Supply Chain Security stories
More than half of patched flaws in major DevOps tools were high or critical in 2025, putting software supply chains at greater risk.
Security teams can now fold supplier risk alerts into incident response as GuidePoint's new service targets breaches from third-party tools.
Reco COO Zoe Hillenmeyer says enterprises typically underestimate their AI agent exposure by a factor of ten and that gap is widening.
The move targets vulnerabilities in software used by large firms, as AI makes it easier to find and exploit flaws.
The funding will help firms spot hidden flaws and backdoors in compiled code as AI-generated software and supplier risk raise security concerns.
The new service aims to help firms keep pace as AI-powered criminals automate attacks faster than security teams can patch flaws.
Businesses adopting AI agents face new security and accountability risks as Ping Identity extends access controls, auditability and governance.
A zero-day in a widely used Japanese learning platform let hackers plant malware, while Chinese phishing services are now bypassing one-time codes.
Businesses rushing to deploy AI agents face a fresh security gap, as Zscaler adds identity mapping and partner services to its platform.
The certification should ease procurement concerns for finance teams handling sensitive planning data, as buyers demand tougher proof of security controls.
A Floxy study warns developers that Google's coding assistant keeps code for 540 days and defaults to training on user data.
The round values the software supply chain security company at USD $1 billion as AI coding boosts the flow of third-party code into production.
Threats from AI skills are escalating as the cybersecurity group expands research to counter a fast-growing software supply chain and attack surface.
The new integration keeps passwords out of prompts and repos, reducing the risk of leaks as AI coding agents move into production workflows.
Charities, small firms and fraud victims across Scotland got more than GBP £3 million in cyber support as the centre reinvested profits.
A free account could have let attackers alter Zapier-maintained packages and hijack logged-in users' browser sessions, researchers said.
Thousands of schools faced disruption after a vendor breach exposed how learning platforms and cloud services can halt teaching and assessments.
The hire signals CodeHunter's push to scale pre-execution software security as threats mount across supply chains and development environments.
A JFrog study says weak package and container defences are leaving Indian organisations exposed as AI use adds new checks for developers.
Belgian software SMEs risk losing B2B contracts as new EU rules expose weak threat modelling and scant security training, a PXL study says.