#software supply chain
21 stories taggedsoftware supply chain.

SectopRAT Hidden Inside Legitimate Audio Software to Steal Passwords and Take Remote Control
Fortinet's incident responders found a powerful remote-access trojan tucked inside a tampered copy of a real audio program. The malware can grab browser passwords, watch your screen, and hand full control of a Windows PC to criminals.

Chainguard Hits 1 Billion Container Build Manifests: What the Numbers Mean for Software Supply Chain Security
The secure container specialist doubled its output in six months. What's interesting is the machinery behind the number, not the number itself.

AIR Security Raises $50 Million to Build a Firewall for AI Agents
A new startup wants to screen the AI tools companies are rushing to adopt, checking them for hidden malicious instructions and overly broad permissions before they cause harm.

AI Is Finding Software Flaws Faster Than Anyone Can Fix Them. Here's Why Experts Say Don't Panic Yet.
A new report tracked nearly 40,000 software vulnerability reports across a year of real data. The headline number is alarming. The fine print is more reassuring.

Hackers Are Already Breaking Into Software Stores Using a Flaw Disclosed Three Days Ago
A critical security hole in JFrog Artifactory, a platform used by thousands of companies to store and ship software, is being actively exploited just 72 hours after its public disclosure.

Hackers Are Already Exploiting a Critical Flaw in JFrog Artifactory
A severe authentication weakness in a tool used by software teams worldwide was patched on August 28. Within days, attackers had found a way to use it to give themselves full administrator access.

Companies Are Spending More on Cyber 'Attack Drills' to Keep Up with AI-Powered Hackers
New research from Omdia finds 88% of organisations plan to increase spending on offensive security, as AI gives attackers a speed advantage that human-paced testing can no longer match.

CISA: Hackers Are Actively Exploiting a Patched Gitea Flaw That Lets Them Run Malicious Commands
A security hole in Gitea, a widely used code-hosting platform, is being exploited in the wild. A patch has existed since late July, but federal agencies have until August 28 to apply it.

AI Is Writing Your Code Faster Than Your Security Team Can Read It
Coding assistants are flooding repos with open-source packages, and the vulnerability backlog is winning the race.

AI Coding Assistants Are Pulling in Open Source Packages Faster Than Anyone Can Check Them
Developers using AI helpers are importing software libraries at machine speed. Security teams built for human review can't keep up, and dodgy code is slipping through.

Credential-Stealing Worm Spreads Across npm Packages
A worm seeded in a single npm package replicated into hundreds of others on August 4, 2026, with two security firms putting the damage count at different but alarming numbers.

US and allies rewrite the software 'ingredients list' rulebook for 2026
CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

Nvidia Leads 40-Company Coalition to Build Open Security Tools for AI Systems
The Open Secure AI Alliance wants shared, openly inspectable tools to become the standard defence against attacks on artificial intelligence systems, and it is warning regulators that locking down open AI could leave defenders blind.

What Is Really Inside Your Work Apps? Lookout's New Tool Aims to Tell You
A new scanning service from mobile security firm Lookout builds detailed ingredient lists for enterprise apps, exposing hidden vulnerable components before criminals can exploit them.

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months
Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.