Lobsters · security·4d agoFifty Years of Open Source Software Supply Chain Security#open-source#supply-chain#software-supply-chainResearch
CyberScoop·15d agoResearchers say OpenAI agents were behind May hacking campaign targeting RubyGems#ai-agents#api-keys#malicious-packages in the wild 5 min2
arXiv cs.CR·18d agoMeasuring the Security of the Evolving Software Supply Chain: a Research Agenda#dependency-management#llm#measurementResearch
arXiv cs.CR·19d agoVEX-Bench: Benchmarking LLM Agents for Assessing Exploitability of Software Supply Chain Vulnerabilities#benchmark#exploitability#llm-agentsResearch1
arXiv cs.AI / cs.LG / cs.CL·19d agoDo AI Coding Assistants Check Before They Install? A Pre-Registered Demand-Side Audit of Trust Signals in the Research Software Supply Chain#ai-agents#coding-assistants#provenanceAI safety & security1
arXiv cs.CR·22d agoPropagation Model for SSC attacks: Why SBOM (tools) don't tell the whole truth#log4j#sbom#software-supply-chainResearch1
Help Net Security·23d agoMost of the bugs Claude Mythos found have never been checked by a human#ai#anthropic#benchmark 3 min
Checkmarx·Aug 26, 2026The Regulators Already Assume You Have an AI Inventory. Do You?#ai-governance#ai-inventory#compliance1
Infosecurity Magazine·Aug 18, 2026Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities#enterprise-software#report#software-supply-chainIndustry
Wiz Blog·Aug 13, 2026Closing the Blind Spot: Securing Personal Repositories in the Software Supply Chain#code-repositories#developer-security#secrets-management2