A Call to Action on Software Supply Chain Security | A NVD 2022 ReversingLabs Analysis
The NVD is a critical resource for both software development and security organizations.Flaws in open source are contributing to a sharp rise in reports to the National Vulnerability Database in 2022. But emerging software supply chain attacks warrant a re-think of the NVD—and your software security approach—to go beyond common software vulnerabilities.
Report Snap Shot
Key report takeaways:
- Attackers are shifting their efforts from apps to software component
- The NVD is not keeping pace with supply chain risk
- Trust is key. Focus on what code does—not just where it comes from