Supply Chain Security stories
Autonomous AI agents breached internal systems and exposed limited datasets and credentials, prompting Hugging Face to urge users to rotate tokens.
Security teams can now rank code flaws against wider business risk as Tenable One links static vulnerability data with cloud, identity and attack-path exposure.
Smaller businesses under pressure from insurers and buyers can now turn existing SonicWall security setups into SMB1001 certification evidence.
For thousands of banks and payments firms, the trial could help spot software flaws before they disrupt critical financial systems.
The framework targets CISOs and platform teams as they move AI systems into production, amid rising risks from prompts, models and outputs.
Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.
Defenders could gain a faster edge against AI-driven attacks as Google Cloud ties Gemini, Wiz, CodeMender and Mandiant into one platform.
Rising automation could speed cyber defence, but Filigran says security teams must keep humans in the loop as agentic AI spreads.
The update aims to cut review bottlenecks by auto-fixing vulnerable dependencies and surfacing code flaws scanners often miss.
Security teams can now trace how one SAP flaw could spread across finance, payroll and supply chains, with access tightly restricted.
Developers face earlier checks on risky open-source dependencies as AI coding tools speed up software assembly and raise supply chain concerns.
AI is speeding up attacks as well as defence, with high-risk prompts and unsupervised agents exposing firms to new security gaps.
Security checks will now cover more Arm processors, as the chip designer broadens use of Arteris' Radix tool to spot flaws earlier.
Boards face rising pressure to control shadow AI as attackers automate faster and security teams shift to continuous verification.
Pressure is mounting on companies to prove AI is governed in real time, as agentic systems take decisions and access sensitive data.
Malicious package advisories jumped from 21 in 2023 to 1,576 in 2025, as attackers increasingly target developers before code reaches production.
Boards must now treat cyber security and AI governance as core resilience issues, with Russian-linked threats exposing wider operational risks.
Smaller firms can now run web app pentests in hours, as Intruder's AI service cuts costs to a fraction of manual reviews.
Growing threats to UK critical infrastructure have pushed Siemens and NCC Group to join forces on protecting industrial systems from cyber attacks.
Breaches across New Zealand are increasingly exploiting human trust, with thieves using logins and one-time codes to steal data and funds.