This page was machine-translated and may differ from the original. View original

▲ Aqua open source status assessment, part of a software supply chain security solution (Image - Aqua Security)
SW Supply Chain Attack Blocking · End-to-End Solution from Code to Runtime
Attacks on software supply chains have been on the rise recently. According to recent proprietary data from Aqua Security, attacks on software supply chains have shown a trend of increasing by 300% annually. Governments around the world are also recognizing the severity of the situation and are taking countermeasures one after another. The U.S. White House already issued an executive order last May stating that supply chain security must be strengthened starting from the software development stage.
Aqua Security (hereinafter Aqua), a pure-play cloud-native security company, announced on the 25th that it has launched the end-to-end 'Aqua Software Supply Chain Security Solution'.
The Aqua Software supply chain security solution introduced this time protects the entire software development lifecycle (SDLC) and is characterized by its ability to actively prevent and block attacks on cloud-native applications.
Aqua identifies third-party artifacts, open source dependencies, and attacks targeting proprietary developer toolsets and environments as causes of supply chain risks.
Aqua is expanding the capabilities of its existing supply chain solutions to address these software supply chain risks. Through this expansion of capabilities, Aqua provides solutions that address supply chain risks from code to runtime, encompassing applications and underlying infrastructure.
Amir Jerbi, CTO and co-founder of Aqua Security, explained, “Other vendors are all missing the critical part. There are solutions that focus on the build, and solutions that focus on both code and the build, but Aqua is the only solution that can take security measures at every stage—code, build, deployment, and runtime.” He added, “Now, development and security teams can build cloud-native application development capabilities and prevent supply chain attacks without any worries.”
According to a report by IBM’s Systems Sciences Institute, fixing bugs during the execution phase costs six times more than fixing them during the design phase. It also pointed out that fixing bugs during the testing phase costs 15 times more than fixing them during the design phase.
Joseph Elbaz, Head of Application Security at the U.S. food delivery platform Grubhub, stated, “There are many attackers targeting source code and dependencies to plant vulnerabilities and backdoors in applications. Aqua’s assurance policy identifies and resolves risks by actively applying security to software supply chain processes and deliverables.” "This is the best way to improve launch quality," he said.
The first software supply chain security solution integrated into CNAPP. The newly released solution is part of Aqua’s integrated Cloud Native Application Protection Platform (CNAPP). As the first CNAPP to include a supply chain solution, Aqua is redefining the CNAPP category with unparalleled integration capabilities and end-to-end protection.
New features of Aqua Software’s supply chain security solution include code scanning to scan code and fix hidden vulnerabilities and risks, CI/CD configuration management to ensure CI/CD toolchain security, pipeline security, and next-generation SBOM.
Aqua's CTO, Amir Zervi, emphasized, "Aqua creates a comprehensive, deep defense shield by adding software supply chain security capabilities to existing dynamic threat analysis and runtime protection, instantly blocking attacks on cloud-native environments."
Meanwhile, with the launch of this SW supply chain security solution, Aqua has completed the technology integration with Argon Security, which it acquired in December 2021.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.















