Supply Chain Security stories - Page 4
Trivy GitHub breach exposes CI/CD supply chain risk
Last month
#
devops
#
cloud security
#
application security
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
GitLab widens AI access & sets flat review pricing
Last month
#
devops
#
application security
#
devsecops
GitLab opens agentic AI to free-tier users, sets USD $0.25 flat fee for automated code reviews and expands security false-positive filtering.
Yubico & Delinea link AI actions to human approval
Last month
#
data protection
#
hybrid cloud
#
pam
Yubico and Delinea unite hardware keys with identity checks to ensure each high‑risk AI agent action is explicitly approved by a human.
Varist launches free malware scanner amid AI threat
Last month
#
cloud security
#
advanced persistent threat protection
#
socs
Iceland-based Varist has launched a free malware scanner that rates suspicious files in seconds to counter fast-evolving AI-driven threats.
OPSWAT founder urges prevention-first cyber defence
Last month
#
malware
#
firewalls
#
ransomware
OPSWAT founder Benny Czarny urges a prevention-first cyber defence in his new book, arguing detection-led tools can no longer keep pace.
DigiCert posts record Q4 ARR after expansion spree
Last month
#
digital transformation
#
encryption
#
hyperscale
DigiCert reports record Q4 ARR in FY26 as DigiCert ONE platform growth, acquisitions and automation demand drive digital trust expansion.
BloodHound expands identity attack path mapping reach
Last month
#
data protection
#
encryption
#
pam
SpecterOps broadens BloodHound Enterprise to map identity attack paths across Okta, GitHub and Jamf-managed Macs in hybrid environments.
Miggo & Grafana link runtime security with telemetry
Last month
#
devops
#
cloud security
#
application security
Miggo and Grafana link runtime security to Grafana Cloud telemetry, promising major cuts to critical vulnerability noise for joint users.
Keysight unveils SBOM Manager to meet new cyber rules
Last month
#
application security
#
physical security
#
devsecops
Keysight debuts SBOM Manager to automate software bills of materials as EU and US cyber rules tighten transparency and compliance demands.
Chainguard unveils free starter pack for secure images
Last month
#
virtualisation
#
devops
#
cloud security
Chainguard launches a free Catalog Starter pack, giving developers five production-grade secure container images from its vast library.
Lineaje unveils UnifAI to secure enterprise agentic AI
Last month
#
data protection
#
digital transformation
#
application security
Lineaje launches UnifAI, a security and governance layer to centralise control, discovery and policy for enterprise agentic AI deployments.
JFrog unveils MCP registry to secure AI coding agents
Last month
#
devops
#
digital transformation
#
application security
JFrog launches an MCP registry to centralise and secure AI coding agents, extending software supply chain controls to agent workflows.
TrendAI links with HPE to secure private cloud AI stack
Last month
#
virtualisation
#
data protection
#
private cloud
TrendAI integrates its AI security platform with HPE Private Cloud AI to secure enterprise AI deployments from infrastructure to applications.
TrendAI, Nvidia bring digital twin security to AI hubs
Last month
#
firewalls
#
hybrid cloud
#
digital transformation
TrendAI and Nvidia link DSX Air with digital twin security tools so AI datacentre “factories” can be hardened before hardware is built.
TrendAI & Nvidia boost security for agentic AI tools
Last month
#
cloud security
#
application security
#
advanced persistent threat protection
TrendAI and Nvidia deepen collaboration to embed layered security and governance into OpenShell, protecting long-lived autonomous AI agents.
Secure Code Warrior unveils AI code governance tool
Last month
#
application security
#
devsecops
#
supply chain
Secure Code Warrior launches SCW Trust Agent: AI, giving security teams commit-level visibility and control over AI-influenced code.
AI surge drives record secrets sprawl across GitHub
Last month
#
cloud security
#
application security
#
socs
AI-fuelled coding drives record 29 million hardcoded secrets on GitHub in 2025, with leaks from AI tools and services surging sharply.
Harness unveils AI Security & coding tools for DevSecOps
Last month
#
devops
#
application security
#
advanced persistent threat protection
Harness has launched AI Security and Secure AI Coding tools to spot and block vulnerabilities in AI-powered apps and AI-generated code.
1Password debuts Unified Access to secure AI agents
Last month
#
data protection
#
cloud security
#
mdm
1Password unveils Unified Access to secure AI agents and machine credentials, promising endpoint-to-agent visibility for security teams.
FIRST announces 2026 cyber security conference trio
Last month
#
application security
#
advanced persistent threat protection
#
socs
FIRST to host three cybersecurity conferences in 2026 as it predicts annual CVE disclosures will surpass 50,000 for the first time.