Skip to main content

Cloudsmith Extends Policies and Controls to Secure Application Binaries

Cloudsmith this week revealed it has expanded the policy management and continuous risk detection capabilities it makes available within its software artifact management platform to now include policy templates, cooldown policies, and expanded evaluation triggers.

Alison Sickelka, vice president of product for Cloudsmith, said these additions to the platform will make it simpler to prevent malicious packages from inadvertently being incorporated into the binaries that DevOps teams deploy in production environments.

For example, policy templates written in the Rego programming language can now be used to provide a set of baseline controls that are consistently implemented across a DevOps workflow.

Additionally, DevOps teams can now implement a set of cooldown policies that prevent any recently made available software package from being indexed. That capability ensures that only versions of a validated package are exposed to application developers, noted Sickelka. That’s crucial because many of those packages have been created by maintainers of open source software projects that are targeted by adversaries that have no shortage of time, patience and financial resources.

Finally, the expanded evaluation triggers now consider when a policy was created or updated as part of the metrics used alongside threat intelligence feeds to generate an alert. That capability helps ensure that policies are updated as the application development environment continues to evolve, said Sickelka.

Rather than trying to secure software supply chains by focusing mainly on the source code used to create binaries, Cloudsmith is making a case for applying policies to the binaries that cybercriminals are actually targeting. That approach ensures that application developers are not incorporating malicious packages spread, for example, through a compromised instance of the Axios Node Package Manager that resulted in malicious code being added to an application after it had been deployed, noted Sickelka.

In general, the way software supply chains are secured now clearly needs to evolve, added Sickelka. The days when DevSecOps teams could prioritize their efforts based on the severity ranking of a vulnerability are over. As business and IT leaders in the artificial intelligence (AI) era become more aware of threats to software supply chains, there is a lot more focus on preventing security incidents from occurring in the first place by ensuring malicious packages and other known vulnerabilities that can now be easily exploited don’t find their way into production environments, said Sickelka.

In fact, in many cases CISOs are now willing to fund the acquisition of the tools and platforms needed to secure software supply chains in the hopes of reducing the number of downstream incidents they might later need to respond to in the event of a cyberattack, she added.

Hopefully, the increased focus on software supply chains will result in more secure applications being deployed. In the short term, however, it’s probable there will be a significant amount of turmoil as cybercriminals leverage AI to exploit increasingly well-known weaknesses in software supply chains. The challenge and the opportunity now is to reduce as many of those potential incidents as possible by applying more rigorous policies and controls that, if properly implemented, should not slow down the pace at which modern software can be securely built and deployed.



from DevOps.com https://ift.tt/LeCFM3Y

Comments

Popular posts from this blog

AWS Adds Agentic Workspace to Kiro AI Coding Tool

Amazon Web Services (AWS) this week added an open source workspace for its Kiro artificial intelligence (AI) coding tool that enables application developers to asynchronously assign tasks to an AI agent that is capable of autonomously performing tasks, such as testing code as it is created, in a way that maintains context across multiple sessions. Darko Mesaros, a distinguished developer advocate at AWS, said the Kiro Crew workspace is also capable of creating reusable AI skills by observing the tasks developers assign to Kiro as they write code. Kiro Crew orchestrates agents using the Agent Client Protocol (ACP) to ensure every step is observable in real time as sub-agents are spawned. For example, developers can also hand off a ticket queue to Kiro Crew for it to triage issues and flag what needs their attention or ask it to investigate the root cause of an incident while a developer continues to work on another task. An Activity view shows each agent’s reasoning, every tool call,...

Five Tips to Approach DevSecOps Training

Developers are on the front lines when it comes to protecting their organizations from cyberattacks. As we’ve seen with the hacks of Monster.com or the Fortnite vulnerability, 2019 has been a trying year for organizations who have failed to protect their applications and websites. With an increase of cyberthreats today, it is vital that organizations and developers incorporate standard […] The post Five Tips to Approach DevSecOps Training appeared first on DevOps.com . from DevOps.com https://ift.tt/2N1jSTn

Hospitals That Fail to Reopen Psychiatric Wards Risk Fines, Hochul Says

Hospitals That Fail to Reopen Psychiatric Wards Risk Fines, Hochul Says By Joseph Goldstein from NYT New York https://ift.tt/GHzkOtc Psychiatry and Psychiatrists, Mental Health and Disorders, Hospitals, Subways, Emergency Medical Treatment, Methodist Hospital, Northwell Health, Hochul, Kathleen C, Go, Michelle Alyssa, Adams, Eric L, Neely, Jordan (d 2023)