appsec.fyi · Sources

msspalert.com

5 curated AppSec resources from msspalert.com across 4 topics on appsec.fyi.

msspalert.com

Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-09-04.

Date Added Resource Excerpt
2026-09-04 2026CrowdStrike introduces real-time supply chain attack protectionSupply ChainCrowdStrike has launched a new real-time supply chain attack protection solution. This innovative offering aims to safeguard organizations by detecting and preventing threats that originate from compromised third-party software or services. The focus is on proactive defense against evolving supply chain risks, ensuring businesses can maintain operational integrity and data security.
2026-09-04 2026Hackers exploit chained SonicWall gaps for remote code executionRCEAttackers are exploiting chained vulnerabilities in SonicWall network security devices to achieve remote code execution. This allows them to gain unauthorized access and control over compromised systems. The identified vulnerabilities, when chained together, create a significant security risk for organizations relying on SonicWall appliances. This exploit highlights the ongoing threats to network infrastructure and the importance of prompt security patching and monitoring.
2026-07-29 2026Bugcrowd brings continuous agentic pentesting to web apps and APIs with Savant PathseekerAPI SecLibrary by Bugcrowd, Savant Pathseeker, offers continuous agentic penetration testing for external web applications and APIs. Unlike traditional scanners, it identifies vulnerabilities, attempts exploitation, and provides evidence of exploitability. Pathseeker utilizes purpose-built agentic systems with proprietary security testing skills and orchestration, including autonomous API fuzzing and attack-path reasoning, complementing human-led investigations for complex issues. Findings integrate directly into the Bugcrowd platform, correlating with human results for prioritized remediation.
2026-07-01 2026NetRise brings managed software supply chain risk management to federal partnersSupply ChainLibrary for managed software supply chain risk management, targeting federal integrators and MSPs. It combines binary analysis with NetRise Provenance to provide context on software origin, maintainers, repository health, and downstream exposure. The offering helps validate SBOMs, build software inventories, identify cryptographic algorithms and libraries, and supports federal workflows like RMF, ATO, and continuous monitoring. It addresses federal pressure for better software visibility due to risks from vendors, open source, and third-party products, and supports initiatives around vulnerability remediation and AI security.
2026-04-23 2026Six AI Vulnerabilities Three Attack Patterns One Dangerous Service GapAILibrary for analyzing AI vulnerabilities, focusing on three distinct attack patterns: untrusted input processed as trusted AI context, overly broad AI data access without per-operation enforcement, and process containment and functional scoping failures. This analysis covers vulnerabilities like EchoLeak, Reprompt, ForcedLeak, GeminiJack, and GrafanaGhost, highlighting the need for robust input validation extended to all data sources AI touches, per-operation access control for AI data requests, and strict functional scoping for back-end AI processes, rather than solely relying on model-level guardrails.