Connect with us

TECHNOLOGY

Palo Alto Networks: Poor software supply chain impacts cloud infrastructure

As an example of the prevalence of misconfigurations, Unit 42 researchers analyzed public Terraform modules by number of misconfigurations (left) and types of misconfigurations and their percentages (right). Source: Unit 42 Cloud Threat Report, 2H 2021.

Posted on Nov. 19, 8:48 p.m.

HIGH-PROFILE software supply chain attacks such as SolarWinds and Kaseya have shed a glaring light on the disparity between organizations’ perceptions of security within their cloud infrastructure, and the reality of threats in their supply chains that can impact business catastrophically. 

In the latest Palo Alto Networks’ Unit 42 Cloud Threat Report, 2H 2021, Unit 42 researchers dive deep into the full scope of supply chain attacks in the cloud and explain often misunderstood details about how they occur.

They also provide actionable recommendations any organization can adopt immediately to begin protecting their software supply chains in the cloud. 

The Unit 42 team analyzed data from a variety of public data sources around the world in order to draw conclusions about the growing threats organizations face today in their software supply chains. 

Their findings indicate that many organizations may have a false sense of security in the cloud and in reality are vastly unprepared for the threats they face. 

In addition to analyzing data, Unit 42 researchers were commissioned by a large SaaS provider (a customer of Palo Alto Networks) to run a red team exercise against their software development environment. In just three days, a single Unit 42 researcher discovered critical software development flaws that left the customer vulnerable to an attack similar to that of SolarWinds and Kaseya.

Key Findings

Poor Supply Chain Hygiene Impacts Cloud Infrastructure

The large SaaS provider detailed in the red team exercise has what many would consider a mature cloud security posture. However, during the exercise, Unit 42 researchers were able to leverage misconfigurations in the organization’s software development environment, such as the presence of hardcoded IAM key pairs, that would have allowed them to control all development processes and thus conduct a successful supply chain attack.Further, Unit 42 researchers found that 21% of the security scans they ran against the customer’s development environment resulted in misconfigurations or vulnerabilities, highlighting how process gaps and critical security flaws leave an organization exposed and susceptible to a business-halting attack.

Third-Party Code Is Rarely Trustworthy

In their research, Unit 42 researchers discovered that 63% of third-party code templates used in building cloud infrastructure contained insecure configurations, and 96% of third-party container applications deployed in cloud infrastructure contain known vulnerabilities. With this level of risk, an attacker could easily gain access to sensitive data in the cloud and even take control of an organization’s software development environment. Based on the Unit 42 team’s findings, it’s evident that unvetted code can quickly snowball into a security breach, especially as infrastructure flaws can directly impact thousands of cloud workloads. For that reason, it is critical that organizations understand where their code is coming from since third-party code can come from anyone, including an Advanced Persistent Threat (APT).

Conclusion: Organizations Need to Shift Security Left

Teams continue to neglect DevOps security, due in part to lack of attention to supply chain threats. Cloud native applications have a long chain of dependencies, and those links have relationships of their own. DevOps and Security teams need to gain visibility into the bill of materials in every cloud workload in order to evaluate risk at every stage of the dependency chain and establish guardrails.

TECHNOLOGY

AI can do that?! 5 ways AI is changing the game for communicators

12:30 p.m. March 8, 2025

Artificial Intelligence (AI) is undeniably here, transforming how communication professionals create content, engage audiences, and predict trends.

But while AI can do a lot, it’s not here to replace human creativity, strategy, and judgment. The real advantage lies in knowing how to use AI as a tool to work smarter and more efficiently.

Whether you’re in PR, marketing, media, or even a student, here are practical ways how AI can enhance your output and make you more effective.

1. Next-Level Personalization

A social media team for a fashion brand uses AI to analyze customer data and segment audiences based on their style preferences. The result? Hyper-personalized email campaigns that suggest products each customer is actually interested in.

2. Real-Time Brand Sentiment Tracking

A crisis communication team at a telecom company notices a sudden spike in negative tweets about a network outage. Thanks to AI-powered sentiment analysis, they react in minutes — crafting a strategic response before things further escalate.

3. Trend Prediction Like a Pro

A political campaign team taps AI to analyze past election data and social media conversations. They predict the key issues voters will care about and fine-tune their messaging before the conversation even starts.

4. AI Ethics 101: Sticking to Facts

A news agency integrates AI-driven fact-checking tools to ensure their reports stay credible and unbiased. They also train their team to detect AI-generated misinformation—because integrity still matters.

5. Instant VO with Zero Studio Time

A content creator needs a last-minute voiceover for a campaign video but has no time for a studio session. AI-generated voiceovers save the day—delivering pro-level narration from the comforts of their own home.

These are just some of the ways AI is transforming the way we communicate, market, and engage with audiences. As AI continues to evolve, everyone needs to upgrade their skills—learning how to adapt, think critically, and integrate AI tools strategically to stay ahead in an increasingly tech-driven world.

If you want to future-proof your skills, don’t miss the AI Centre of Excellence (ACE) Workshop: Power of AI for Communications & Beyond, led by AI expert and India’s Director and CEO of the School of Communications & Reputation, Hemant Gaule.

Happening on March 21, 2025, 1:00 to 5:00 PM, at the Holiday Inn & Suites Makati, this workshop will give you valuable insights into leveraging AI tools to boost efficiency, engagement, and results.

Limited slots available — secure yours now at www.centreofexcellence.ai.

Continue Reading

TECHNOLOGY

Say hello to Whisk, Google’s innovative answer to generative AI image creation

1:12 p.m. February 20, 2025

Generative AI opens up a world of creative possibilities with its ability to make unique content. Following the success of Google’s AI tools, it’s taking another significant step with Whisk, the newest experiment that explores the capabilities of gen AI.

Whisk is a fun and engaging tool that makes AI image generation more accessible, especially to those without prior AI knowledge. Instead of typing out long, detailed text prompts, it allows people to use image prompts. They simply drag images and start creating.

Generative AI utilizes deep-learning models to make high-quality content based on existing data. Sometimes, certain design elements get lost in text prompts. But with Whisk, anyone can easily customize how the image will come out. It allows specific image inputs for the main subject, the scene, and preferred art styles.

Behind the scenes, the Gemini model automatically writes a detailed caption of chosen images. It then feeds those descriptions into Google’s latest image generation model, Imagen 3. This process captures the subject’s essence, and doesn’t create an exact replica. This further allows people to remix their subjects, scenes, and styles in novel ways to create something that is uniquely theirs, from character concepts to enamel pin designs.

It’s also important to highlight that Whisk extracts only a few key characters from images, so generated content may differ from one’s expectations. Fortunately, it allows users to view and edit underlying prompts at any time to get the output they want.

Play with Whisk here: https://labs.google/fx/tools/whisk.

Continue Reading

TECHNOLOGY

Love begins at home with Beko

5:22 p.m. February 17, 2025

As we finally embrace the love month, the pressure to find the perfect gift can often feel overwhelming. However, there’s no need to break the bank just to express your feelings. After all, it’s the thought that counts!

This love month, create lasting memories in the place you cherish most—your home. Beko, Europe’s number 1 home appliance brand, is here to help you make the perfect Valentine’s plan through meaningful, practical gifts that enhance everyday life.

Show your love in a cup

There’s nothing quite like a warm cup of coffee in the morning to express love. When it’s made by someone special, it means even more. Start your day with a delightful breakfast by pairing your coffee with a hearty meal. Experiment with different coffee blends and recipes for future breakfast dates!

Feel like a barista at home with the Beko espresso machine. The Beko CaffeExperto® Espresso Machine features an integrated milk frother, allowing you to create delicious cappuccinos and lattes right at home. Its user-friendly touchscreen interface lets you make coffee with just a tap, while the easy-to-clean design simplifies maintenance.

Acts of Service

Sometimes, it’s the simplest acts that have the biggest impact in showing how much you care, such as helping your loved ones with household tasks to create a more harmonious home. Lend a hand by volunteering to clean surfaces, wash the dishes, or do the laundry. Your loved ones will truly appreciate the effort!

Make laundry easier with Beko’s line of washers and dryers. These powerful appliances provide the gentle care your clothes need. One of Beko’s top washer-dryers has an Xpress Super Short 14-Minute Program that allows you to wash up to 2 kg of laundry in just 14 minutes. While 2 kg might not sound like a lot, it’s enough to wash around 20 T-shirts! That means more quality bonding time with your loved ones.

Cook Up Some Romance

Cooking is a way to someone’s heart, especially when it’s made with love. Instead of waiting in long reservation lines at a restaurant, consider having a simple yet intimate dinner date at home. Elevate the experience by setting up the table beautifully and creating a personalized menu that features your loved one’s favorite dishes.

Unleash your cooking prowess in the kitchen with Beko refrigerators featuring the innovative NutriFreeze technology. Imagine preparing for steak night or dishes with delicate fish—now you can keep your meats fresh, without deep freezing!

This unique feature freezes fresh foods like meat, shrimp, and fish at a precise temperature of -3°C, which helps to keep the natural texture and taste intact while slowing down bacterial growth. With NutriFreeze, you can reduce nutrient loss and extend the shelf life of your meats, making it easier to store food and enjoy restaurant-quality meals at home.

This Valentine’s season, show your loved ones how much they mean to you with Beko’s high-quality European appliances. Transform your home into a more love-filled space. Visit your nearest leading appliance store, or shop online at Beko Philippines’ official stores on Lazada, Shopee, and TikTok Shop.

For more details, visit our official website at www.beko.com/ph-en and connect with us on Facebook, Instagram, and TikTok at @bekoph.

Continue Reading