Tag

#SBOM

9 stories taggedSBOM.

Photoreal editorial image of a sleek modern server rack glowing with blue indicator lights, partially connected by old beige Ethernet cables and a vintage patch
Policy & Regulation

CISA Rewrites the Rules for Software Ingredients Lists. Critics Say It's Not Enough.

A 17-nation coalition has updated the global standard for tracking what goes into software. The framework is broader than its 2021 predecessor, but security experts argue it sidesteps the hardest questions.

4 min read
A long polished conference table in a modern governmental chamber, empty high-backed chairs arranged formally on both sides, soft overhead lighting casting clea
Policy & Regulation

CISA Publishes Open Source Security Playbook for Federal Agencies

The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.

4 min read
AI analyzing network data
Policy & Regulation

US and allies rewrite the software 'ingredients list' rulebook for 2026

CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

4 min read
Close-up overhead view of a modern Android smartphone lying face-up on a dark matte desk, its screen glowing with a soft blue-white light, surrounded by faint a
Vulnerabilities

What Is Really Inside Your Work Apps? Lookout's New Tool Aims to Tell You

A new scanning service from mobile security firm Lookout builds detailed ingredient lists for enterprise apps, exposing hidden vulnerable components before criminals can exploit them.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Policy & Regulation

White House Orders Defense Contractors to Chart Every Software Tool and Supplier in Their Supply Chains

A new executive order requires companies that sell to the US military to map their entire software stack and flag any foreign ownership lurking in their supply chains.

3 min read
Full-frame photoreal editorial image of a modern developer's desk at dusk, two monitors glowing with abstract lines of code, one screen subtly tinted a cool blu
AI Security

When AI writes your code, your supply chain just got a new stranger in it

For years, defenders worried about which open-source parts sat inside their software. Now an AI assistant is quietly adding parts of its own, and nobody is quite sure who owns the risk.

4 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Policy & Regulation

The Software Safety Label Problem: Why What Companies Ship Often Doesn't Match What They Report

A growing body of regulation now requires software makers to list every component inside their products. A Toronto-based firm says most of those lists are wrong before the ink dries, and regulators are starting to agree.

3 min read
Vulnerabilities

FFmpeg Vulnerability 'PixelSmash' Threatens Media Applications

A critical flaw in FFmpeg's MagicYUV decoder reveals the fragility of software supply chains.

2 min read
Cloud Security

IBM and Red Hat Pledge $5 Billion to Lock Down Open Source Supply Chains via Project Lightwell

The initiative targets a deceptively hard problem: patching vulnerabilities in open source dependencies without breaking production workloads that millions of systems depend on.

2 min read
© 2026 Threat Vectr