Supply Chain Security stories
Industrials remained the main target as the monthly ransomware total eased 7%, even as The Gentlemen surged to second place among active gangs.
The move gives the cyber risk provider closer access to EMEA customers as demand rises for better oversight of supplier vulnerabilities.
Critical infrastructure operators could gain broader visibility as Dragos adds Phosphorus tools for managing exposed connected devices across OT networks.
Industrial operators are turning to tighter network controls to curb cyberattacks, with OT now featuring in 26% of Zero Networks deals.
More than half of patched flaws in major DevOps tools were high or critical in 2025, putting software supply chains at greater risk.
Security teams can now fold supplier risk alerts into incident response as GuidePoint's new service targets breaches from third-party tools.
Reco COO Zoe Hillenmeyer says enterprises typically underestimate their AI agent exposure by a factor of ten and that gap is widening.
The move targets vulnerabilities in software used by large firms, as AI makes it easier to find and exploit flaws.
The funding will help firms spot hidden flaws and backdoors in compiled code as AI-generated software and supplier risk raise security concerns.
The new service aims to help firms keep pace as AI-powered criminals automate attacks faster than security teams can patch flaws.
Businesses adopting AI agents face new security and accountability risks as Ping Identity extends access controls, auditability and governance.
A zero-day in a widely used Japanese learning platform let hackers plant malware, while Chinese phishing services are now bypassing one-time codes.
Businesses rushing to deploy AI agents face a fresh security gap, as Zscaler adds identity mapping and partner services to its platform.
The certification should ease procurement concerns for finance teams handling sensitive planning data, as buyers demand tougher proof of security controls.
A Floxy study warns developers that Google's coding assistant keeps code for 540 days and defaults to training on user data.
Malicious open source packages are increasingly slipping past spelling checks, exposing developer data and build systems to supply-chain attacks.
Charities, small firms and fraud victims across Scotland got more than GBP £3 million in cyber support as the centre reinvested profits.
A free account could have let attackers alter Zapier-maintained packages and hijack logged-in users' browser sessions, researchers said.
Thousands of schools faced disruption after a vendor breach exposed how learning platforms and cloud services can halt teaching and assessments.
The hire signals CodeHunter's push to scale pre-execution software security as threats mount across supply chains and development environments.