#Supply Chain Security
All CosmicBytez Labs articles tagged #Supply Chain Security, across news, security advisories, how-to guides, and projects.
- News
Anthropic Turns Claude Into an AI Marketplace With 2,000+ Plugins and Connectors
Anthropic launched the Claude Marketplace with 2,000+ plugins, connectors, and partner agents, plus a submission portal for developers.
- News
Homebrew 7.0.0 Gets Built-In GUI, Better Security Controls
Homebrew 7.0.0 ships a native GUI (BrewUI), a built-in brew vulns scanner, and Landlock sandboxing in its biggest security release yet.
- HOWTO
Software Bill of Materials (SBOM) Generation with Syft and Grype
Generate a complete inventory of every package, library, and dependency in your containers and codebases with Syft, then scan that inventory for known...
- News
Chainguard Surpasses 1 Billion Container Build Manifests With Factory 2.0
Chainguard doubled its build volume to over 1 billion manifests in six months, powered by an automated factory rebuilding images at scale.
- News
Chainguard Doubles Output to 1 Billion Build Manifests in Six Months
Chainguard's container image factory doubled its rebuild output from 500 million to over 1 billion manifests, driven by a new agentic pipeline.
- Project
Container Supply Chain Security: SBOMs and Keyless Signing with Syft, Grype, and Cosign
Build a CI pipeline that generates SBOMs with Syft, scans them for vulnerabilities with Grype, and signs container images keylessly with Cosign — closing...
- News
Over 8,300 Gitea Servers Still Vulnerable to Active Code Execution Attacks
Shadowserver finds 8,300+ exposed Gitea instances unpatched against CVE-2026-60004, a critical RCE flaw already deploying cryptominers.
- Security
CVE-2026-66384: JFrog Artifactory Path Traversal Added to CISA KEV
CISA added CVE-2026-66384, a JFrog Artifactory Docker-cache path traversal flaw, to its KEV catalog after confirmed active exploitation.
- News
Semiconductor Chip Titan Analog Devices Reports Data Breach
Analog Devices, the $178 billion semiconductor giant, disclosed a data breach via SEC 8-K filing after unauthorized access was detected in June 2026....
- News
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
Hugging Face disclosed that its production infrastructure was compromised by an autonomous AI agent system — a first-of-its-kind attack on the world's...
- News
New Initiative Tackles Security for End-of-Life Open Source Software
The Open Source Sustainability Initiative launches to help enterprises manage and secure aging open source projects, addressing the growing compliance and...
- News
OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds
OWASP has launched CVE Lite CLI, a free open-source command line tool that scans software projects in seconds to identify packages with known CVE…
- News
The State of Secrets Sprawl 2026: 9 Takeaways for CISOs
GitGuardian's State of Secrets Sprawl 2026 report found 29 million new hardcoded secrets in public GitHub repositories in 2025 alone — a 34%...
- HOWTO
How to Secure GitHub Actions Workflows with OIDC, SHA
Harden your CI/CD pipeline by replacing long-lived secrets with OIDC short-lived tokens, pinning third-party actions to commit SHAs, enforcing...