Lunes 27 Julio 2026 00:25:46 GMT+02:00

Netcrook

InicioManifiesto
Noticias
Techcrook
Geocrook
WikicrookEquipoAppContactoLogin
EnglishItaliano

#Supply Chain Security


When Fresh Code Gets a Delay: GitHub Turns Time Into a Supply-Chain Filter

Published: 26 July 2026 18:06Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

A new default cooldown in Dependabot shows how open-source defenders are using age, not just signatures, to slow risky dependency updates.

When the Help Desk Becomes the Heist Route: EY’s Tax Files and the Vendor Trust Problem

Published: 18 July 2026 10:13Category: Breaches & Data LeaksGeo: North America / USAAuthor: SECURERECLAIMER

A breach involving a vendor-managed IT support platform shows how sensitive client tax data can travel through a trust boundary that many organizations do not fully see.

Supplier Risk Gets Bankable as Security Teams Push Past Static Questionnaires

Risk Ledger’s $32 million Series B puts a spotlight on a growing idea in cyber defense: that supplier risk data works better when it is shared, updated, and tied to live dependency maps.

Governments Are Rewiring Vulnerability Disclosure Before the Next Bug Goes Public

Published: 16 July 2026 17:22Category: Legal, Policy & Government CybersecurityGeo: North America / USAAuthor: ROOTBEACON

A new cross-border disclosure framework puts structure around how suppliers receive, triage, and fix security flaws, with coordination now treated as part of the job.

JetBrains Patch Wave Exposes a Quiet Fault Line in Developer Security

Published: 16 July 2026 12:52Category: Vulnerabilities & Patch ManagementGeo: Europe / Czech RepublicAuthor: NEONPALADIN

A critical path traversal bug in IntelliJ IDEA is a reminder that the tools used to build software can become part of the attack surface themselves.

Healthcare’s Quiet Weak Spot Is Not a Hack - It Is the Gaps Between Vendors, Logins, and Practice

Published: 14 July 2026 18:18Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A new healthcare warning puts supply-chain security, identity management, and staff readiness in the same frame: cyber risk becomes operational risk when hospitals cannot trust who connects, who updates, or who responds.

When Cyber Compliance Gets Too Pricey, the Slowdown Starts at the Perimeter

Published: 14 July 2026 14:20Category: Legal, Policy & Government CybersecurityGeo: North America / USAAuthor: ROOTBEACON

The Pentagon has paused phase two of CMMC, turning a certification dispute into a sharper question: how much security can smaller defense suppliers realistically afford?

Poisoned Packages, Quiet Secrets: The Jscrambler npm Case Exposes a Familiar Trap

Published: 14 July 2026 12:20Category: Malware & BotnetsGeo: Europe / PortugalAuthor: IRONQUERY

Multiple npm package versions tied to Jscrambler were poisoned in a supply chain attack, showing how a trusted update path can become the delivery mechanism for credential-stealing malware.

Poisoned npm Update Turns a Security Tool Into a Secret Grabber

Published: 13 July 2026 10:35Category: Cloud, SaaS & Identity SecurityGeo: Europe / PortugalAuthor: SHADOWFIREWALL

A malicious jscrambler release in npm shows how one compromised publish path can put developer workstations and CI jobs in the crosshairs of cloud and source-control secrets.

When a Build File Becomes the Breach Door

Published: 11 July 2026 08:04Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A multi-stage Trojan tied to Visual Studio project files shows how ordinary build logic can turn into a supply-chain attack surface.

GNU Guix Bug Turned a Trusted Restore Path Into a Host-Write Risk

Published: 10 July 2026 19:30Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A vulnerability in Guix's privileged daemon shows how package restoration, when mishandled, can cross from software delivery into root-level file tampering.

Deadlock Victim Listing Puts a Logistics Provider Under a Cyber Microscope

Published: 10 July 2026 18:54Category: Ransomware & ExtortionAuthor: NEBULASCOUT

A named victim entry tied to a logistics company is only a claim, not proof, but it is enough to justify a careful look at how 3PL environments absorb ransomware pressure.

DeadLock’s New Logistics Target Puts Luxury Supply Chains Under Extortion Pressure

Published: 10 July 2026 18:51Category: Ransomware & ExtortionGeo: Europe / ItalyAuthor: HEXSENTINEL

A ransomware listing tied to NXIT, Franco Vago S.p.a., and Traconf Srl points to a high-value logistics environment where stolen data can matter as much as encryption.

GNU Guix Faces a Rare Trust-Chain Break in Its Most Sensitive Paths

Published: 10 July 2026 12:11Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

Multiple critical flaws in Guix’s substitute and channel-update workflows highlight how a package manager built for integrity can still be shaken by unsafe parsing, archive handling, and privileged daemon logic.

Inside the Trust Breakpoint Open Source Projects Fear Most

Published: 10 July 2026 02:04Category: Technology, Innovation & Digital InfrastructureGeo: Europe / FranceAuthor: TRUSTBREAKER

OpenMandriva Linux says it faced an attempted internal sabotage tied to a contributor dispute, a reminder that repository access can become a security issue long before malware enters the picture.

Banking’s New Weak Spot Is Not the Firewall - It Is the Vendor Map

Published: 09 July 2026 16:27Category: Cloud, SaaS & Identity SecurityAuthor: AUDITWOLF

In finance, cyber risk is no longer confined to the bank’s own systems; the real exposure now stretches across SaaS tools, network gear, suppliers, and the quieter layers of the technology supply chain.

When AI Tooling Inherits Old Bugs, the Blast Radius Gets New

Published: 07 July 2026 14:30Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: PATCHVIPER

A large scan of MCP servers suggests that familiar flaws like file abuse, command injection, SSRF, and SQL injection are now surfacing inside the software layer that connects LLMs to real systems.

The SBOM Trust Problem: Why the Inventory Has to Match the Binary

Published: 06 July 2026 19:30Category: Privacy, Regulation & ComplianceGeo: Asia / South KoreaAuthor: SAFEHEXER

A compliance-focused push toward binary-level verification shows that software transparency is only useful when the record reflects what is actually shipped.

Italy’s Underwater Power Play Raises the Stakes for Critical Infrastructure

Published: 06 July 2026 19:24Category: Technology, Innovation & Digital InfrastructureGeo: Europe / ItalyAuthor: TRUSTBREAKER

Fincantieri’s reported four-way acquisition push is not a cyber incident, but it does spotlight how subsea technology is becoming a strategic layer of security, energy, and infrastructure resilience.

AI Can Draft the App in Minutes - Security Still Has to Earn Its Place

Published: 06 July 2026 18:43Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

As AI-assisted coding shrinks the distance between an idea and a deployable application, the real risk is not speed itself but the disappearance of the review moments that used to catch bad code before it shipped.