Tag

#software supply chain

21 stories taggedsoftware supply chain · page 2 of 2.

Illustration: a glowing computer monitor in a dimly lit office showing dense lines of green and white code
AI Security

The Hidden Cost of AI Coding Tools: Security Gaps, Leaked Secrets, and a Bill That Keeps Growing

New research shows AI coding assistants leak sensitive credentials at twice the normal rate, routinely produce flawed code, and may cost more than a developer's salary within three years.

4 min read
A dimly lit server room at night, rows of glowing blue and green indicator lights on rack-mounted hardware stretching into the distance, empty operator chairs i
AI Security

Your AI Coding Bots Are Running Unsupervised and Nobody Knows What They Did Last Night

AI agents inside software development teams can write, test, and deploy code on their own, often with no human checking what they did. Most companies have no way to answer a simple question: who authorised that change?

4 min read
Illustration: a developer workstation at night, two nearly identical strings of hexadecimal characters glowing softly
Cloud Security

GitHub's Green 'Verified' Badge Can Lie: Signed Commits Cloned Without the Key

Researchers show anyone can produce a second signed commit that matches the author, date and files of a real one, keeping GitHub's Verified stamp while carrying a different hash than developers recorded.

4 min read
Illustration: a modern developer's desk at dusk, two monitors glowing with abstract lines of code
AI Security

When AI writes your code, your supply chain just got a new stranger in it

For years, defenders worried about which open-source parts sat inside their software. Now an AI assistant is quietly adding parts of its own, and nobody is quite sure who owns the risk.

4 min read
Illustration: a circuit board with dense rows of chips and soldered components
Policy & Regulation

The Software Safety Label Problem: Why What Companies Ship Often Doesn't Match What They Report

A growing body of regulation now requires software makers to list every component inside their products. A Toronto-based firm says most of those lists are wrong before the ink dries, and regulators are starting to agree.

3 min read
Illustration: A vast dark server room with rows of illuminated rack hardware receding into the distance
Cloud Security

AWS Continuum Wants to Close the Gap Between AI-Generated Code and AI-Fixed Vulnerabilities

Amazon's new agentic security service promises continuous discovery, triage, and remediation. In practice, it's a bet that the same AI acceleration creating your backlog can also drain it.

3 min read
© 2026 Threat Vectr