Supply Chain Risks
The latest Supply Chain Risks coverage — news, analysis, and updates from the WindowsNews.AI desk.
Malicious Next.js Repos Target Developers in Sophisticated C2 Campaign
Microsoft Defender Experts have uncovered a sophisticated, coordinated campaign specifically targeting software developers through malicious Next.js repositories and fake technical assessments,...
Microsoft Copilot DLP Gap & CarGurus Breach Expose Modern IT Security Risks
A recent security incident involving Microsoft's Copilot AI assistant has revealed significant gaps in data loss prevention (DLP) controls, highlighting how even enterprise-grade productivity tools...
CVE-2023-31484: Critical TLS Flaw in CPAN.pm Exposed Perl Developers to Supply Chain Attacks
A critical security vulnerability in Perl's CPAN.pm module, tracked as CVE-2023-31484, exposed countless developers to potential supply chain attacks by failing to properly verify TLS certificates...
Azure Linux Attestation & CVE-2024-42259: Understanding Supply Chain Risk
Microsoft's recent security advisory regarding CVE-2024-42259 in Azure Linux has highlighted critical questions about software supply chain security and the meaning of vendor attestations. The...
Go Toolchain Flaw CVE-2023-29405 Lets Attackers Hijack Builds on Windows, Linux
A critical vulnerability in Go’s build tooling lets attackers run arbitrary code during compilation simply by introducing a malicious module. The flaw, tracked as CVE-2023-29405, affects any...
Go 1.22.5 Patches CVE-2024-34158 Stack Exhaustion Bug in Build Parser
A critical vulnerability in the Go programming language's standard library has been disclosed, posing significant risks to software supply chains and development pipelines worldwide. Tracked as...
SQLite CVE-2019-19926: How a Tiny Patch Caused Major Security Vulnerabilities
In late 2019, the SQLite database engine, which powers countless applications from web browsers to mobile operating systems, revealed a critical vulnerability that demonstrated how even the smallest...
CVE-2024-29195: Critical Buffer Overflow Vulnerability in Azure IoT C SDK Threatens Linux Systems
A critical security vulnerability in Microsoft's Azure IoT infrastructure has exposed Linux systems running Azure IoT applications to potential remote code execution attacks. CVE-2024-29195, a buffer...
CVE-2024-27304: Critical pgx PostgreSQL Driver Vulnerability Exposes SQL Injection Risk
A subtle arithmetic bug in the widely-used Go PostgreSQL driver pgx has escalated into a critical security vulnerability that exposes applications to SQL injection attacks, highlighting the hidden...
CVE-2024-28110: CloudEvents Go SDK Token Leak Threatens Azure & Windows Supply Chains
A critical vulnerability in the CloudEvents Go SDK, designated CVE-2024-28110, has exposed a significant supply-chain risk for applications built on Azure, Windows, and Linux platforms. This security...
CVE-2023-35945: Understanding Azure Linux's nghttp2 Risk & Supply Chain Security
The disclosure of CVE-2023-35945, a critical vulnerability in the nghttp2 library used by the Envoy proxy, has exposed fundamental challenges in modern software supply chain security, particularly...
EcoVadis Wins Microsoft AI Transformation Award: How Sustainability Tech Scales with Azure
EcoVadis, a leading provider of business sustainability ratings, has been recognized by Microsoft with the Local Partner Award for FY25 in the AI Transformation – Scale category. This award...