
How do we stop malware from infecting open-source software libraries?
Cyberattacks on open-source software libraries on are on the rise, creating huge risks for businesses that depend heavily on this resource of basic applications. Malicious code is stealing data, hijacking information systems and harvesting developer credentials. So how can businesses protect themselves? On this episode, we get expert advice from Nathan Kirk, director at NR Labs, a firm specializing in cybersecurity tools and procedures. We’ll talk about recent attacks, and how future ones can be detected and deflected with the help of such techniques as penetration testing to ensure the integrity of applications. And we’ll address the basic question: In these perilous times in which hackers abound, how can we trust software vendors? Hosted by Bob Bowman, Editor-in-Chief of SupplyChainBrain.
Show notes:
An article from NR Labs: “Dynamic Software Composition Analysis: Securing npm Packages With dSCA.”



.png?auto=format%2Ccompress&fit=crop&h=141&q=70&w=250)






