#SBOM
12 stories taggedSBOM.

CISA's Updated Software Ingredient List Rules Change What Knowing Your Code Actually Means
The US government just raised the bar on software transparency. The harder problem is that no single inventory was ever enough to answer the question that matters most: what can your software actually do?

The EU's New Cyber Security Law Gives Manufacturers 24 Hours to Report Flaws. Almost No One Is Ready.
The Cyber Resilience Act, which took effect in September, requires companies to report actively exploited vulnerabilities within one day. Security experts say the clock will break every manual process most vendors currently rely on.

Chainguard Hits 1 Billion Container Build Manifests: What the Numbers Mean for Software Supply Chain Security
The secure container specialist doubled its output in six months. What's interesting is the machinery behind the number, not the number itself.

The EU's New 24-Hour Bug Reporting Rule Starts September 11. Most Vendors Aren't Ready.
A new European law forces software makers to disclose actively exploited flaws within a day. The hard part isn't the paperwork, it's knowing what you shipped.

The Race to Answer 'Are We Exposed?' Is Getting Harder
A new CVE drops and the clock starts. Security teams still hop between six tools to find out if it matters. AI is making that lag more dangerous.

CISA Publishes Open Source Security Playbook for Federal Agencies
The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.

US and allies rewrite the software 'ingredients list' rulebook for 2026
CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

What Is Really Inside Your Work Apps? Lookout's New Tool Aims to Tell You
A new scanning service from mobile security firm Lookout builds detailed ingredient lists for enterprise apps, exposing hidden vulnerable components before criminals can exploit them.

White House Orders Defense Contractors to Chart Every Software Tool and Supplier in Their Supply Chains
A new executive order requires companies that sell to the US military to map their entire software stack and flag any foreign ownership lurking in their supply chains.

When AI writes your code, your supply chain just got a new stranger in it
For years, defenders worried about which open-source parts sat inside their software. Now an AI assistant is quietly adding parts of its own, and nobody is quite sure who owns the risk.

The Software Safety Label Problem: Why What Companies Ship Often Doesn't Match What They Report
A growing body of regulation now requires software makers to list every component inside their products. A Toronto-based firm says most of those lists are wrong before the ink dries, and regulators are starting to agree.

FFmpeg Vulnerability 'PixelSmash' Threatens Media Applications
A critical flaw in FFmpeg's MagicYUV decoder reveals the fragility of software supply chains.