Tag

#supply chain security

28 stories taggedsupply chain security · page 2 of 2.

Illustration: a matte-grey autonomous military ground vehicle parked on a concrete airfield at dusk, sensor array on top
Policy & Regulation

Militaries Want Autonomous Weapons Fast. The Data Pipes Behind Them Are the Weak Link.

Defence ministries are pouring money into drones and robots that can think for themselves. The information systems feeding those machines haven't caught up.

4 min read
A London office conference room where professionals review security audit reports displayed on a large wall-mounted screen, collaborative workspace suggesting n
Cloud Security

Risk Ledger Raises £24 Million to Expand Its Supply Chain Security Network

The London firm wants more organisations checking each other's security hygiene in one shared space. Now it has the money to push into the US and build AI review tools.

3 min read
A warehouse floor with a humanoid robot performing tasks among human workers, with visible electronic joints and cables exposed, surrounded by question marks an
AI Security

Give an AI a Body and You Give It an Attack Surface

Warehouses and factories are buying humanoid robots before security teams have a single audit standard to work from. Here's what that means for the people on the floor.

4 min read
Illustration: a large corporate server room at night
Opinion

Your Vendors Are a Risk You Cannot Ignore. Here Is How Boards Should Own It.

Most companies review their suppliers and tick the boxes. Far fewer can say how much financial damage a vendor failure would actually cost them. That gap is the problem.

3 min read
Illustration: A glowing laptop screen in a dimly lit office showing abstract streams of green code mixed with faint red
AI Security

HalluSquatting: How AI Hallucinations Are Being Turned Into a Doorway for Malware

Security researchers have found a way to turn a known quirk of AI chatbots into a method for delivering malicious software directly to developers' computers, without hacking the AI itself.

3 min read
Illustration: On the screen, a software approval dialog box glows in blue and white
AI Security

GhostApproval: Six AI Coding Tools Were Tricking Developers Into Approving Dangerous Actions

A new attack pattern shows that the 'human approval' step built into AI coding assistants can be fed false information by the very tool it is supposed to oversee.

4 min read
Illustration: a darkened developer workstation with a large monitor showing abstract cascading package dependency graphs
Policy & Regulation

npm 12 Turns Off Auto-Run Install Scripts to Blunt Supply Chain Attacks

GitHub's package manager for JavaScript now ships with a safer default, and it retires a token type that let developers skip two-factor login.

3 min read
Illustration: a glowing server rack inside a dark data centre
Threat Intelligence

Criminals Are Using GitHub's Own Public Tools to Map Your Company Before They Strike

Researchers at Datadog tracked months of quiet, automated snooping across GitHub that blends perfectly into normal traffic, and most organisations never notice it happening.

3 min read
Illustration: a glowing laptop screen displaying dense lines of green and white code in a dark room
AI Security

A Hidden Command in a GitHub Issue Can Silently Steal a Company's Private Code

Researchers found a flaw in GitHub's AI automation tool that lets an outsider read an organisation's private repositories by hiding plain-English instructions inside a public bug report.

3 min read
Macro photograph of a glowing computer terminal screen in a dark room displaying cascading green lines of code and error log text, with a single line subtly hig
AI Security

A Fake Error Message Hijacked AI Coding Assistants — and Security Tools Saw Nothing

Researchers planted a single bogus bug report in a popular developer service and watched AI coding agents obediently run the attackers' code. No password stolen. No alarm raised.

3 min read
Illustration: A dark server room bathed in dim green terminal light
AI Security

Bash Shell Tricks From the '90s Are Breaking AI Coding Agents Wide Open

Old-school shell injection techniques can bypass safeguards in most open-source AI coding agents, and a poisoned repo is all it takes to start the chain.

3 min read
Illustration: GitHub Actions workflow interface showing secure code execution, digital screen, repository checkout process
Vulnerabilities

GitHub Hardens actions/checkout Against Pwn Request Exploits

From 18 June 2026, the updated action blocks malicious code execution through pull_request_target workflows.

3 min read
Illustration: a vast illuminated data-center floor at night
AI Security

Zero Trust as the AI Control Plane: What Zscaler's Vienna Pitch Means for APAC CISOs

AI agents are joining the workforce whether security teams are ready or not. At Zenith Live 2026, Zscaler made its case for why zero trust should govern them the same way it governs humans.

3 min read
© 2026 Threat Vectr