Supply Chain Security stories
Dell unveils quantum-ready PC firmware and AI-focused data protection tools to counter emerging threats across devices and AI workloads.
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
OpenSSF adds new members and launches AI security, supply chain and training initiatives after securing USD $12.5 million in funding.
GitLab opens agentic AI to free-tier users, sets USD $0.25 flat fee for automated code reviews and expands security false-positive filtering.
Yubico and Delinea unite hardware keys with identity checks to ensure each high‑risk AI agent action is explicitly approved by a human.
Iceland-based Varist has launched a free malware scanner that rates suspicious files in seconds to counter fast-evolving AI-driven threats.
OPSWAT founder Benny Czarny urges a prevention-first cyber defence in his new book, arguing detection-led tools can no longer keep pace.
DigiCert reports record Q4 ARR in FY26 as DigiCert ONE platform growth, acquisitions and automation demand drive digital trust expansion.
SpecterOps broadens BloodHound Enterprise to map identity attack paths across Okta, GitHub and Jamf-managed Macs in hybrid environments.
Miggo and Grafana link runtime security to Grafana Cloud telemetry, promising major cuts to critical vulnerability noise for joint users.
Keysight debuts SBOM Manager to automate software bills of materials as EU and US cyber rules tighten transparency and compliance demands.
AppViewX acquires AI identity start-up Eos and appoints its co-founder Archit Lohokare as Chief Executive, targeting non-human identity security.
Chainguard launches a free Catalog Starter pack, giving developers five production-grade secure container images from its vast library.
North Korean IT workers using Western collaborators and fake identities are infiltrating remote jobs to funnel foreign salaries home.
Lineaje launches UnifAI, a security and governance layer to centralise control, discovery and policy for enterprise agentic AI deployments.
JFrog launches an MCP registry to centralise and secure AI coding agents, extending software supply chain controls to agent workflows.
Morphisec unveils Adaptive AI Defence to spot shadow AI, block compromised agents and thwart AI-driven ransomware in real time.
Organisations test just a third of their attack surface as reliance on agentic AI grows, raising fresh concerns over unseen cyber risks.
Canadian firms warn ageing networks, quantum threats and data rules are outpacing cyber defences, as most report major outages.
Backslash adds cross-tool governance to discover, vet and monitor 'Skills' powering AI coding assistants like Cursor, Claude Code and Copilot.