Home / Companies / JFrog / Blog / December 2022

December 2022 Summaries

6 posts from JFrog

Filter
Month: Year:
Post Summaries Back to Blog
In August, LastPass, a cloud-based password manager, suffered a security breach where an unauthorized party accessed its development environment; initially, it was reported that no user data was compromised. However, a December update revealed that attackers used leaked technical data to target another employee, leading to the compromise of customer vault data containing unencrypted website URLs and encrypted usernames and passwords. This breach poses significant risks, including potential phishing attacks and offline brute-forcing of master passwords. The incident highlights the growing trend of targeting developers due to their control over company environments. In response, users are advised to use multi-factor authentication, change their passwords, and consider switching to other password managers like 1Password or Bitwarden, which address the security shortcomings exposed by this breach. The JFrog Security Research team emphasizes the importance of staying informed about security updates and being cautious of phishing campaigns exploiting the leaked information.
Dec 29, 2022 859 words in the original blog post.
AWS re:Invent 2022 saw a return to full capacity with over 50,000 attendees, highlighting themes of event-driven architectures and cloud-powered innovation as key enablers of business transformation. The event underscored the diverse paths to digital transformation, with examples like Trustpilot leveraging event-driven microservices for enhanced service delivery. AWS introduced Amazon CodeCatalyst to simplify developer processes, supporting a vision of continuously updated, interconnected "liquid software." Security in the software supply chain emerged as a critical focus, with tools like AWS Marketplace Vendor Insights streamlining risk assessments. The conference emphasized the strategic role of AWS Marketplace in monetizing cloud partnerships and optimizing committed spend dollars, with JFrog illustrating how these innovations can accelerate DevOps transformations.
Dec 19, 2022 1,043 words in the original blog post.
Red Hat OpenShift serves as an enterprise Kubernetes container platform, enabling the creation and deployment of Docker images in a cloud-like environment. These images can be seamlessly integrated into JFrog Artifactory, a universal repository manager, to facilitate build metadata recording using JFrog’s SBOM format, which includes modules, artifacts, and dependencies crucial for identifying code vulnerabilities. To utilize this feature, users need a JFrog subscription, along with the installation of JFrog CLI version 2.4.0 or above, and OpenShift CLI version 3.0.0 or above. The process involves logging into the OpenShift environment, creating a credentials secret for secure Artifactory access, modifying the BuildConfig YAML in OpenShift, and configuring the JFrog CLI with platform details. Once set up, users can build images, collect build-info, and publish it to Artifactory, with additional capabilities such as scanning for security vulnerabilities and license compliance available through JFrog CLI. The JFrog CLI project is open-source, welcoming community contributions via its GitHub repository.
Dec 14, 2022 482 words in the original blog post.
The JFrog Security Research team has identified and reported a sophisticated piece of malware on the Python Package Index (PyPI) named "cookiezlog," which employs advanced static and dynamic obfuscation techniques to evade detection. Unlike typical malware, "cookiezlog" incorporates anti-debugging code, a first in PyPI malware, to thwart dynamic analysis tools. Upon installation, the package executes malicious code that downloads an executable disguised as a Python script packed into a Windows PE file. The malware's defenses include zlib encoding, PyArmor obfuscation, and checks for virtual machine environments and debugging tools. Despite its complex defenses, the payload itself is a relatively simple password grabber targeting browser-stored passwords and financial services credentials. The discovery highlights the evolving sophistication of malware in open-source software repositories, paralleling the development of native malware in employing multifaceted protection against analysis.
Dec 13, 2022 1,516 words in the original blog post.
As software complexity grows, securing the software supply chain becomes increasingly critical and challenging, prompting the International Data Corporation (IDC) to provide insights on addressing these challenges following the release of JFrog Advanced Security on October 18, 2022. JFrog's new DevSecOps solution is hailed as a compelling approach to simplifying security tooling for businesses, emphasizing the importance of securing the software supply chain to prevent significant impacts from undetected attacks. Existing JFrog customers are encouraged to integrate these new security capabilities into their DevOps pipelines, while organizations not yet using JFrog’s tools are advised to consider adopting them. The introduction of Advanced Security features is set to bolster JFrog's standing in the rapidly growing DevSecOps market, driven largely by the widespread adoption of open-source software.
Dec 06, 2022 380 words in the original blog post.
Tail Spend refers to the unmanaged, high-volume, low-value transactions within organizations, often overlooked but cumulatively significant in financial impact, especially in procurement processes. The rise in SaaS usage, with companies averaging over 130 apps, complicates Tail Spend management as procurement leaders struggle with visibility and control over application expenditures. While SaaS facilitates fast solutions, it also introduces procurement manageability issues, leading to challenges in building strategic vendor relationships. Companies are encouraged to transform Tail Spend into Strategic Spend by consolidating SaaS products through marketplaces, thus optimizing costs and leveraging opportunities for savings. In a cloud-driven digital transformation landscape, traditional procurement models are inadequate, necessitating agile and flexible approaches to align with rapid technological advancements and market demands. JFrog aids in this transition by collaborating with cloud partners to consolidate spending and co-designing DevSecOps platforms, facilitating a seamless shift to SaaS-based or hybrid models for improved efficiency and cost-effectiveness.
Dec 05, 2022 1,235 words in the original blog post.