Supply Chain Security stories
AI flaws & supply-chain risks top new pentesting report
Yesterday
#
data protection
#
devops
#
application security
Cobalt's annual pentesting study says AI and supplier tools are exposing fresh weaknesses, with security teams struggling to keep pace with rapid deployment.
Cyber Essentials update raises bar on visibility gaps
2 days ago
#
firewalls
#
data protection
#
network security
UK Cyber Essentials overhaul tightens MFA and patching rules, forcing firms to prove controls cover every device and account or risk failure.
Cloudsmith raises USD $72 million in Series C round
2 days ago
#
cloud security
#
application security
#
devsecops
Belfast software firm Cloudsmith secures USD $72 million as TCV returns to back its push to secure AI-driven software supply chains.
CrowdStrike launches AI security coalition with partners
2 days ago
#
cloud security
#
application security
#
devsecops
CrowdStrike unveils AI security coalition with Accenture, EY, IBM Cybersecurity Services, Kroll and OpenAI to spot and fix code flaws faster.
Anthropic AI's Mythos triggers warnings over cyber risk
3 days ago
#
firewalls
#
data protection
#
devops
Anthropic AI's Mythos prompts cyber security warnings as experts urge UK boards to treat AI-driven threats as a strategic risk.
Thales launches Imperva for Google Cloud in controlled availability
3 days ago
#
firewalls
#
data protection
#
devops
Thales brings Imperva into Google Cloud as controlled launch targets app and API protection with lower latency and simpler operations.
Lineaje survey finds AI code confidence outpaces visibility
3 days ago
#
digital transformation
#
application security
#
devsecops
Lineaje survey flags a widening governance gap as most firms use AI-generated code, yet few can fully see or track it.
Claude Code can leak secrets in public npm packages
3 days ago
#
data protection
#
application security
#
devsecops
Check Point says Anthropic's Claude Code can quietly stash credentials in .claude/settings.local.json, which may be published in public npm packages.
LevelBlue warns of GhostOps risk from rogue AI agents
4 days ago
#
data protection
#
digital transformation
#
cloud security
LevelBlue says unsanctioned AI agents are slipping into enterprise systems, creating a hidden governance and security blind spot for businesses.
Google Cloud unveils AI security tools & fraud defence
4 days ago
#
firewalls
#
data protection
#
hyperscale
Google Cloud expands AI security with new agents, Wiz integrations and fraud defences as it targets faster, more automated cyber attacks.
Cambridge Wireless unveils 2026 conference on AI & security
4 days ago
#
robots
#
uc
#
firewalls
Cambridge Wireless sets out a 2026 conference agenda spanning AI, cyber resilience, quantum networking and industrial automation.
Zscaler joins Anthropic Project Glasswing on cyber AI
4 days ago
#
firewalls
#
vpns
#
network security
Zscaler joins Anthropic's Project Glasswing to test Claude Mythos Preview in software scans, as the firm pushes zero trust against AI-driven attacks.
HackerOne launches h1 Validation to tackle AI flaws
4 days ago
#
devops
#
digital transformation
#
application security
HackerOne unveils h1 Validation as vulnerability reports surge 76% and AI tools speed up discovery, leaving firms struggling to triage real threats.
CIS launches AI security guides for models & agents
4 days ago
#
digital transformation
#
application security
#
physical security
CIS, Astrix and Cequence publish AI security guides for large language models, autonomous agents and MCP environments.
SUSE launches AI Factory with NVIDIA for enterprise control
4 days ago
#
virtualisation
#
private cloud
#
devops
SUSE and NVIDIA unveil an enterprise AI stack aimed at regulated sectors, offering on-premise control, governance and sovereignty for production use.
Chainguard & Cursor tackle AI code supply chain risks
4 days ago
#
devops
#
application security
#
devsecops
Chainguard and Cursor strike partnership to embed verified open source dependencies into AI coding, aiming to curb supply chain risks at machine speed.
Tenable flags Microsoft GitHub workflow flaw exposing code
4 days ago
#
devops
#
cloud security
#
application security
Tenable warns a GitHub Actions bug in Microsoft's Windows-driver-samples repo could let attackers run code and steal secrets via public issues.
BlackBerry survey flags secure messaging gaps in government
5 days ago
#
data protection
#
encryption
#
mdm
BlackBerry survey finds government and infrastructure security chiefs relying on WhatsApp for sensitive talks despite major misunderstandings over encryption.
AI vulnerability discovery forces boards to rethink cyber risk
5 days ago
#
data protection
#
application security
#
iam
AI models that can hunt and chain software flaws are forcing boards to rethink cyber defences, while scrutiny grows over Anthropic's MCP design risks.
Cyber Scheme launches company accreditation programme
5 days ago
#
devops
#
iot security
#
socs
Cyber Scheme extends professional standards to firms with new company accreditation backed by UK council benchmarks and procurement access.