Intelligence announced a new feature to CI Sense, a scalable fuzzing platform for continuous testing.
WSO2 is adding new capabilities for WSO2 API Manager, WSO2 API Platform for Kubernetes (WSO2 APK), and WSO2 Micro Integrator.