Connect with us

TECHNOLOGY

Palo Alto Networks: Poor software supply chain impacts cloud infrastructure

As an example of the prevalence of misconfigurations, Unit 42 researchers analyzed public Terraform modules by number of misconfigurations (left) and types of misconfigurations and their percentages (right). Source: Unit 42 Cloud Threat Report, 2H 2021.

Posted on Nov. 19, 8:48 p.m.

HIGH-PROFILE software supply chain attacks such as SolarWinds and Kaseya have shed a glaring light on the disparity between organizations’ perceptions of security within their cloud infrastructure, and the reality of threats in their supply chains that can impact business catastrophically. 

In the latest Palo Alto Networks’ Unit 42 Cloud Threat Report, 2H 2021, Unit 42 researchers dive deep into the full scope of supply chain attacks in the cloud and explain often misunderstood details about how they occur.

They also provide actionable recommendations any organization can adopt immediately to begin protecting their software supply chains in the cloud. 

The Unit 42 team analyzed data from a variety of public data sources around the world in order to draw conclusions about the growing threats organizations face today in their software supply chains. 

Their findings indicate that many organizations may have a false sense of security in the cloud and in reality are vastly unprepared for the threats they face. 

In addition to analyzing data, Unit 42 researchers were commissioned by a large SaaS provider (a customer of Palo Alto Networks) to run a red team exercise against their software development environment. In just three days, a single Unit 42 researcher discovered critical software development flaws that left the customer vulnerable to an attack similar to that of SolarWinds and Kaseya.

Key Findings

Poor Supply Chain Hygiene Impacts Cloud Infrastructure

The large SaaS provider detailed in the red team exercise has what many would consider a mature cloud security posture. However, during the exercise, Unit 42 researchers were able to leverage misconfigurations in the organization’s software development environment, such as the presence of hardcoded IAM key pairs, that would have allowed them to control all development processes and thus conduct a successful supply chain attack.Further, Unit 42 researchers found that 21% of the security scans they ran against the customer’s development environment resulted in misconfigurations or vulnerabilities, highlighting how process gaps and critical security flaws leave an organization exposed and susceptible to a business-halting attack.

Third-Party Code Is Rarely Trustworthy

In their research, Unit 42 researchers discovered that 63% of third-party code templates used in building cloud infrastructure contained insecure configurations, and 96% of third-party container applications deployed in cloud infrastructure contain known vulnerabilities. With this level of risk, an attacker could easily gain access to sensitive data in the cloud and even take control of an organization’s software development environment. Based on the Unit 42 team’s findings, it’s evident that unvetted code can quickly snowball into a security breach, especially as infrastructure flaws can directly impact thousands of cloud workloads. For that reason, it is critical that organizations understand where their code is coming from since third-party code can come from anyone, including an Advanced Persistent Threat (APT).

Conclusion: Organizations Need to Shift Security Left

Teams continue to neglect DevOps security, due in part to lack of attention to supply chain threats. Cloud native applications have a long chain of dependencies, and those links have relationships of their own. DevOps and Security teams need to gain visibility into the bill of materials in every cloud workload in order to evaluate risk at every stage of the dependency chain and establish guardrails.

TECHNOLOGY

inDrive is 4th most downloaded travel app in PH

2:11 p.m. February 12, 2026

WITH over four million installations in 2025 alone, inDrive ranked fourth among the most downloaded travel apps in the Philippines, according to market intelligence firm Sensor Tower. 

This ranking underscores Filipino users’ growing demand for inDrive to expand beyond ride-hailing as it evolves into a mobility super app.

inDrive also remained the world’s second most downloaded ride-hailing app for the fourth straight year. It also climbed from fifth to fourth place among the top travel apps globally and topped this category in Pakistan, Peru, Egypt, Morocco, the Dominican Republic, Ecuador, Guatemala, Panama, and Zimbabwe.

Reflecting on this milestone, inDrive Founder and CEO Arsen Tomsky said, “This recognition reflects the trust people place in our platform and the continued dedication of our global team. As inDrive evolves into a super app, we remain focused on our core principles of fairness, transparency, and user choice while expanding access to services that make a meaningful difference in people’s daily lives.”

Full Speed Ahead as inDrive Evolves into a SuperApp

With inDrive growing its user base year-on-year, the app has begun expanding its services beyond ride-hailing in other key markets. Among these new offerings is inDrive.Ads, an in-app advertising platform. By generating new income streams, inDrive can keep its take rate among the lowest in the industry while supporting long-term sustainability for riders, drivers, and local communities. 

Now live in 20 countries, including the Philippines, inDrive.Ads plans to expand to all global markets within this year. On inDrive.Ads, ads appear across various screens in the funnel and include multiple-dimension banners featuring graphics and animation, with transparent measurement tools built in.

Tomsky said in a statement, “Diversifying our business with a high-margin stream like Ads is an important step for inDrive. This new line gives us more flexibility to fund affordability at scale.”

Sofia Guinto, inDrive Philippines Country Representative, echoed similar sentiments, saying, “inDrive.Ads is our way of championing fairness and accessibility on all facets of our SuperApp. Through this, we can maintain fares that are both affordable for passengers and lucrative for our drivers and create equal opportunities for more people and brands.”

Beyond its global launch of inDrive.Ads, inDrive has also expanded into intercity transportation, courier and grocery delivery, and financial services in other global markets. These new services utilize artificial intelligence and predictive analytics to fix mapping gaps, improve ETA accuracy, anticipate user needs, and personalize solutions. Through these AI-powered offerings, inDrive continues to drive innovation while still giving users the freedom of choice in every ride.

Throughout the rest of 2026, inDrive will continue to update its features and grow its user base, becoming a true mobility superapp. Amid this shift, it ensures that all rollouts will be built around fairness, opportunity, and people’s real needs. For more updates on inDrive’s new offerings available in the Philippines, visit www.inDrive.com or follow @inDrive.ph on social media.

Continue Reading

TECHNOLOGY

Google AI Tools open new frontiers for wildlife conservation in PH, Southeast Asia

2:22 p.m. February 5, 2026


The endangered hog deer was once plentiful throughout South and in Southeast Asia, including India, Pakistan, Burma and Thailand. The species now faces serious decline and a loss in genetic diversity.

As the Philippines continues to battle biodiversity loss, Google has announced a major step forward in using AI to preserve endangered species. Through a partnership with the Vertebrate Genomes Project (VGP), Google is providing advanced AI tools and funding to sequence the genetic codes of threatened animals, a move that holds significant promise for conservation efforts in biodiversity hotspots like the Philippines.

Scientists predict that up to one million species globally face extinction. To combat this, Google is deploying AI technologies—including DeepPolisher, DeepVariant, and DeepConsensus—to make genomic sequencing faster, more accurate, and more affordable.

This process allows researchers to create a “biological instruction manual” for species, vital for designing effective conservation strategies.

Regional Impact for Southeast Asia. The initiative has already successfully sequenced 13 endangered species, several of which are native to the broader Southeast Asian region, highlighting the technology’s relevance to local ecosystems:

● The Elongated Tortoise: A critically endangered reptile native to Southeast Asia, currently the focus of captive breeding and reintroduction efforts.
● The Hog Deer: Once plentiful across South and Southeast Asia, this species now faces serious decline and loss of genetic diversity.
● Eld’s Deer: An endangered deer species indigenous to the region that requires breeding and conservation plan to survive.

Expanding the Safety Net. In addition to the initial species, Google.org has awarded the AI for Science fund to The Rockefeller University to expand this work to 150 additional species. This expansion opens the door for more unique wildlife—potentially including species found in the Philippines—to benefit from genomic preservation.

Continue Reading

TECHNOLOGY

Infinix unveils XPAD Edge, its first 13.2-inch PC-level tablet redefining workplace productivity

12:01 p.m. February 2, 2026

Infinix today announced the launch of its first 13.2-inch ultra-slim productivity tablet, Infinix XPAD Edge. Featuring a 13.2-inch FHD+ (Full High Definition Plus) display, a sleek 6.19 mm metallic body, and a lightweight 588g design, XPAD Edge delivers the ideal balance of mobility and performance.With all-scenario 4G connectivity, the tablet redefines mobile productivity for modern creators, professionals, and learners.

Its detachable keyboard with touchpad transforms it into a true PC-level device, delivering a seamless workplace productivity experience, while combining cutting-edge technology and accessibility to give users greater freedom and efficiency everywhere.

Large Display, Ultra-Slim Design, and Productivity on the Go

Designed for today’s dynamic hybrid workforce, XPAD Edge enables users to work and learn efficiently anywhere. Measuring only 6.19mm thin and weighing 588g, it slips easily into a backpack or briefcase. Its 8000 mAh battery and all-scenario 4G connectivity provide lasting power and reliable access whether in a café, during travel, or at a remote worksite.

Furthermore, the expansive 13.2-inch 3:2 aspect-ratio display mirrors the proportions of a traditional PC screen, offering a broad workspace for documents, presentations, and spreadsheets.

With rich color reproduction and optimized contrast, every detail appears vivid and clear. Certified by TÜV Rheinland for low blue light and flicker-free performance, the XPAD Edge display filters up to 70% of harmful short-wave blue light and addresses the often-overlooked issue of screen flicker—helping to reduce eye fatigue during long working hours.

Inspired by the colors and light of the cosmos, the XPAD Edge is presented in the “Celestial Ink” colorway, refined metallic finish combines deep hues with a matte texture, blending technology with elegance in a minimalist design that suits both professional and personal settings.

PC-Level Experience for Smarter Workflows

Building on its ultra-slim design, XPAD Edge transforms mobile work into a truly PC-level experience. Designed as a versatile productivity hub, it brings together portability and power for efficient hybrid work and learning. Pre-installed WPS Office and an optimized task interface allow users to edit documents, manage files, and collaborate with ease. Whether preparing presentations, reviewing reports, or managing creative projects, XPAD Edge delivers a fast, intuitive, and professional workflow in every environment.

XPAD Edge supports split-screen, Parallel Windows, and multi-task drag-and-drop operations, maximizing the 13.2-inch large display for parallel applications. Within a single interface, users can browse data, take notes, and edit webpages effortlessly. 

For external productivity, XPAD Edge supports Wireless Second Screen for PC*, enabling content mirroring or extension for meetings, design work, or entertainment. Users can also connect keyboards, mice, and other peripherals for a smooth, desktop-like experience that enhances both comfort and control.

In addition, XPAD Edge pairs seamlessly with the X Keyboard 20 to provide a flexible and natural writing experience. The magnetic keyboard and stylus combine precision with comfort, allowing users to take notes, sketch, or edit content with accuracy. Whether working in a café, classroom, or creative studio, XPAD Edge enables users to enjoy the freedom and efficiency of a complete mobile office anywhere.

Continue Reading