Chainguard Repository adds new policies, Chainguard Libraries for JavaScript is GA
Chainguard Repository adds malware and greyware scanning, expanded policy controls, and visibility to secure AI-driven software supply chains.

4276 articles
4276 ARTICLES
Chainguard Repository adds malware and greyware scanning, expanded policy controls, and visibility to secure AI-driven software supply chains.


Get the details on everything Chainguard announced during AI Readiness Innovation Week, including new features for Chainguard Libraries and Chainguard Containers

Wiz now scans Chainguard Libraries for Python and Java, combining trusted, source-built dependencies with risk-based visibility and remediation.

NIST’s shift to risk-based enrichment makes one thing clear: modern security teams need more than a single public source. In the AI era, trusted vulnerability intelligence depends on multiple signals, human validation, and clear context.

Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA codes, email messages, meeting details, and private organizational files — with a single click. Varonis Threat Labs has uncovered a new three-stage vulnerability chain that turns Microsoft 365 Copilot Enterprise Search into a silent data exfiltration weapon. Dubbed SearchLeak, the chain combines a relatively new class

Amazon Web Services (AWS) recently announced support for resource-based policies and resource control policies (RCPs) for AWS Sign-In. By using resource-based policies and RCPs, you can restrict access to the AWS Management Console sign-in and aws login CLI sessions to requests from your expected networks, your on-premises data center networks, and your Amazon Virtual Private

Learn how CNAPP platforms are helping organizations prioritize exploitable risks, reduce exposure, and operationalize security across the application lifecycle. The post CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms appeared first on Microsoft Security Blog.

Machine learning models are not like other software artifacts. A single fine-tuned LLM can weigh 70 GB. A model family may share 95% of its weights across dozens of variants. When hundreds of developers, training jobs, and GPU clusters all need the same model at the same time, the infrastructure underneath needs to be built

For years, organizations approached SaaS security as an access management problem. Enable SSO. Turn on MFA. Provision users correctly. Deprovision them quickly. Audit permissions periodically. That model no longer reflects how modern SaaS breaches actually happen. The recent ADT breach attributed to the ShinyHunters extortion group demonstrates why. According to reports, attackers allegedly compromised an employee’s Okta account through a voice phishing attack and used that foothold to…

The regulatory landscape for AI is shifting rapidly between evolving federal policies, an explosion of state-level legislation, and the emergence of industry-specific compliance requirements. Many organizations know they need AI governance but may face uncertainty about how to navigate the evolving landscape. The most forward-thinking companies aren’t waiting for regulatory clarity, they’re building governance frameworks now that will position themselves to adapt and comply with whatev…

Most security teams evaluate Claude Cowork as if it were a chatbot with extra buttons. It isn’t. Cowork is a local agent that runs on the employee’s machine, reads their files, runs shell commands, browses the web with their logged-in cookies, and connects to the enterprise systems they can reach. As Anthropic frames it, when something goes wrong, the impact depends on what Claude can read and what Claude is allowed to do. That changes the threat model. A prompt injection against a ch…

Most organizations operate across complex digital ecosystems that include cloud providers, SaaS platforms, API integrations, and outsourced infrastructure. While these technologies enable scalability and operational efficiency, they also introduce additional security considerations. As vendor networks expand, security and procurement teams often encounter lengthy due diligence processes, repetitive security questionnaires, and limited visibility into third-party risks. Managing tra…
Cookies
We use analytics cookies (Google Analytics) to improve this site. Accept to allow them. Privacy Policy