Tag

#SBOM

12 stories taggedSBOM.

Illustration for the story: CISA's Updated Software Ingredient List Rules Change What Knowing Your Code Actually Means
Policy & Regulation

CISA's Updated Software Ingredient List Rules Change What Knowing Your Code Actually Means

The US government just raised the bar on software transparency. The harder problem is that no single inventory was ever enough to answer the question that matters most: what can your software actually do?

4 min read
Illustration: a large industrial server room at night
Policy & Regulation

The EU's New Cyber Security Law Gives Manufacturers 24 Hours to Report Flaws. Almost No One Is Ready.

The Cyber Resilience Act, which took effect in September, requires companies to report actively exploited vulnerabilities within one day. Security experts say the clock will break every manual process most vendors currently rely on.

4 min read
A software supply chain security dashboard displaying container build manifests flowing through secure verification checkpoints, with metrics showing exponentia
Cloud Security

Chainguard Hits 1 Billion Container Build Manifests: What the Numbers Mean for Software Supply Chain Security

The secure container specialist doubled its output in six months. What's interesting is the machinery behind the number, not the number itself.

4 min read
A calendar showing September 11 highlighted in red with notification badges, surrounded by software vendor communication interfaces and vulnerability disclosure
Policy & Regulation

The EU's New 24-Hour Bug Reporting Rule Starts September 11. Most Vendors Aren't Ready.

A new European law forces software makers to disclose actively exploited flaws within a day. The hard part isn't the paperwork, it's knowing what you shipped.

4 min read
A security operations center with six different security dashboards and tools displayed across multiple monitors, with a CVE notification appearing on one scree
Vulnerabilities

The Race to Answer 'Are We Exposed?' Is Getting Harder

A new CVE drops and the clock starts. Security teams still hop between six tools to find out if it matters. AI is making that lag more dangerous.

3 min read
A government office workspace with multiple screens displaying open source code repositories and security vetting checklists, with the C4 trust framework diagra
Policy & Regulation

CISA Publishes Open Source Security Playbook for Federal Agencies

The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.

4 min read
Government and international security agency emblems arranged around a software blueprint document with detailed ingredient lists and components clearly labeled
Policy & Regulation

US and allies rewrite the software 'ingredients list' rulebook for 2026

CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

4 min read
Illustration: A mobile app interface displayed on a smartphone with an X-ray-
Vulnerabilities

What Is Really Inside Your Work Apps? Lookout's New Tool Aims to Tell You

A new scanning service from mobile security firm Lookout builds detailed ingredient lists for enterprise apps, exposing hidden vulnerable components before criminals can exploit them.

3 min read
A defense contractor's operations center with multiple computer workstations displaying interconnected software architecture diagrams and supply chain flowchart
Policy & Regulation

White House Orders Defense Contractors to Chart Every Software Tool and Supplier in Their Supply Chains

A new executive order requires companies that sell to the US military to map their entire software stack and flag any foreign ownership lurking in their supply chains.

3 min read
Illustration: a modern developer's desk at dusk, two monitors glowing with abstract lines of code
AI Security

When AI writes your code, your supply chain just got a new stranger in it

For years, defenders worried about which open-source parts sat inside their software. Now an AI assistant is quietly adding parts of its own, and nobody is quite sure who owns the risk.

4 min read
Illustration: a circuit board with dense rows of chips and soldered components
Policy & Regulation

The Software Safety Label Problem: Why What Companies Ship Often Doesn't Match What They Report

A growing body of regulation now requires software makers to list every component inside their products. A Toronto-based firm says most of those lists are wrong before the ink dries, and regulators are starting to agree.

3 min read
Illustration: A digital representation of software code with the FFmpeg logo subtly integrated into a background of data
Vulnerabilities

FFmpeg Vulnerability 'PixelSmash' Threatens Media Applications

A critical flaw in FFmpeg's MagicYUV decoder reveals the fragility of software supply chains.

3 min read
© 2026 Threat Vectr