OutSystems announced the general availability (GA) of Mentor on OutSystems Developer Cloud (ODC).
Software supply chain attacks are rising fast, targeting organizations' vulnerabilities with increasing sophistication. High-profile cases like MOVEit Transfer, Apache Log4J, and Polyfill created holes in the defenses of thousands of organizations, emphasizing the need for stronger security. As businesses rely more on third-party software providers, their attack surfaces grow, often leaving them exposed to hidden threats from managed assets.
CyCognito recently conducted an analysis of over 39 million data points from a diverse range of companies, providing concrete evidence validating the growing concerns about the vulnerability of our software supply chains.
The report's findings reveal a troubling reality: our digital ecosystems are far more vulnerable than we'd like to believe. This isn't just another cybersecurity warning — it's a critical issue that demands immediate attention from business leaders, IT professionals, and policymakers alike.
Web Servers: The Achilles' Heel of Cybersecurity
The report's most alarming finding is that web servers account for one in three severe issues among surveyed assets. These include known platforms Apache, NGINX, Microsoft IIS, and Google Web Server that many organizations rely on. Given how critical these servers are to digital infrastructure, this level of vulnerability is extremely dangerous. If left unaddressed, these weaknesses could lead to major security breaches and system failures.
Encryption Protocols: Not as Secure as We Thought
Even more alarming is the state of our encryption protocols. The report found that 15% of all severe issues on the attack surface affect platforms using TLS or HTTPS protocols. TLS issues are significant for all network-delivered data, but web apps especially so; web apps lacking encryption are currently ranked #2 of the OWASP Top 10.
Personal Data at Risk
Perhaps the most concerning aspect of the report is its findings on personal data protection. Only half of the web interfaces handling personally identifiable information (PII) are protected by a Web Application Firewall (WAF). This lack of protection for our most sensitive data is unacceptable in today's threat landscape.
Despite HTTPS celebrating its 30th birthday this year, almost one in three (31%) of surveyed web interfaces failed to implement it. More than 60% of these interfaces that expose PII also lack a WAF.
A Call to Action
These findings clearly highlight that businesses must prioritize cybersecurity at every level of their operations. This involves rigorous testing and vetting of all software, whether developed in-house or sourced from third parties. Companies must implement robust security measures throughout their software supply chains and cultivate a culture of cybersecurity awareness among employees.
Consumers, too, have a role to play. We need to be more discerning about our digital security by asking tough questions regarding how companies protect our data. Holding businesses accountable for their security practices should become second nature, and we must be willing to prioritize safety over convenience, even if it means sacrificing some ease of use.
Policymakers must step up as well. Stronger regulations and enforcement mechanisms are essential to ensure that companies take adequate steps to protect their software supply chains. Increased funding for cybersecurity research and education will help build a workforce capable of tackling these challenges head-on. Additionally, developing policies that incentivize better security practices within the private sector is crucial for long-term improvement.
The Road Ahead
The vulnerabilities exposed in the report are not abstract concepts — they are real weaknesses that could be exploited at any moment, potentially leading to data breaches, financial losses, and erosion of public trust.
We face a choice: continue with business as usual and hope we're not the next victim, or take decisive action to secure our digital infrastructure. The stakes are too high for half-measures or quick fixes. We need a comprehensive, coordinated effort to address the vulnerabilities in our software supply chains.
Industry News
Kurrent announced availability of public internet access on its managed service, Kurrent Cloud, streamlining the connectivity process and empowering developers with ease of use.
MacStadium highlighted its major enterprise partnerships and technical innovations over the past year. This momentum underscores MacStadium’s commitment to innovation, customer success and leadership in the Apple enterprise ecosystem as the company prepares for continued expansion in the coming months.
Traefik Labs announced the integration of its Traefik Proxy with the Nutanix Kubernetes Platform® (NKP) solution.
Perforce Software announced the launch of AI Validation, a new capability within its Perfecto continuous testing platform for web and mobile applications.
Mirantis announced the launch of Rockoon, an open-source project that simplifies OpenStack management on Kubernetes.
Endor Labs announced a new feature, AI Model Discovery, enabling organizations to discover the AI models already in use across their applications, and to set and enforce security policies over which models are permitted.
Qt Group is launching Qt AI Assistant, an experimental tool for streamlining cross-platform user interface (UI) development.
Sonatype announced its integration with Buy with AWS, a new feature now available through AWS Marketplace.
Endor Labs, Aikido Security, Arnica, Amplify, Kodem, Legit, Mobb and Orca Security have launched Opengrep to ensure static code analysis remains truly open, accessible and innovative for everyone:
Progress announced the launch of Progress Data Cloud, a managed Data Platform as a Service designed to simplify enterprise data and artificial intelligence (AI) operations in the cloud.
Sonar announced the release of its latest Long-Term Active (LTA) version, SonarQube Server 2025 Release 1 (2025.1).
Idera announced the launch of Sembi, a multi-brand entity created to unify its premier software quality and security solutions under a single umbrella.
Postman announced the Postman AI Agent Builder, a suite empowering developers to quickly design, test, and deploy intelligent agents by combining LLMs, APIs, and workflows into a unified solution.
The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, announced the graduation of CubeFS.