Tag

#software supply chain

16 stories taggedsoftware supply chain.

Full-frame photoreal editorial image of a modern developer's desk at dusk, two monitors glowing with abstract lines of code, one screen subtly tinted a cool blu
AI Security

AI Is Writing Your Code Faster Than Your Security Team Can Read It

Coding assistants are flooding repos with open-source packages, and the vulnerability backlog is winning the race.

4 min read
Macro close-up of a glowing blue search bar interface on a dark enterprise dashboard screen, with faint streams of data characters flowing outward from the inpu
AI Security

AI Coding Assistants Are Pulling in Open Source Packages Faster Than Anyone Can Check Them

Developers using AI helpers are importing software libraries at machine speed. Security teams built for human review can't keep up, and dodgy code is slipping through.

4 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Vulnerabilities

Credential-Stealing Worm Spreads Across npm Packages

A worm targeting npm packages has affected hundreds of software components, raising security concerns for developers.

2 min read
Photoreal editorial image of a sleek modern server rack glowing with blue indicator lights, partially connected by old beige Ethernet cables and a vintage patch
Policy & Regulation

CISA Rewrites the Rules for Software Ingredients Lists. Critics Say It's Not Enough.

A 17-nation coalition has updated the global standard for tracking what goes into software. The framework is broader than its 2021 predecessor, but security experts argue it sidesteps the hardest questions.

4 min read
AI analyzing network data
Policy & Regulation

US and allies rewrite the software 'ingredients list' rulebook for 2026

CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

4 min read
Full-frame photoreal editorial image of a modern developer's desk at dusk, two monitors glowing with abstract lines of code, one screen subtly tinted a cool blu
AI Security

Nvidia Leads 40-Company Coalition to Build Open Security Tools for AI Systems

The Open Secure AI Alliance wants shared, openly inspectable tools to become the standard defence against attacks on artificial intelligence systems, and it is warning regulators that locking down open AI could leave defenders blind.

4 min read
Close-up overhead view of a modern Android smartphone lying face-up on a dark matte desk, its screen glowing with a soft blue-white light, surrounded by faint a
Vulnerabilities

What Is Really Inside Your Work Apps? Lookout's New Tool Aims to Tell You

A new scanning service from mobile security firm Lookout builds detailed ingredient lists for enterprise apps, exposing hidden vulnerable components before criminals can exploit them.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Threat Intelligence

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months

Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

3 min read
Photoreal news-editorial 16:9 image of a glowing computer monitor in a dimly lit office showing dense lines of green and white code, with a physical padlock sit
AI Security

The Hidden Cost of AI Coding Tools: Security Gaps, Leaked Secrets, and a Bill That Keeps Growing

Businesses are rushing to adopt AI coding assistants, but new research shows the tools leak sensitive credentials at twice the normal rate, routinely produce flawed code, and may cost more than a developer's salary within three years.

3 min read
A dimly lit server room at night, rows of glowing blue and green indicator lights on rack-mounted hardware stretching into the distance, empty operator chairs i
AI Security

Your AI Coding Bots Are Running Unsupervised and Nobody Knows What They Did Last Night

AI agents inside software development teams can write, test, and deploy code on their own, often with no human checking what they did. Most companies have no way to answer a simple question: who authorised that change?

4 min read
Full-frame photoreal editorial image of a developer workstation at night, two nearly identical strings of hexadecimal characters glowing softly on a dark monito
Cloud Security

GitHub's Green 'Verified' Badge Can Lie: Signed Commits Cloned Without the Key

Researchers show anyone can produce a second signed commit that matches the author, date and files of a real one, keeping GitHub's Verified stamp while changing the unique fingerprint developers rely on.

4 min read
Full-frame photoreal editorial image of a modern developer's desk at dusk, two monitors glowing with abstract lines of code, one screen subtly tinted a cool blu
AI Security

When AI writes your code, your supply chain just got a new stranger in it

For years, defenders worried about which open-source parts sat inside their software. Now an AI assistant is quietly adding parts of its own, and nobody is quite sure who owns the risk.

4 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Policy & Regulation

The Software Safety Label Problem: Why What Companies Ship Often Doesn't Match What They Report

A growing body of regulation now requires software makers to list every component inside their products. A Toronto-based firm says most of those lists are wrong before the ink dries, and regulators are starting to agree.

3 min read
Cloud Security

AWS Continuum Wants to Close the Gap Between AI-Generated Code and AI-Fixed Vulnerabilities

Amazon's new agentic security service promises continuous discovery, triage, and remediation. In practice, it's a bet that the same AI acceleration creating your backlog can also drain it.

3 min read
Threat Intelligence

Three Stories You Probably Missed: Trump Mobile Leak, FIFA Phishing, and CISA's Supply Chain Cleanup

A customer data exposure, a tournament-themed phishing campaign, and a federal agency scrambling to respond to upstream compromise — a busy week for the incidents no one headlined.

2 min read
© 2026 Threat Vectr