Supply Chain Security stories
Researchers warn the campaign can bypass multi-factor authentication, putting university and EU-linked accounts at risk of real-time takeover.
Security teams are racing to shrink exposure windows as AI makes newly disclosed vulnerabilities exploitable almost immediately.
Consumers could have had passwords and cloud tokens exposed from a low-cost indoor camera, after researchers found a flaw first disclosed in 2002.
The episode has sharpened concerns that advanced AI systems can uncover and exploit real-world security flaws during testing, even in restricted environments.
Financial firms in Asia Pacific face signed malware that can evade Windows checks after attackers abuse support portals to steal certificates.
Developers may get patched code faster as Google's preview agent scans repositories, tests exploits and drafts fixes for review.
Developers using AI assistants could face stolen credentials and poisoned repositories as the worm hides inside normal coding workflows.
Companies and individual developers have helped sustain open source as GitHub Sponsors passes USD $100 million, easing pressure on maintainers.
The coalition has now processed more than 40,000 findings, underscoring how quickly open source flaws can spread across corporate systems.
Businesses using AI coding tools face repeatable security gaps, as the new index found an average 15 vulnerabilities in each codebase.
The tool aims to help developers cut vulnerability backlogs and reach no exploitable flaws within 90 days as AI coding expands risk.
Enterprise teams can now switch on controls for AI agents and APIs faster, with Salt Security bundling 100 pre-built policies into its Policy Hub.
Security and compliance teams can now patch buildpack-based containers from a single hardened base, rather than chasing Dockerfiles across repositories.
Autonomous AI agents breached internal systems and exposed limited datasets and credentials, prompting Hugging Face to urge users to rotate tokens.
Security teams can now rank code flaws against wider business risk as Tenable One links static vulnerability data with cloud, identity and attack-path exposure.
Security teams are reassessing AI access controls after autonomous models exploited an unknown flaw and moved laterally inside a real system.
Ransomware attacks spread through vendor systems and AI-aided tactics, leaving 7,551 publicly disclosed victims in the latest 12-month period.
Real-time logging during cyber incidents helps firms rebuild events accurately and close gaps faster after attacks, Marie Hargraves says.
The certification could sway procurement decisions for critical infrastructure buyers weighing cyber assurance alongside surveillance performance.
Businesses risk false confidence if they meet the ACSC framework but leave staff exposed to phishing, social engineering and fake MFA prompts.