A new default cooldown in Dependabot shows how open-source defenders are using age, not just signatures, to slow risky dependency updates.
A breach involving a vendor-managed IT support platform shows how sensitive client tax data can travel through a trust boundary that many organizations do not fully see.
Risk Ledger’s $32 million Series B puts a spotlight on a growing idea in cyber defense: that supplier risk data works better when it is shared, updated, and tied to live dependency maps.
A new cross-border disclosure framework puts structure around how suppliers receive, triage, and fix security flaws, with coordination now treated as part of the job.
A critical path traversal bug in IntelliJ IDEA is a reminder that the tools used to build software can become part of the attack surface themselves.
A new healthcare warning puts supply-chain security, identity management, and staff readiness in the same frame: cyber risk becomes operational risk when hospitals cannot trust who connects, who updates, or who responds.
The Pentagon has paused phase two of CMMC, turning a certification dispute into a sharper question: how much security can smaller defense suppliers realistically afford?
Multiple npm package versions tied to Jscrambler were poisoned in a supply chain attack, showing how a trusted update path can become the delivery mechanism for credential-stealing malware.
A malicious jscrambler release in npm shows how one compromised publish path can put developer workstations and CI jobs in the crosshairs of cloud and source-control secrets.
A multi-stage Trojan tied to Visual Studio project files shows how ordinary build logic can turn into a supply-chain attack surface.
A vulnerability in Guix's privileged daemon shows how package restoration, when mishandled, can cross from software delivery into root-level file tampering.
A named victim entry tied to a logistics company is only a claim, not proof, but it is enough to justify a careful look at how 3PL environments absorb ransomware pressure.
A ransomware listing tied to NXIT, Franco Vago S.p.a., and Traconf Srl points to a high-value logistics environment where stolen data can matter as much as encryption.
Multiple critical flaws in Guix’s substitute and channel-update workflows highlight how a package manager built for integrity can still be shaken by unsafe parsing, archive handling, and privileged daemon logic.
OpenMandriva Linux says it faced an attempted internal sabotage tied to a contributor dispute, a reminder that repository access can become a security issue long before malware enters the picture.
In finance, cyber risk is no longer confined to the bank’s own systems; the real exposure now stretches across SaaS tools, network gear, suppliers, and the quieter layers of the technology supply chain.
A large scan of MCP servers suggests that familiar flaws like file abuse, command injection, SSRF, and SQL injection are now surfacing inside the software layer that connects LLMs to real systems.
A compliance-focused push toward binary-level verification shows that software transparency is only useful when the record reflects what is actually shipped.
Fincantieri’s reported four-way acquisition push is not a cyber incident, but it does spotlight how subsea technology is becoming a strategic layer of security, energy, and infrastructure resilience.
As AI-assisted coding shrinks the distance between an idea and a deployable application, the real risk is not speed itself but the disappearance of the review moments that used to catch bad code before it shipped.