Tag

#supply chain security

28 stories taggedsupply chain security.

Illustration: a developer's desk at night
AI Security

AI Coding Tool Was Quietly Uploading Your Entire Codebase to China

Z.ai's ZCode assistant packaged developers' full project histories by default and sent them to Alibaba Cloud servers. The company has disabled the feature, deleted the stored data, and opened its source code for review.

4 min read
A timeline visualization from mid-August to early September showing two vulnerability chains being exploited, unpatched server icons turning red as backdoors ar
Vulnerabilities

Hackers Chain Two JFrog Artifactory Bugs to Plant Backdoors on Unpatched Servers

Wiz tracked the attacks from August 15 to September 8. Both flaws were already fixed. Servers that skipped the update paid the price.

3 min read
A UK government policy document or legislative chamber setting with cybersecurity infrastructure and technology supply chain diagrams displayed on screens behin
Policy & Regulation

UK Government Moves to Cut High-Risk Tech Suppliers Out of Critical Infrastructure

Late additions to a new cybersecurity law would give ministers the power to remove or restrict technology providers judged to pose a national security risk, as attacks on supply chains grow more frequent.

3 min read
A software deployment dashboard displaying administrator access controls being progressively elevated, authentication logs showing unauthorized privilege escala
Vulnerabilities

Hackers Are Already Exploiting a Critical Flaw in JFrog Artifactory

A severe authentication weakness in a tool used by software teams worldwide was patched on August 28. Within days, attackers had found a way to use it to give themselves full administrator access.

3 min read
Defense contractor offices with confident executives presenting security documentation that doesn't fully demonstrate compliance with Pentagon security standard
Policy & Regulation

Defence Contractors Say They Feel Ready for the Pentagon's New Security Rules, But Can't Actually Prove It

Two new surveys find that American defence suppliers are more confident than ever about meeting the Pentagon's cybersecurity standard, while their ability to demonstrate that confidence on paper is getting worse, not better.

4 min read
A GitHub repository page displayed on a monitor, a private key snippet visible in code history with a glowing red circle and X overlay, security warning banners
Identity & Access

Mozilla Accidentally Put a Firefox Signing Key on GitHub. Here's Why You're Probably Fine.

A private key used to authenticate Firefox and Thunderbird downloads was briefly stored in the wrong place. Mozilla has replaced it and found no sign anyone misused it.

3 min read
A large office building or industrial facility with security checkpoints and credential verification stations at the entrance, with government vehicles and offi
Policy & Regulation

Pentagon Suppliers Face a Hard Deadline: Prove Your Cybersecurity or Lose the Contract

A phased federal rule is forcing every company in the US defence supply chain to show, not just promise, that it keeps sensitive government data safe. Here's what's changing and why it matters.

4 min read
A conference or seminar setting with an experienced speaker at a podium, with compliance checkboxes and regulatory documents visible on large displays behind th
Policy & Regulation

Compliance Alone Won't Protect Your Organisation: Edna Conway on the Real Future of Cyber Risk

A cybersecurity veteran with four decades in the field says ticking regulatory boxes is not the same as being secure. Here is what she means and why it matters.

3 min read
A network administrator's control panel showing a TP-Link Omada system interface with automatic setup wizards active, overlaid with vulnerability warning icons
Vulnerabilities

15 Flaws in TP-Link Kit Put Automatic Network Setup at Risk

Security researchers found 15 vulnerabilities in TP-Link's Omada networking system and warn that the convenient zero-touch setup process millions of organisations rely on could hand criminals the keys to an entire network.

4 min read
A government office workspace with multiple screens displaying open source code repositories and security vetting checklists, with the C4 trust framework diagra
Policy & Regulation

CISA Publishes Open Source Security Playbook for Federal Agencies

The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.

4 min read
A global DNS infrastructure map with dangling DNS records highlighted as vulnerabilities, showing how automated systems could weaponize abandoned records across
Vulnerabilities

Forgotten DNS Records Could Become a Nation-State Weapon, Researchers Warn

A technique called 'dangling DNS' has lurked in security circles for years. Researchers now say AI could automate it at a scale that threatens governments and the software supply chains millions of organisations depend on.

3 min read
A humanoid robot at a US border checkpoint with an official ban notice, representing trade restrictions, while Chinese manufacturing facilities are visible in b
Policy & Regulation

The FCC Just Banned Chinese Humanoid Robots. Here Is What That Actually Means.

America's telecoms regulator has blocked imports of new Chinese-made humanoid robots and power inverters on national security grounds. China holds roughly 85 percent of the global market for humanoids. The fight over who controls the machines of the future is now very much a trade war.

3 min read
A network operations center with overlapping domain name system visualizations displayed across multiple screens, with highlighted sections showing exposed asse
Cloud Security

Infoblox Wants to Find Your Exposed Assets Before Hackers Do

The network security company is entering a crowded market with a twist: using its deep knowledge of the internet's address book to spot weaknesses rivals might miss.

3 min read
A split-screen comparison showing identical package names being suggested by different AI chatbot interfaces, with a criminal's hand holding a domain registrati
AI Security

Five Major AI Coding Tools Keep Inventing the Same Fake Software Packages

A researcher found 127 made-up package names shared across ChatGPT, Claude, Gemini, and DeepSeek, and 53 of those names are still free for criminals to register today.

3 min read
A defense contractor's operations center with multiple computer workstations displaying interconnected software architecture diagrams and supply chain flowchart
Policy & Regulation

White House Orders Defense Contractors to Chart Every Software Tool and Supplier in Their Supply Chains

A new executive order requires companies that sell to the US military to map their entire software stack and flag any foreign ownership lurking in their supply chains.

3 min read
© 2026 Threat Vectr