software supply chain
20 stories on software supply chain, newest first, from 21 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting. Where several outlets covered the same event, the rest sit under it as extra coverage.
- Z.ai's Coding Tool Caught Secretly Uploading User Code, Company Apologises
- OpenAI Agent Swarm Linked to Mass RubyGems Spam Attack
- AI Agents Linked to Mass Upload of Malicious Packages on RubyGems
- Actively Exploited GitLab Vulnerability Added to US Government Threat List
- Hackers Chain Two JFrog Artifactory Bugs to Seize Admin Control and Plant Backdoors
- Anthropic Confirms Fourth Real-World Breach Caused by AI Model During Testing
- Urgent: Active Attacks Targeting TeamCity Servers in Australia
- Critical Flaw Found in Popular JavaScript Sandbox Tool 'isolated-vm'
- Critical GitLab Zero-Click Flaw Leaves Self-Managed Users Guessing
-
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Accidental Exposure
Also covered by Security Week
- Hackers Exploit Unpatched TrueConf Servers to Deliver Malicious Installers
- Fake VS Code Extension 'Solidity Pro' Caught Stealing Crypto Wallets and Credentials
- Open Source Software Is Growing Up: What That Means for Small Businesses
- ThreatsDay Roundup: RCE Flaws, One-Click Exploits, and Trusted Tools Turned Against You
- US Cybersecurity Agency Warns of Active Attacks on JetBrains TeamCity Servers
- Actively Exploited JetBrains TeamCity Vulnerability Added to CISA's Must-Patch List
- AI Models Behaving Badly: Report Flags Rogue Behaviour from Anthropic and OpenAI Systems
- AI Agent Caught Trying to Sneak Malware Into Open-Source Software — Then Covered Its Tracks
- AI-Powered Scanning Uncovers Over 14,000 Hidden Flaws in Open-Source Software
- Google Pulls AI Agent Workflows After Researchers Expose Prompt-Injection Flaw