Here is another example of a critical software provider being exploited. Organizations need to ensure they are performing proper vendor due diligence, particularly on critical service providers and partners. Not all partners play critical roles, so organizations should focus on those providers who directly impact the business's operations or possess critical data needed to operate the business. Prioritization and context are key in building an effective third party risk management program.
| less than a minute read
Is this going to be SolarWinds 2.0?
Federal officials are investigating a security breach at software auditing company Codecov, which apparently went undetected for months, Reuters reported. Codecov’s platform is used to test software code for vulnerabilities, and its 29,000 clients include Atlassian, Proctor & Gamble, GoDaddy, and the Washington Post.