Tag: software supply chain

Organizations need stronger visibility into AI agents before applying Zero Trust controls, as experts highlight risks around shadow AI, monitoring gaps and governance challenges.
Systems Limited has supported Wafi Energy Pakistan in separating from a legacy global IT ecosystem through an SAP S/4HANA transformation, helping establish greater local technology ownership.

Shai Hulud Infostealer Highlights Growing Credential Security Risks In Software Supply Chains

GitGuardian researchers report that the latest Shai Hulud variant now scans 469 credential locations, highlighting increased risks to software supply chains, CI/CD systems, cloud platforms, and AI development environments.

GitHub Introduces Three Day Dependabot Delay To Reduce Supply Chain Risks

GitHub has introduced a default three day cooldown for Dependabot version updates to help reduce the risk of poisoned software packages spreading through supply chains.

Trojanized Newtonsoft Json Package Targets Digitain Gaming Platform

Researchers discovered a trojanized NuGet package posing as Newtonsoft.Json that secretly targeted Digitain gaming systems while functioning as a legitimate library for other users.

GhostApproval Flaw Exposes AI Coding Assistants To Malicious Repository Code Execution Risks

Researchers at Wiz have disclosed the GhostApproval vulnerability affecting several AI coding assistants, enabling malicious repositories to manipulate file approvals and potentially execute code on developer systems.

GuardFall Research Reveals Shell Injection Risks Across Open Source AI Coding Agents

Adversa AI has disclosed GuardFall, a shell injection bypass affecting 10 of 11 tested open source AI coding agents, exposing systems to command execution and credential theft risks.

Malicious NPM Package Targets Claude AI User Directory To Steal Files Via GitHub

Researchers uncover a malicious npm package targeting Claude AI user directories to steal files and upload them to attacker controlled GitHub repositories.

Google Patches Antigravity IDE Flaw As Researchers Expose Expanding Prompt Injection Attack Surface In AI Tools

Google fixes Antigravity IDE vulnerability enabling prompt injection based code execution as researchers uncover wider AI tool security flaws across coding agents and platforms.

GlassWorm Supply Chain Campaign Targets Developers Through Malicious Open VSX Extensions

Security researchers report an expanded GlassWorm campaign using malicious Open VSX extensions and hidden Unicode code to target developers and steal sensitive data.

Recent articles

spot_img