search
software supply chain
Trends
- 1WordPress.org's forced takeover of ACF plugin sparks debate●Analisis pengambilalihan paksa plugin ACF oleh WordPress.org menjadi Secure Custom Fields. Dampak etika open source dan
WordPress.org took over the popular Advanced Custom Fields plugin and renamed it Secure Custom Fields, prompting analysis of the ethics of the move. Commenters are weighing the impact on open-source principles, trust between maintainers and repositories, and software supply-chain security for developers who rely on plugins distributed through WordPress.org.
- 2Frontline Education Breach Exposes K-12 Employee Data▼Frontline Education Data Breach 2026: Third-Party Software Vulnerability Exposes K-12 School District Employee Data
Frontline Education, a software provider serving US K-12 school districts, has reportedly suffered a data breach in which a vulnerability in third-party software exposed employee data across multiple districts. The incident raises renewed concerns about supply-chain security risks in education technology and the handling of sensitive staff information by vendors serving public schools.
- 3Bitget Hit by $387.5 Million Zero-Day Exploit Breach▼Bitget Cryptocurrency Exchange Breach: $387.5M Stolen via Zero-Day Exploit in Third-Party Security Products
Cryptocurrency exchange Bitget has reportedly been breached, with $387.5 million stolen through a zero-day exploit targeting third-party security products. The attack did not exploit Bitget's own systems directly but a vulnerability in software supplied by external vendors, raising fresh questions about supply-chain risk across crypto platforms. Analysts are warning exchanges to audit vendor security as details of the theft and recovery prospects remain limited.
- 4Experts call for broader Cybersecurity Awareness Month message▼Cybersecurity Awareness Month 2026 shouldn’t be reduced to “don’t click suspicious links.” Modern attacks now span the e
Cybersecurity professionals are arguing that Cybersecurity Awareness Month 2026 should not be reduced to the familiar advice of avoiding suspicious links. They say modern attacks now cover the full kill chain, including reconnaissance, credential theft, lateral movement, ransomware and data exfiltration, alongside AI-powered social engineering and software supply chain threats. The discussion is prompting calls for security education that reflects how sophisticated today's attack techniques have become.
- 5Value Chain Risk Institute sponsors JawnCon 0x3 at Arcadia University●The Value Chain Risk Institute is proud to sponsor JawnCon 0x3, October 16 to 18 at Arcadia University. JawnCon is what
The Value Chain Risk Institute is sponsoring JawnCon 0x3, a community-run cybersecurity conference taking place October 16 to 18 at Arcadia University. The nonprofit, which publishes open data on software supply chain risk, describes JawnCon as hands-on, welcoming, and run by practitioners passionate about their work.
- 6o9 Named a Leader in IDC Retail Planning MarketScape●o9 Named a Leader in the IDC MarketScape: Worldwide Retail Merchandise Financial Planning Solutions 2026 Vendor Assessment
o9 Solutions has been named a Leader in the IDC MarketScape assessment of worldwide retail merchandise financial planning solutions for 2026. The recognition places the supply chain and planning software firm among the top vendors serving retailers' merchandise financial planning needs. Industry watchers see it as a boost to o9's standing in the competitive retail technology market.
- 7Broadcom launches TrueSource to bolster open source security▼Broadcom Launches TrueSource to Strengthen Open Source Software Security
Broadcom has announced TrueSource, a new offering aimed at strengthening the security of open source software. The initiative is intended to help organisations identify and manage risks in the open source components they rely on. Details beyond the launch announcement are limited so far, and industry reaction is still developing.
- 8Chainguard launches Athena coalition against AI-driven open-source attacks●Chainguard launches Athena coalition to tackle AI-driven open-source software hacks
Chainguard has launched a coalition called Athena aimed at countering hacks targeting open-source software that are increasingly driven by artificial intelligence. The initiative brings partners together to address growing security risks in the open-source supply chain as AI makes attacks faster and more scalable. Details on members and specific programmes remain limited so far.