Application Security New GitHub, PyPI Policies Boost Supply Chain Security Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. Ionut Arghire6 days ago
Cybersecurity Funding Risk Ledger Raises $32 Million in Series B Funding The British firm has built a collaborative platform to help organizations address supply chain security risks. Ionut ArghireJuly 17, 2026
Supply Chain Security NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks By default, npm install will no longer execute scripts from dependencies, unless explicitly allowed. Ionut ArghireJune 13, 2026
Cybersecurity Funding Socket Raises $60 Million at $1 Billion Valuation The company will invest in its firewall, certified patches, protection extensions, new products, and team expansion. Ionut ArghireMay 21, 2026
Supply Chain Security Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility New vulnerabilities are being discovered too fast, the time-to-exploitation is too short, and our visibility into them is largely lacking. Kevin TownsendMay 21, 2026
Supply Chain Security Build Application Firewalls Aim to Stop the Next Supply Chain Attack Rather than scanning code alone, Build Application Firewalls inspect runtime behavior inside the software build pipeline. Kevin TownsendMay 11, 2026
Artificial Intelligence AI Coding Agents Could Fuel Next Supply Chain Crisis “TrustFall” attack shows how AI coding agents can be manipulated into launching stealthy supply chain compromises. Kevin TownsendMay 7, 2026
Artificial Intelligence Gemini CLI Vulnerability Could Have Led to Code Execution, Supply Chain Attack Attackers could inject prompts into a GitHub issue and take over the AI agent designed to automatically triage the issue. Ionut ArghireMay 7, 2026
Supply Chain Security Are SBOMs Failing? Supply Chain Attacks Rise as Security Teams Struggle With SBOM Data Researcher says the missing piece is a governance-driven intelligence layer that turns SBOM and VEX data into explainable security decisions. Kevin TownsendApril 22, 2026
Malware & Threats New ‘Sandworm_Mode’ Supply Chain Attack Hits NPM The malicious code propagates like a worm, poisons AI assistants, exfiltrates secrets, and contains a destructive dead switch. Ionut ArghireFebruary 24, 2026
Cybersecurity Funding RapidFort Raises $42M to Automate Software Supply Chain Security The company will use the latest capital to scale its go-to-market efforts and expand its platform’s capabilities. Eduard KovacsFebruary 3, 2026
Malware & Threats eScan Antivirus Delivers Malware in Supply Chain Attack Hackers compromised a MicroWorld Technologies update server and fed a malicious file to eScan customers. Ionut ArghireJanuary 31, 2026
Supply Chain Security ‘PackageGate’ Flaws Open JavaScript Ecosystem to Supply Chain Attacks The protections against NPM supply chain attacks could be bypassed, leading to arbitrary code execution. Ionut ArghireJanuary 27, 2026
Application Security Shai-Hulud Supply Chain Attack Led to $8.5 Million Trust Wallet Heist The worm exposed Trust Wallet’s Developer GitHub secrets, allowing attackers to publish a backdoor extension and steal funds from 2,520 wallets. Ionut ArghireDecember 31, 2025
Supply Chain Security From Open Source to OpenAI: The Evolution of Third-Party Risk From open source libraries to AI-powered coding assistants, speed-driven development is introducing new third-party risks that threat actors are increasingly exploiting. Nadir IzraelDecember 16, 2025
Malware & Threats Notepad++ Patches Updater Flaw After Reports of Traffic Hijacking Notepad++ found a vulnerability in the way the software updater authenticates update files. Eduard KovacsDecember 12, 2025
Supply Chain Security 640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack The new self-replicating worm iteration has destructive capabilities, erasing home directory contents if it cannot spread to more repositories. Ionut ArghireNovember 25, 2025
Malware & Threats Chinese Cyberspies Deploy ‘BadAudio’ Malware via Supply Chain Attacks APT24 has been relying on various techniques to drop the BadAudio downloader and then deploy additional payloads. Ionut ArghireNovember 21, 2025
Supply Chain Security Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks PowerShell and .NET variants of the malware abuse AirWatch’s MDM API to establish a C&C communication channel. Ionut ArghireNovember 3, 2025
Cybersecurity Funding Chainguard Raises $280 Million in Growth Funding Chainguard has raised $636 million in the past six months alone for its software supply chain security solutions. Eduard KovacsOctober 27, 2025