Tag

#software supply chain

21 stories taggedsoftware supply chain.

Illustration for the story: SectopRAT Hidden Inside Legitimate Audio Software to Steal Passwords and Take Remote Control
Threat Intelligence

SectopRAT Hidden Inside Legitimate Audio Software to Steal Passwords and Take Remote Control

Fortinet's incident responders found a powerful remote-access trojan tucked inside a tampered copy of a real audio program. The malware can grab browser passwords, watch your screen, and hand full control of a Windows PC to criminals.

4 min read
A software supply chain security dashboard displaying container build manifests flowing through secure verification checkpoints, with metrics showing exponentia
Cloud Security

Chainguard Hits 1 Billion Container Build Manifests: What the Numbers Mean for Software Supply Chain Security

The secure container specialist doubled its output in six months. What's interesting is the machinery behind the number, not the number itself.

4 min read
A network security operations center with multiple analysts monitoring AI agent activities on wraparound displays, permission trees and malicious instruction de
AI Security

AIR Security Raises $50 Million to Build a Firewall for AI Agents

A new startup wants to screen the AI tools companies are rushing to adopt, checking them for hidden malicious instructions and overly broad permissions before they cause harm.

3 min read
A software developer's workstation with multiple monitors displaying code repositories and vulnerability scanning tools, with notification alerts cascading acro
AI Security

AI Is Finding Software Flaws Faster Than Anyone Can Fix Them. Here's Why Experts Say Don't Panic Yet.

A new report tracked nearly 40,000 software vulnerability reports across a year of real data. The headline number is alarming. The fine print is more reassuring.

4 min read
A software repository server facility with glowing rack-mounted hardware and network cables, while a security alert banner scrolls across a monitoring station's
Vulnerabilities

Hackers Are Already Breaking Into Software Stores Using a Flaw Disclosed Three Days Ago

A critical security hole in JFrog Artifactory, a platform used by thousands of companies to store and ship software, is being actively exploited just 72 hours after its public disclosure.

4 min read
A software deployment dashboard displaying administrator access controls being progressively elevated, authentication logs showing unauthorized privilege escala
Vulnerabilities

Hackers Are Already Exploiting a Critical Flaw in JFrog Artifactory

A severe authentication weakness in a tool used by software teams worldwide was patched on August 28. Within days, attackers had found a way to use it to give themselves full administrator access.

3 min read
A corporate security team running a simulated attack drill in a control room, multiple screens showing attack scenarios, AI-powered threat patterns, and rapid r
AI Security

Companies Are Spending More on Cyber 'Attack Drills' to Keep Up with AI-Powered Hackers

New research from Omdia finds 88% of organisations plan to increase spending on offensive security, as AI gives attackers a speed advantage that human-paced testing can no longer match.

4 min read
A code repository interface showing file directories and command execution logs, with a highlighted patch notice dated late July and a federal agency seal in th
Vulnerabilities

CISA: Hackers Are Actively Exploiting a Patched Gitea Flaw That Lets Them Run Malicious Commands

A security hole in Gitea, a widely used code-hosting platform, is being exploited in the wild. A patch has existed since late July, but federal agencies have until August 28 to apply it.

3 min read
A code repository dashboard on a monitor showing rapidly accumulating open-source packages and dependencies, with a growing vulnerability count meter displayed
AI Security

AI Is Writing Your Code Faster Than Your Security Team Can Read It

Coding assistants are flooding repos with open-source packages, and the vulnerability backlog is winning the race.

4 min read
A software development workspace with AI coding assistant running on one monitor displaying auto-imported open source packages at high speed, a security team's
AI Security

AI Coding Assistants Are Pulling in Open Source Packages Faster Than Anyone Can Check Them

Developers using AI helpers are importing software libraries at machine speed. Security teams built for human review can't keep up, and dodgy code is slipping through.

4 min read
A developer's terminal window showing npm package listings with multiple entries highlighted in red, illustrating how a single compromised package spawned infec
Vulnerabilities

Credential-Stealing Worm Spreads Across npm Packages

A worm seeded in a single npm package replicated into hundreds of others on August 4, 2026, with two security firms putting the damage count at different but alarming numbers.

2 min read
Government and international security agency emblems arranged around a software blueprint document with detailed ingredient lists and components clearly labeled
Policy & Regulation

US and allies rewrite the software 'ingredients list' rulebook for 2026

CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

4 min read
A conference table surrounded by corporate logos and security tool interfaces displayed on multiple monitors, with interconnected lines showing shared defense f
AI Security

Nvidia Leads 40-Company Coalition to Build Open Security Tools for AI Systems

The Open Secure AI Alliance wants shared, openly inspectable tools to become the standard defence against attacks on artificial intelligence systems, and it is warning regulators that locking down open AI could leave defenders blind.

4 min read
Illustration: A mobile app interface displayed on a smartphone with an X-ray-
Vulnerabilities

What Is Really Inside Your Work Apps? Lookout's New Tool Aims to Tell You

A new scanning service from mobile security firm Lookout builds detailed ingredient lists for enterprise apps, exposing hidden vulnerable components before criminals can exploit them.

3 min read
Illustration: A vast dark server room with long rows of glowing rack servers receding into the distance
Threat Intelligence

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months

Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

3 min read
© 2026 Threat Vectr