Tag: Supply Chain
-

The Honest State of Open Source Security in 2026
Open source security in 2026 has matured, with the SCA tools, the SBOM standards, the SLSA framework, the supply chain attestation, the package signing, the major platform support. The state of the open source security in 2026 amounts to the state of a market that has the tooling, the standards, the platform support, the adoption…
-

Open Source Is Holding Up the Internet, and Most Companies Don’t Even Know It
The internet runs on open source. Not metaphorically, literally. The TLS that secures your bank’s website, the kernel that runs most of the cloud, the package manager that built the app on your phone.
-

A Field Guide to the Supply Chain Attack
The supply chain attack in 2026 sits as the dominant attack pattern in the typical enterprise breach, with the attacker compromising the vendor, the vendor distributing the malicious update, the enterprise installing the update, the enterprise getting breached. The SolarWinds, the 3CX, the xz utils near miss, the 2024 Snowflake credential theft, all the same…
-

2026: The Mid Year Cybersecurity Review
Halfway through 2026, the threat landscape has done the usual thing of mutating faster than the people defending it expected. The first half gave us three patterns worth noticing: supply chain attacks still lead, identity attacks crossed a threshold, and AI became both a weapon and a target.
-

Open Source Funding in 2026: The State of the Money
Open source funding in 2026 is no longer the GitHub Sponsors and Patreon era. The money is now flowing through corporate sponsorship, foundation grants, government programs, and the new crop of open source startups that have figured out how to charge for the service without charging for the code. The state of the money in…
-

Supply Chain Attacks: When the Software You Trust Is the Problem
Traditional security assumes the dangerous code arrives from somewhere obviously untrusted. Supply chain attacks invert that model. The malicious component may arrive through a signed update, a trusted maintainer, or a dependency your team never knew it was running.
-

A Field Guide to the Secure Code Review
A field guide to the secure code review in 2026, with what the review actually catches, what the review is going to miss, and the right way to set up a review programme that scales without burning out the engineering team.
-

Why the Supply Chain Attack Keeps Winning
The supply chain attack keeps winning because defenders optimise for the wrong layer. Here is what actually works, in 2026, against the upstream dependency, the build pipeline, and the signed vendor update.
-

The Real Cost of the Data Broker Economy
Your personal data is in roughly 4,000 databases you have never heard of. The data broker economy is the market that buys it, packages it, and resells it. Here is what is actually happening, and what the cost really is.
-

Malware in the Open Source Supply Chain Is Now the Default
The malicious npm package, the typosquatted PyPI release, the compromised Docker image. The pattern has matured. The frequency has increased. The defence has not kept up.