Tuesday 28 July 2026 12:12:36 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#Supply chain


Vendor Trust, Not Just Data, Is the Real Target in EY Extortion Claim

Published: 28 July 2026 08:19Category: Ransomware & ExtortionGeo: Europe / United KingdomAuthor: LOGICFALCON

A public claim tied to EY points to the risk hidden in third-party support access, where one trusted link can become the pressure point for an extortion attempt.

AppSec’s Noise Problem: Why ASPM Is Becoming the New Gatekeeper

Published: 28 July 2026 08:14Category: Technology, Innovation & Digital InfrastructureAuthor: SECPULSE

Application Security Posture Management is being judged less by marketing and more by whether it can turn scattered findings into a defensible, continuous view of real exposure.

Open Secure AI Alliance Forms as Big Tech Bets on Shared AI Defense

Published: 28 July 2026 08:03Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

NVIDIA, Microsoft, CrowdStrike and more than 30 industry participants have backed a new coalition focused on open-source tools for AI safety and security, with the technical challenge centered on making complex AI systems easier to inspect, test, and govern.

Italy Turns Supplier Risk Into a Security Discipline Under NIS2

Published: 27 July 2026 18:34Category: Privacy, Regulation & ComplianceGeo: Europe / ItalyAuthor: WHITEHAWK

ACN’s updated FAQs show how NIS2 supply-chain obligations are being translated from legal text into day-to-day controls for regulated organizations.

Why the Week’s Cyber Noise Points to a Bigger Control Problem

Published: 27 July 2026 18:28Category: Cyber Intelligence & Threat TrendsAuthor: PHANTOMINTEGRITY

A cluster of topics around rogue AI agents, a Check Point exploit, slopsquatting, and ClickFix lures points to one hard truth: attackers keep aiming at trust boundaries, not just code flaws.

GitHub and PyPI Draw a New Line Around Dependency Risk

Published: 27 July 2026 18:20Category: Cyber Intelligence & Threat TrendsGeo: North America / USAAuthor: PHANTOMINTEGRITY

A three-day Dependabot delay and a 14-day PyPI upload cutoff show how software platforms are turning timing into a supply-chain defense.

When AI Booms on Borrowed Ground: The Infrastructure Bill Hiding Behind the Hype

Published: 27 July 2026 16:42Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

The loudest AI narratives focus on models and miracles, but the harder story is about power-hungry data centers, layered financing, and where the downside quietly lands.

GitHub Slows the Dependency Firehose With a Hidden Waiting Game

Published: 27 July 2026 14:27Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A new three-day cooldown in Dependabot changes automated updates from instant reaction to release-age vetting, aiming to blunt fast-moving supply chain abuse.

GitHub Slams a Pause on Fresh Dependencies Before Automation Makes the First Move

Published: 27 July 2026 14:25Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A new default cooldown for Dependabot version updates is designed to slow the automatic adoption of newly released packages and narrow the window for supply-chain abuse.

More Than 70 Look-Alike Windows Download Sites Turn Software Search Into a Trap

Published: 27 July 2026 14:17Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A cluster of impersonation domains shows how attackers can abuse search traffic, brand trust, and download reputation before any file ever reaches the desktop.

Why Mobile App Inventory Is Becoming a Security Control, Not a Nice-to-Have

Published: 27 July 2026 14:14Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: TRUSTBREAKER

Lookout’s Mobile Security Exposure Center puts SBOMs to work on enterprise apps, helping teams spot vulnerable components, dependencies, and other hidden risks before they become a problem.

GitHub’s New Dependabot Delay Turns Fresh Packages Into Waiting Room Cases

Published: 27 July 2026 12:56Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A default three-day cooldown for version updates changes how quickly automation can promote newly published dependencies into a maintainer’s review queue.

The Air-Gap Myth: Why Isolation Is Not the Same as Security

Offline networks reduce remote exposure, but removable media, insider access, supply-chain flaws, firmware trust, and side channels still define the real attack surface.

Italy Tightens the Lens on NIS2 Supplier Risk

Published: 27 July 2026 12:07Category: Legal, Policy & Government CybersecurityGeo: Europe / ItalyAuthor: WARDRIVERZERO

ACN’s updated FAQs push supply-chain security into the compliance spotlight, signaling that regulated entities need clearer governance over suppliers, requirements, and verification.

Ransomware Counts Rise as Supply Chain Pressure Accelerates

Published: 27 July 2026 10:17Category: Ransomware & ExtortionAuthor: HEXSENTINEL

Recorded ransomware activity climbed 3% quarter over quarter in Q2 2026, while software supply chain attacks continued to speed up.

PyPI Locks the Back Door on Aging Releases

Published: 27 July 2026 08:11Category: CybercrimeGeo: North America / USAAuthor: VULNCRUSADER

By refusing late file uploads to older package releases, the Python registry is tightening a trust boundary that attackers have long tried to exploit.

PyPI Puts a Time Lock on Package Tampering

Published: 27 July 2026 08:06Category: CybercrimeGeo: North America / USAAuthor: VULNCRUSADER

A new 14-day upload restriction narrows one of the cleaner routes for package poisoning when publishing access is compromised.

When Fresh Code Gets a Delay: GitHub Turns Time Into a Supply-Chain Filter

Published: 26 July 2026 18:06Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

A new default cooldown in Dependabot shows how open-source defenders are using age, not just signatures, to slow risky dependency updates.

The Quiet Sabotage Hidden Inside Build Files

Published: 24 July 2026 19:20Category: Malware & BotnetsGeo: Europe / RussiaAuthor: NEXUSGUARDIAN

A reported Doctor Web finding shows how C++ and C# project files can become a supply-chain attack surface, turning ordinary development workflows into a distribution risk.

When AI Invents the Dependency, Attackers May Own the Download

Published: 24 July 2026 18:34Category: Research, Exploits & Offensive SecurityAuthor: PATCHVIPER

A growing class of supply-chain tricks targets the moment an AI assistant turns a made-up package, repo, or domain name into an actual fetch or install action.