Related Threat Clusters
-
AI Coding Agents Expand Software Supply Chain Risks
AI coding agents are introducing significant vulnerabilities into the software supply chain by selecting insecure dependencies without human oversight. Research indicates that only 20% of dependency versions recommended…
7 articles · Updated July 27, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
743 articles · Updated April 29, 2026 -
Chainguard Libraries for Java Launches CVE Remediation for Legacy Vulnerabilities
Chainguard has announced the general availability of Chainguard Libraries for Java, which includes CVE remediation for critical and high-severity vulnerabilities in the Spring Boot ecosystem. This initiative addresses…
2 articles · Updated June 24, 2026 -
TeamPCP Supply Chain Attack Compromises Databricks Platform
Databricks is investigating a potential security compromise linked to the TeamPCP supply chain attack. This incident follows a notification from International Cyber Digest, which indicated that Databricks was alerted…
4 articles · Updated March 30, 2026 -
Chainguard Partners with AWS Security Hub to Enhance Supply Chain Security
On August 4, 2026, Chainguard announced its partnership with AWS Security Hub Extended to provide enhanced supply chain security for AWS customers. This partnership allows users to access Chainguard Libraries, which…
6 articles · Updated August 5, 2026 -
Chainguard and Cursor Enhance Security for AI-Driven Software Development
Chainguard and Cursor have partnered to improve security in agentic software development by providing secure-by-default open source artifacts. This collaboration aims to close the software supply chain trust gap, as 84%…
3 articles · Updated April 21, 2026 -
Open Source Registries Face Financial Crisis Impacting Security Features
Open source registries are experiencing significant financial difficulties, which are hindering their ability to implement essential security measures. Michael Winser, co-founder of the Alpha-Omega project under the…
4 articles · Updated February 16, 2026 -
Malware Campaign Targets Maven Central via Jackson JSON Library Impersonation
A malware campaign has infiltrated Maven Central by impersonating a legitimate Jackson JSON library extension. The malicious package was published under the org.fasterxml.jackson.core/jackson-databind namespace, marking…
2 articles · Updated December 30, 2025 -
Sonatype Study Reveals AI Models Require Real-Time Intelligence for Safe Software Recommendations
Sonatype's research published on March 24, 2026, indicates that larger AI models alone do not yield the safest software dependency recommendations. The study assessed approximately 37,000 open source upgrade…
3 articles · Updated March 24, 2026 -
Sonatype Launches Nexus One for Software Supply Chain Security
On November 19, 2025, Sonatype announced the launch of Nexus One, a software supply chain infrastructure designed to unify open source intelligence, governance, and automation in enterprise software development. The…
2 articles · Updated November 19, 2025
Recent Intelligence Reports
- Chainguard Libraries — edge.prnewswire.com · August 5, 2026
- Supply Chain Security in the Agentic Era — Augmentcode · July 27, 2026
- Focusing on Vulnerability Prioritization Is Missing the AI-Era Point — Sonatype · July 1, 2026
- Chainguard targets Java's unpatched vulnerability backlog with drop — Thenewstack · June 24, 2026
- Chainguard And Cursor Partner To Secure Agentic Coding With Trusted Open Source 302748112 — www.prnewswire.com · April 21, 2026
- Risks, emerging when developing or using open-source software — Kaspersky · April 2, 2026
- TeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, (Mon, Mar 30th) — Isc.Sans.Edu · March 30, 2026
- Sonatype Finds AI Grounded in Intelligence Delivers Safer Outcomes — Sonatype · March 24, 2026