Navigating fragmenta…
thinktankcalendar.com/event/ca2ff1...
#Global #SupplyChainSecurity #TradePolicy

Navigating fragmenta…
thinktankcalendar.com/event/ca2ff1...
#Global #SupplyChainSecurity #TradePolicy
⏱ We flagged pypi [email protected] 8 hours before the public advisory landed (MAL-2026-17712).
AI agent skills deserve code-review energy. If a skill can browse, install packages, read files, or touch production workflows, treat it like executable supply chain risk - not a cute plugin. Scan before you trust. #AIAgents #SupplyChainSecurity
⏱ Caught early: npm @xayz/[email protected] was on our radar 53 days before MAL-2026-17384 went public.
📊 In the last day: 31 malicious packages caught across npm, a median 12 days ahead of the public advisory. We were first on 41%.
The session continued with Mahmod & Hicks's "Retain The Date: Detecting Recycled Chips in the Supply Chain through SRAM's Data Retention Behavior" on detecting recycled ICs via SRAM aging, reaching 97% accuracy. (www.acsac.org/2025/p...) 5/6
#SupplyChainSecurity #RecycledICs
Malware is now querying smart contracts to hide C2 domains—supply chain security risks just got smarter with Web3. #Web3 #SupplyChainSecurity #BlockchainC2 #Malware #CloudSecurity https://thedailytechfeed.com/hackers-turn-public-blockchains-into-stealth-c2-hubs-in-supply-chain-attacks/
Learn more and apply today: www.sovereign.tech/programs/res...
#OpenSource #PotatoSecurity #SupplyChainSecurity #PotatoResilienceAct
Learn more and apply today: www.sovereign.tech/programs/res...
#OpenSource #CyberSecurity #SupplyChainSecurity #CyberResilienceAct
⏱ Caught early: npm @ikyyjee/[email protected] was on our radar 31 days before MAL-2026-17357 went public.
A Gitea security update fixes 27 flaws, including SSRF bug CVE-2026-101027 and SSH key flaw CVE-2026-103059. Upgrade to Gitea 28.1.0 now.
#Gitea #Git #DevSecOps #SSRF #CVE2026101027 #CVE2026103059 #SupplyChainSecurity #Vulnerability
⏱ 57 days of lead time on npm @badzz88/[email protected]: we flagged it, then MAL-2026-17341 confirmed it.
📊 In the last day: 11 malicious packages caught across npm and pypi, a median 49 days ahead of the public advisory. We were first on 64%.
The Security Angle
🏢 Freight fraud and double-brokering cost carriers nearly $1 Billion last year.
🔗 Book Demo Today! calendly.com/bidciti-com/...
🌐 Platform: bidciti.pro/Dispatch
#FreightWaves #LogisticsTech #SupplyChainSecurity #USAFreight #DispatchSoftware #BidCiti
📈 This week npm was the most-targeted ecosystem we saw: 246 malicious packages caught, a median 4 days before their public advisories.
⏱ 49 days of lead time on npm [email protected]: we flagged it, then MAL-2026-17404 confirmed it.
🚨 Critical TeamCity vulnerability now being exploited by ransomware groups. CVE-2026-63077 CVSS score of 9.8.
#Cybersecurity #Ransomware #DevSecOps #TeamCity #JetBrains #CICD #SupplyChainSecurity #VulnerabilityManagement #SoftwareSecurity #CloudSecurity
Critical Minerals & the G2…
thinktankcalendar.com/event/f41681...
#Commodities #Global #SupplyChainSecurity
📊 In the last day: 1 malicious package caught across pypi, ahead of the public advisory. We were first on 6%.
⏱ 46 days of lead time on npm [email protected]: we flagged it, then MAL-2026-17444 confirmed it.