#supply chain security
28 stories taggedsupply chain security.

AI Coding Tool Was Quietly Uploading Your Entire Codebase to China
Z.ai's ZCode assistant packaged developers' full project histories by default and sent them to Alibaba Cloud servers. The company has disabled the feature, deleted the stored data, and opened its source code for review.

Hackers Chain Two JFrog Artifactory Bugs to Plant Backdoors on Unpatched Servers
Wiz tracked the attacks from August 15 to September 8. Both flaws were already fixed. Servers that skipped the update paid the price.

UK Government Moves to Cut High-Risk Tech Suppliers Out of Critical Infrastructure
Late additions to a new cybersecurity law would give ministers the power to remove or restrict technology providers judged to pose a national security risk, as attacks on supply chains grow more frequent.

Hackers Are Already Exploiting a Critical Flaw in JFrog Artifactory
A severe authentication weakness in a tool used by software teams worldwide was patched on August 28. Within days, attackers had found a way to use it to give themselves full administrator access.

Defence Contractors Say They Feel Ready for the Pentagon's New Security Rules, But Can't Actually Prove It
Two new surveys find that American defence suppliers are more confident than ever about meeting the Pentagon's cybersecurity standard, while their ability to demonstrate that confidence on paper is getting worse, not better.

Mozilla Accidentally Put a Firefox Signing Key on GitHub. Here's Why You're Probably Fine.
A private key used to authenticate Firefox and Thunderbird downloads was briefly stored in the wrong place. Mozilla has replaced it and found no sign anyone misused it.

Pentagon Suppliers Face a Hard Deadline: Prove Your Cybersecurity or Lose the Contract
A phased federal rule is forcing every company in the US defence supply chain to show, not just promise, that it keeps sensitive government data safe. Here's what's changing and why it matters.

Compliance Alone Won't Protect Your Organisation: Edna Conway on the Real Future of Cyber Risk
A cybersecurity veteran with four decades in the field says ticking regulatory boxes is not the same as being secure. Here is what she means and why it matters.

15 Flaws in TP-Link Kit Put Automatic Network Setup at Risk
Security researchers found 15 vulnerabilities in TP-Link's Omada networking system and warn that the convenient zero-touch setup process millions of organisations rely on could hand criminals the keys to an entire network.

CISA Publishes Open Source Security Playbook for Federal Agencies
The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.

Forgotten DNS Records Could Become a Nation-State Weapon, Researchers Warn
A technique called 'dangling DNS' has lurked in security circles for years. Researchers now say AI could automate it at a scale that threatens governments and the software supply chains millions of organisations depend on.

The FCC Just Banned Chinese Humanoid Robots. Here Is What That Actually Means.
America's telecoms regulator has blocked imports of new Chinese-made humanoid robots and power inverters on national security grounds. China holds roughly 85 percent of the global market for humanoids. The fight over who controls the machines of the future is now very much a trade war.

Infoblox Wants to Find Your Exposed Assets Before Hackers Do
The network security company is entering a crowded market with a twist: using its deep knowledge of the internet's address book to spot weaknesses rivals might miss.

Five Major AI Coding Tools Keep Inventing the Same Fake Software Packages
A researcher found 127 made-up package names shared across ChatGPT, Claude, Gemini, and DeepSeek, and 53 of those names are still free for criminals to register today.

White House Orders Defense Contractors to Chart Every Software Tool and Supplier in Their Supply Chains
A new executive order requires companies that sell to the US military to map their entire software stack and flag any foreign ownership lurking in their supply chains.