{"id":4995,"date":"2026-09-02T20:21:29","date_gmt":"2026-09-02T20:21:29","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/02\/crowdstrike-moves-to-secure-software-supply-chains-at-the-endpoint\/"},"modified":"2026-09-02T20:21:29","modified_gmt":"2026-09-02T20:21:29","slug":"crowdstrike-moves-to-secure-software-supply-chains-at-the-endpoint","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/02\/crowdstrike-moves-to-secure-software-supply-chains-at-the-endpoint\/","title":{"rendered":"CrowdStrike Moves to Secure Software Supply Chains at the Endpoint"},"content":{"rendered":"<div><img data-opt-id=1384438764  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/09\/crowdstrike_supply_chain_770x330.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=448408937  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/09\/crowdstrike_supply_chain_770x330-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p>CrowdStrike today at its <a href=\"https:\/\/www.crowdstrike.com\/en-us\/events\/fal-con\/las-vegas\/\">Fal.con 2026 <\/a>conference extended its reach into the realm of software supply chain security with the addition of an offering that blocks malicious open-source packages at the endpoint before their embedded code can run.<\/p>\n<p><span>Bartley Richardson, chief AI and autonomous systems officer for CrowdStrike, said <\/span><a href=\"https:\/\/www.crowdstrike.com\/en-us\/press-releases\/crowdstrike-extends-endpoint-advantage-to-secure-software-supply-chain\/\"><span>Real-Time Supply Chain Attack Protection<\/span><\/a><span> is designed to prevent both human developers and artificial intelligence (AI) coding agents from downloading malicious software packages that have been poisoned by malicious actors. The only place to effectively thwart these types of attacks is at the command line interface (CLI) running on the endpoint used to build an application, added Richardson.<\/span><\/p>\n<p><span>Based on a sensor that CrowdStrike relies on to secure endpoints, Real-Time Supply Chain Attack Protection intercepts open-source package manager transactions before any embedded script runs on a Windows, macOS or Linux endpoint. DevSecOps teams, as a result, have complete visibility into every software package installed across every endpoint, so when a package is compromised, security teams know exactly where it lives and can act immediately.<\/span><\/p>\n<p><span>Additionally, the moment a package is flagged, CrowdStrike automatically runs a lookback across every endpoint and triggers remediation workflows via its Charlotte agentic AI automation platform.<\/span><\/p>\n<p><span>Finally, every malicious package discovered serves to make Real-Time Supply Chain Attack Protection smarter about what to look for in the next attack, said Richardson. <\/span><\/p>\n<p><span>Software supply chain security is becoming a more pressing concern as adversaries continue to aggressively exploit vulnerabilities found in code. CrowdStrike\u2019s 2026 Threat Hunting Report, for example, found STARDUST CHOLLIMA, a cybersecurity syndicate that operates out of North Korea, has poisoned 131 trusted AI framework packages, while another syndicate dubbed eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day.<\/span><\/p>\n<p><span>The challenge is that poisoned software packages look like any other ordinary file. Once installed, code starts to automatically run, which means that code may not be discovered for days, if ever, by legacy scanning tools. Adding insult to injury, if not stopped at the endpoint before embedded scripts execute, a poisoned package also starts to move downstream as applications are deployed.<\/span><\/p>\n<p><span>More challenging still, AI agents that are becoming more widely deployed are also likely to discover a poisoned package that will then be incorporated into an agentic workflow.<\/span><\/p>\n<p><span>CrowdStrike, in effect, is making a case for using its endpoint security tools to prevent malicious software packages from ever finding their way into the software supply chain in the first place.<\/span><\/p>\n<p><span>It\u2019s not clear to what degree organizations that build software are revisiting their DevSecOps workflows, but it\u2019s apparent that legacy processes need to be updated in the AI era. The challenge is that as it becomes simpler to build and distribute malicious packages, the current state of the art depends far too much on an individual developer to distinguish between one file versus another in what has become a sea of them.<\/span><\/p>\n<p><a href=\"https:\/\/devops.com\/crowdstrike-moves-to-secure-software-supply-chains-at-the-endpoint\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>CrowdStrike today at its Fal.con 2026 conference extended its reach into the realm of software supply chain security with the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4996,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-4995","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4995","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=4995"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4995\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/4996"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=4995"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=4995"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=4995"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}