Medtronic Discloses Cyber Breach by ShinyHunters Gang

Medtronic recently reported a cyber breach by the ShinyHunters gang to federal authorities and the SEC, revealing that hackers had infiltrated its corporate IT system. Fortunately, the company has found no evidence that patient safety or electronic connections to customers were compromised.

https://osintsights.com/medtronic-discloses-cyber-breach-by-shinyhunters-gang?utm_source=mastodon&utm_medium=social

#Healthcare #Medtronic #Shinyhunters #CyberBreach #SoftwareSupplyChain

Medtronic Discloses Cyber Breach by ShinyHunters Gang

Medtronic hit by ShinyHunters gang cyber breach learn how to protect your business from threat modeling risks now and prevent similar attacks effectively today.

OSINTSights

FedRAMP compliance in weeks, not months ⚑

Ready-to-deploy policy packs for instant compliance feedback πŸ“‹

https://anchore.com/platform/enforce/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance

Built on 30M+ download open source tools (Syft & Grype) πŸ”§

Community-proven, enterprise-hardened πŸ’ͺ

https://anchore.com/platform/secure/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps

Your MCP server might be the weakest linkβ€”here's the data. @josh.bressers.name scanned 161 MCP images and found 9,000 vulns / 263 criticals. Read the breakdown and fixes: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/

#MCP #SoftwareSupplyChain #ContainerSecurity #DevSecOps

Cloudsmith Bolsters Software Supply-Chain Security with $72M Raise

Cloudsmith just secured $72 million to supercharge its artifact management platform and take software supply-chain security to the next level. With a strong artifact management layer in place, companies can enjoy the added benefit of a secure software supply chain.

https://osintsights.com/cloudsmith-bolsters-software-supply-chain-security-with-72m-raise?utm_source=mastodon&utm_medium=social

#SoftwareSupplyChain #ArtifactManagement #FundingRound #SeriesC #Cloudsmith

Cloudsmith Bolsters Software Supply-Chain Security with $72M Raise

Learn how Cloudsmith's $72M raise enhances software supply-chain security with artifact management, bolstering defenses - read the latest on their growth strategy now.

OSINTSights

"Bring Your Own SBOM" sounds simple...

Until you try to manage thousands of them πŸ“Š

Scale is everything πŸ“ˆ

https://anchore.com/platform/sbom/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps

False positives killing your team's productivity? πŸ˜΅β€πŸ’«

Anchore Secure gives you signal, not noise πŸ“‘

https://anchore.com/platform/secure/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps

Asfaload can now use your ed25519 #ssh keys to sign artifacts! No additional key to manage for Asfaload. https://github.com/asfaload/asfaload
#security #softwaresupplychain
GitHub - asfaload/asfaload: Generic multisig signoff solution

Generic multisig signoff solution. Contribute to asfaload/asfaload development by creating an account on GitHub.

GitHub

The EU’s Cyber Resilience Act (CRA) is a β€œGDPR moment” for #SoftwareSecurity.

In this #InfoQ #podcast, Viktor Peterson explores how the CRA is reshaping expectations for software producers & supply chain compliance.

Key highlights:
βœ… Why SBOMs are operational assets
βœ… The danger of "weaponized code" in your security tools
βœ… The shift toward vendor-neutral discovery

🎧 Listen now: https://bit.ly/429icwC

πŸ“„ #transcript included

#CyberSecurity #SBOM #SoftwareSupplyChain #Compliance

Recent software supply chain attacks - yowers!

In March, popular open source tools Trivy and Axios were compromised with malware, and we won't know the full blast radius for months.

Axios was breached by North Korean hackers who turned it into a malware delivery vehicle for about three hours after attackers hijacked a maintainer's account and slipped a remote-access trojan (RAT) into two seemingly legitimate releases.

Trivy was hacked by a loosely knit band of hackers called TeamPCP, who injected credential-stealing malware.

"Attackers are starting to really look at the supply chain and open source packages, and figure out ways to compromise developers to deliver malware or gather data" ... https://www.theregister.com/2026/04/11/trivy_axios_supply_chain_attacks/ #Hackers #Malware #Software #OpenSource #SoftwareSupplyChain #Trojan #CyberSecurity #Security #Trivy #Axios