Supply Chain Security stories
A proposed framework could help firms share AI security failures confidentially, as concern grows over agentic systems that act across corporate tools.
Businesses using AI agents face new risks of data leakage and malicious actions as ESET folds detection into its PROTECT platform.
The tie-up aims to help security teams turn validated AI findings into ranked fixes before vulnerabilities pile up and attackers move first.
Enterprises could slash AI compliance work from months to days as Red Hat's open source asago project turns policy documents into deployable controls.
Partners can now embed threat intelligence and exploit detection into their tools, as Proofpoint formalises years of OEM deals into a single programme.
Security teams can now automate triage of leaked credentials, phishing pages and breach claims while keeping policy controls and audit trails in place.
Security teams must now track AI agents and machine accounts as well as staff, as BeyondTrust expands Pathfinder to cover privileged access.
Security teams face a wider visibility gap as Tenable adds Google Gemini, MCP and AI coding tools to its exposure management platform.
Organisations using Wayfinder Frontier AI Services will now get help turning validated vulnerabilities into prioritised fixes and post-deployment checks.
Defenders now face a 48-hour window after proof-of-concept code appears, as attackers use AI to speed exploits and hit software chains.
Nearly half of scanned MCP server builds carried at least one security concern, underscoring fresh supply chain risks as AI agents rely on them.
Organisations now have just 48 hours to patch most flaws, as AI helps attackers weaponise vulnerabilities far faster than before.
Faster digital payments are leaving fintech firms exposed as regulators and attackers pressure weak controls and resilience across the sector.
The move could reshape enterprise AI security as vendors and regulators demand stronger controls around access, logging and containment.
Security teams can now track newly disclosed CVEs in live systems, as RapidFort expands its supply chain tools into production monitoring.
Security teams can now stop rogue enterprise AI agents in seconds as Straiker adds runtime controls to its wider testing platform.
The update aims to cut remediation costs and stop teams wasting time by re-analysing vulnerabilities without enough business context.
AWS customers can now buy Chainguard Libraries through Security Hub Extended, as open-source dependency attacks push firms to tighten supply chain checks.
Mobile teams can now alter protections in published apps without a rebuild, speeding responses to fraud and other threats.
Open source package attacks can now be blocked earlier, as NetRise brings trust checks into editors, command lines and AI coding tools.