#supply chain security
28 stories taggedsupply chain security · page 2 of 2.

Militaries Want Autonomous Weapons Fast. The Data Pipes Behind Them Are the Weak Link.
Defence ministries are pouring money into drones and robots that can think for themselves. The information systems feeding those machines haven't caught up.

Risk Ledger Raises £24 Million to Expand Its Supply Chain Security Network
The London firm wants more organisations checking each other's security hygiene in one shared space. Now it has the money to push into the US and build AI review tools.

Give an AI a Body and You Give It an Attack Surface
Warehouses and factories are buying humanoid robots before security teams have a single audit standard to work from. Here's what that means for the people on the floor.

Your Vendors Are a Risk You Cannot Ignore. Here Is How Boards Should Own It.
Most companies review their suppliers and tick the boxes. Far fewer can say how much financial damage a vendor failure would actually cost them. That gap is the problem.

HalluSquatting: How AI Hallucinations Are Being Turned Into a Doorway for Malware
Security researchers have found a way to turn a known quirk of AI chatbots into a method for delivering malicious software directly to developers' computers, without hacking the AI itself.

GhostApproval: Six AI Coding Tools Were Tricking Developers Into Approving Dangerous Actions
A new attack pattern shows that the 'human approval' step built into AI coding assistants can be fed false information by the very tool it is supposed to oversee.

npm 12 Turns Off Auto-Run Install Scripts to Blunt Supply Chain Attacks
GitHub's package manager for JavaScript now ships with a safer default, and it retires a token type that let developers skip two-factor login.

Criminals Are Using GitHub's Own Public Tools to Map Your Company Before They Strike
Researchers at Datadog tracked months of quiet, automated snooping across GitHub that blends perfectly into normal traffic, and most organisations never notice it happening.

A Hidden Command in a GitHub Issue Can Silently Steal a Company's Private Code
Researchers found a flaw in GitHub's AI automation tool that lets an outsider read an organisation's private repositories by hiding plain-English instructions inside a public bug report.

A Fake Error Message Hijacked AI Coding Assistants — and Security Tools Saw Nothing
Researchers planted a single bogus bug report in a popular developer service and watched AI coding agents obediently run the attackers' code. No password stolen. No alarm raised.

Bash Shell Tricks From the '90s Are Breaking AI Coding Agents Wide Open
Old-school shell injection techniques can bypass safeguards in most open-source AI coding agents, and a poisoned repo is all it takes to start the chain.

GitHub Hardens actions/checkout Against Pwn Request Exploits
From 18 June 2026, the updated action blocks malicious code execution through pull_request_target workflows.

Zero Trust as the AI Control Plane: What Zscaler's Vienna Pitch Means for APAC CISOs
AI agents are joining the workforce whether security teams are ready or not. At Zenith Live 2026, Zscaler made its case for why zero trust should govern them the same way it governs humans.