Supply Chain Security stories
Companies and individual developers have helped sustain open source as GitHub Sponsors passes USD $100 million, easing pressure on maintainers.
The coalition has now processed more than 40,000 findings, underscoring how quickly open source flaws can spread across corporate systems.
Businesses using AI coding tools face repeatable security gaps, as the new index found an average 15 vulnerabilities in each codebase.
The tool aims to help developers cut vulnerability backlogs and reach no exploitable flaws within 90 days as AI coding expands risk.
Enterprise teams can now switch on controls for AI agents and APIs faster, with Salt Security bundling 100 pre-built policies into its Policy Hub.
Security and compliance teams can now patch buildpack-based containers from a single hardened base, rather than chasing Dockerfiles across repositories.
Autonomous AI agents breached internal systems and exposed limited datasets and credentials, prompting Hugging Face to urge users to rotate tokens.
Security teams can now rank code flaws against wider business risk as Tenable One links static vulnerability data with cloud, identity and attack-path exposure.
Smaller businesses under pressure from insurers and buyers can now turn existing SonicWall security setups into SMB1001 certification evidence.
For thousands of banks and payments firms, the trial could help spot software flaws before they disrupt critical financial systems.
The framework targets CISOs and platform teams as they move AI systems into production, amid rising risks from prompts, models and outputs.
Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.
Defenders could gain a faster edge against AI-driven attacks as Google Cloud ties Gemini, Wiz, CodeMender and Mandiant into one platform.
Rising automation could speed cyber defence, but Filigran says security teams must keep humans in the loop as agentic AI spreads.
The update aims to cut review bottlenecks by auto-fixing vulnerable dependencies and surfacing code flaws scanners often miss.
The certification could sway procurement decisions for critical infrastructure buyers weighing cyber assurance alongside surveillance performance.
Businesses risk false confidence if they meet the ACSC framework but leave staff exposed to phishing, social engineering and fake MFA prompts.
Smaller firms can now run web app pentests in hours, as Intruder's AI service cuts costs to a fraction of manual reviews.
Growing threats to UK critical infrastructure have pushed Siemens and NCC Group to join forces on protecting industrial systems from cyber attacks.
Breaches across New Zealand are increasingly exploiting human trust, with thieves using logins and one-time codes to steal data and funds.