FedRAMP compliance in weeks, not months ⚡
Ready-to-deploy policy packs for instant compliance feedback 📋

FedRAMP compliance in weeks, not months ⚡
Ready-to-deploy policy packs for instant compliance feedback 📋
False positives killing your team's productivity? 😵💫
Anchore Secure gives you signal, not noise 📡
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
A malicious Tensorlake release runs on installation, before a developer uses it.
Aikido says it seeks credentials and can spread to other projects.…
Tensorlake version 0.5.144 contained Shai-Hulud, designed to steal access credentials and spread through packages a user could publish.
The releas…
Security is an important shift in how we think about CI/CD pipelines. Hardening the pipeline is critical, but security cannot stop when the deployment finishes, because vulnerabilities are found every day. This is the Gap that Ortelius fills. #SDLC #softwaresupplychain https://cstu.io/a749b8
Security is an important shift in how we think about CI/CD pipelines. Hardening the pipeline is critical, but security cannot stop when the deployment finishes, because vulnerabilities are found every day. This is the Gap that Ortelius fills. #SDLC #softwaresupplychain https://cstu.io/a749b8
Shift-left compliance checking ⬅️
Catch violations before deployment, not during audits 🛡️
Stop relying on annual audits to prove your security works.
With Armornet, every block and allow is logged as evidence for your risk register.
We rank vendors by what they actually ship. Every decision, measured.
Request Alpha: armornet.io
Anchore SBOM Score = CVSS + EPSS + KEV status 📊
Because not all vulnerabilities are created equal ⚠️
https://anchore.com/platform/sbom/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
Ein fehlendes Package stoppt Releases. Single Source plus Lockfiles machen Builds belastbarer. lunaris.digital/blog/article... #devops #softwaresupplychain
Blog post about what I think is a much more realistic AI cybersecurity problem than the usual “AI will hack everything” narrative:
paolozaino.wordpress.com/2026/09/21/a...
#AI #CyberSecurity #SoftwareSupplyChain #AISecurity #AppSec #LLM #Security #SoftwareEngineering #OpenSource
SBOM-first isn't just a buzzword—it's the architecture that makes continuous security actually possible 🔄
Feel the difference ⚡
@broadcom.bsky.social Strengthens Spring Security and Adds Coverage of Java, Python, and Node.js Ecosystems with TrueSource
techlensmedia.com/news/broadco...
#Broadcom #TrueSource #SpringEnterprise #OpenSourceSecurity #SoftwareSupplyChain #EnterpriseSecurity #TechLensMedia
🎉 Excited to share that our paper "VEX-Bench: Benchmarking LLM Agents for Assessing Exploitability of Software Supply Chain Vulnerabilities” has been accepted to EMNLP 2026!
📄 Paper: arxiv.org/abs/2609.08040
#EMNLP2026 #AI #LLM #LLMAgents #Cybersecurity #SoftwareSupplyChain #OpenSource #RedHat
Shift-left compliance checking ⬅️
Catch violations before deployment, not during audits 🛡️
Supply chain attacks ↗️ 742% in 2023
Your traditional security stack wasn't built for this fight.
SBOM-first architecture changes everything ⚡