Articles Tagged “Supply Chain Security”
5 articles found

Securing AI Coding Agents in CI: A Hardening Guide
Black Hat 2026 showed a single GitHub issue could reach CI secrets. Here are seven hardening steps for AI coding agents, plus the patched version numbers.

NVIDIA SkillSpector Scans AI Agent Skills for Risk
NVIDIA's open-source SkillSpector checks AI agent skills for 64 vulnerability patterns before install, scoring risk 0-100 and exporting SARIF for CI.

CISA C4 Framework Scores Open Source Project Trust
CISA's new 35-page open source security guide introduces the C4 Framework — Code, Community, Controls, Continuity — plus SBOM and open AI model practices.

SkillDetonate Catches Malicious AI-Agent Skills That Slip Past Scanners
Researchers released SkillDetonate on July 6, 2026 — a runtime auditor that sandboxes AI-agent skills and caught 97% of malicious ones static scanners miss.

GlassWorm Returns With a Second Wave — The Supply Chain Attack Expands From GitHub to npm Packages and VSCode Extensions
The invisible Unicode malware campaign that hit 151 Python repos has evolved, with security researchers detecting coordinated injections across npm, GitHub, and VSCode/OpenVSX extension marketplaces.
