MikeTrendsTrends right now

search

software supply chain

Trends

  1. 1
    Lenovo Flaw Exposed 5,000 Dropbox Accounts▼Lenovo Flaw Exposed 5,000 Dropbox Accounts Through Identity Federation✉newsTechnologyCybersecurity2 d ago

    A security flaw in Lenovo's systems reportedly exposed around 5,000 Dropbox user accounts through identity federation, according to Cybersecurity Insiders. The vulnerability allowed credentials linked across federated identity services to be put at risk, raising fresh questions about how large enterprises secure single sign-on integrations with third-party cloud services.

  2. 2
    US Arrests Oxygen Forensics Executives Over Alleged Russian Ties●U.S. arrests executives of Oxygen Forensics, accusing them of concealing that the company was controlled by Russian andMmastodonTechnology34 d ago

    United States authorities have arrested executives of the forensics software firm Oxygen Forensics, charging them with concealing that the company was controlled by Russian interests and that its software was developed in Russia. The case is drawing attention because the firm's tools are reportedly used by law enforcement and security agencies, raising questions about undisclosed foreign control in sensitive technology supply chains.

  3. 3
    Nvidia Releases AI Safety Software After Hugging Face Hack●Nvidia releases AI safety software it says could have stopped Hugging Face hack https:// lemmy.world/post/52464191MmastodonTechnology12 d ago

    Nvidia has released new AI safety software that the company says could have prevented the recent breach of AI platform Hugging Face. The announcement ties the product directly to that incident, positioning it as a safeguard against similar supply-chain attacks on machine learning infrastructure. Discussion so far is limited to early sharing of the news among technology communities.

  4. 4
    CodeSupply Launches R&D Grants for Open-Source Software Security▼CodeSupply Announces R and D Grants for Open-Source Software Security✉newsTechnologySoftware5 h ago

    CodeSupply has announced a new research and development grant programme focused on open-source software security. The initiative will fund projects aimed at improving the safety and resilience of open-source code, an area of growing concern following high-profile supply chain vulnerabilities. Details on grant sizes, eligibility and deadlines have not yet been widely reported.

  5. 5
    Manifest Joins Chainguard's Athena Coalition on Open-Source Risk▼Manifest Joins Chainguard's Athena Coalition to Find Open-Source Risk Inside Software Products✉newsTechnologySoftware1 d ago

    Manifest has joined Chainguard's Athena Coalition, an initiative aimed at identifying open-source software risk inside commercial software products. The announcement was carried by Business Wire and picked up by outlets including Yahoo Finance. The coalition brings companies together to improve visibility into the open-source components embedded in software supply chains, a growing concern after a series of high-profile supply chain attacks.

  6. 6
    Legit Security launches agentic remediation for open-source vulnerabilities▼Legit Security launches agentic remediation for open-source dependency vulnerabilities✉newsTechnologySoftware57 min ago

    Legit Security has introduced an agentic remediation capability that automatically addresses vulnerabilities in open-source dependencies. The tool is aimed at helping development teams fix risky software supply chain components faster, reducing manual work in patching and dependency management. The announcement reflects a broader industry push toward AI-driven automation in application security.

  7. 7
    Finastra launches SCF platform to speed bank supply chain finance●Finastra SCF aims to speed up bank supply chain finance✉newsBusinessFinance2 d ago

    Finastra has introduced SCF, a software solution designed to help banks deliver supply chain finance faster. The product is aimed at streamlining how financial institutions offer financing to businesses across their supply chains, reducing processing times and operational friction. Details on pricing, launch partners and customer adoption were not included in the initial announcement.

  8. 8
    Poland healthcare hit by second vendor breach in a month▼Poland's healthcare sector has been breached twice in a month, and both times the way in was a software vendor. First MyMmastodonTechnologyCybersecurity41 d ago

    Poland's healthcare sector has suffered two data breaches in a single month, both traced to software suppliers. The first, at vendor MyDr, may affect up to 19 million people. The second involves Qbusoft, where an SQL injection flaw in its Medyc platform exposed names, addresses, PESEL national identity numbers and medical records. Cybersecurity commentators are highlighting the supply-chain risk posed by third-party healthcare software.

  9. 9
    OpenInfra Europe's JFrog Artifactory breached, packages may be compromised▼OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised✉newsTechnologySoftware59 min ago

    Attackers breached OpenInfra Europe's JFrog Artifactory instance, the repository used to store and distribute software packages. Because such repositories serve code directly to developers, any packages stored there could have been tampered with, raising the risk of supply chain attacks. The incident is drawing attention as organisations assess whether they downloaded affected artifacts.

  10. 10

    Logistics software firm Banyan Technology has introduced artificial intelligence tools that predict when freight shipments will arrive late, giving shippers advance warning before delays happen. The system analyzes freight transportation data to flag at-risk deliveries early. Industry coverage in logistics publications highlights the growing use of predictive AI in supply chain management.

  11. 11
    Hyundai Mobis Backs Localization of Automotive Chips and SDV Shift▼Hyundai Mobis Supports Localization of Automotive Chips, SDV Transition✉newsTechnologySemiconductors10 h ago

    Hyundai Mobis is working to support the localization of automotive semiconductors and the industry's transition to software-defined vehicles (SDVs). The South Korean auto parts maker is positioning itself to reduce reliance on imported chips while adapting its components business to vehicles increasingly controlled by software. The move aligns with broader efforts in Korea's auto supply chain to secure chip supplies and keep pace with the SDV transition reshaping the sector.

  12. 12
    ASUS confirms security breach involving customer data▼News - ASUS confirms security breach involving customer data✉newsTechnologyCybersecurity21 h ago

    ASUS has confirmed that it suffered a security breach involving customer data. The Taiwanese computer maker acknowledged the incident, though details on the scale of the breach, the type of data affected, and the number of customers impacted have not been fully disclosed. The confirmation is drawing attention from cybersecurity watchers concerned about hardware and software supply chains.

  13. 13
    OpenSSF Scorecard flags package risks before advisories exist●Most dependency scanners only tell you about vulnerabilities that already have an advisory filed... # opensource # securMmastodonTechnologySoftware32 h ago

    Security commentators are highlighting a blind spot in common dependency scanners: they only catch vulnerabilities once a formal advisory has been filed. OpenSSF Scorecard is being promoted as a complementary tool, assessing open-source packages for risky practices and structural weaknesses before any advisory is published, giving developers an earlier warning signal about the software they rely on.

  14. 14
    Flexport Launches AI Agent Tools for Global Freight▼Flexport Launches Technology to Let AI Agents Book, Track, and Optimize Global Freight✉newsTechnology1 d ago

    Logistics company Flexport has announced new technology that allows AI agents to book, track, and optimize global freight shipments. The move positions the freight forwarder at the forefront of agentic AI adoption in supply chain management, letting autonomous software handle tasks traditionally managed by human logistics teams.

  15. 15
    Ex-Tesla team raises $12.5 million to automate supply chains▼Exclusive: Ex-Tesla team raises $12.5M to put supply chains on autopilot✉newsBusinessStartups1 d ago

    A startup founded by former Tesla employees has raised $12.5 million to build software that automates supply chain management. The company, which emerged from a team with experience in Tesla's operations, aims to put supply chains 'on autopilot' by reducing manual work in logistics and procurement. The funding round was reported exclusively by TechCrunch, drawing attention to growing investor interest in supply chain automation among former Tesla operators.