msspalert.com
Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-09-04.
| Date Added | Resource | Excerpt |
|---|---|---|
| 2026-09-04 2026 | CrowdStrike introduces real-time supply chain attack protectionSupply Chain | CrowdStrike has launched a new real-time supply chain attack protection solution. This innovative offering aims to safeguard organizations by detecting and preventing threats that originate from compromised third-party software or services. The focus is on proactive defense against evolving supply chain risks, ensuring businesses can maintain operational integrity and data security. |
| 2026-09-04 2026 | Hackers exploit chained SonicWall gaps for remote code executionRCE | Attackers are exploiting chained vulnerabilities in SonicWall network security devices to achieve remote code execution. This allows them to gain unauthorized access and control over compromised systems. The identified vulnerabilities, when chained together, create a significant security risk for organizations relying on SonicWall appliances. This exploit highlights the ongoing threats to network infrastructure and the importance of prompt security patching and monitoring. |
| 2026-07-29 2026 | Bugcrowd brings continuous agentic pentesting to web apps and APIs with Savant PathseekerAPI Sec | Library by Bugcrowd, Savant Pathseeker, offers continuous agentic penetration testing for external web applications and APIs. Unlike traditional scanners, it identifies vulnerabilities, attempts exploitation, and provides evidence of exploitability. Pathseeker utilizes purpose-built agentic systems with proprietary security testing skills and orchestration, including autonomous API fuzzing and attack-path reasoning, complementing human-led investigations for complex issues. Findings integrate directly into the Bugcrowd platform, correlating with human results for prioritized remediation. |
| 2026-07-01 2026 | NetRise brings managed software supply chain risk management to federal partnersSupply Chain | Library for managed software supply chain risk management, targeting federal integrators and MSPs. It combines binary analysis with NetRise Provenance to provide context on software origin, maintainers, repository health, and downstream exposure. The offering helps validate SBOMs, build software inventories, identify cryptographic algorithms and libraries, and supports federal workflows like RMF, ATO, and continuous monitoring. It addresses federal pressure for better software visibility due to risks from vendors, open source, and third-party products, and supports initiatives around vulnerability remediation and AI security. |
| 2026-04-23 2026 | Six AI Vulnerabilities Three Attack Patterns One Dangerous Service GapAI | Library for analyzing AI vulnerabilities, focusing on three distinct attack patterns: untrusted input processed as trusted AI context, overly broad AI data access without per-operation enforcement, and process containment and functional scoping failures. This analysis covers vulnerabilities like EchoLeak, Reprompt, ForcedLeak, GeminiJack, and GrafanaGhost, highlighting the need for robust input validation extended to all data sources AI touches, per-operation access control for AI data requests, and strict functional scoping for back-end AI processes, rather than solely relying on model-level guardrails. |