CMOtech UK - Technology news for CMOs & marketing decision-makers

Supply Chain Security stories

Flux result b0e7cc49 91ef 4484 ba46 cdb3c997b1bf

Claude Code can leak secrets in public npm packages

Today
#
data protection
#
application security
#
devsecops
Check Point says Anthropic's Claude Code can quietly stash credentials in .claude/settings.local.json, which may be published in public npm packages.
Flux result dd4e24eb d611 436e 8eee 5f94a368885c

LevelBlue warns of GhostOps risk from rogue AI agents

Today
#
data protection
#
digital transformation
#
cloud security
LevelBlue says unsanctioned AI agents are slipping into enterprise systems, creating a hidden governance and security blind spot for businesses.
Email attachment20260423 2863807 yrappg

Google Cloud unveils AI security tools & fraud defence

Today
#
firewalls
#
data protection
#
hyperscale
Google Cloud expands AI security with new agents, Wiz integrations and fraud defences as it targets faster, more automated cyber attacks.
Email attachment20260423 2618626 mv2m7k

Cambridge Wireless unveils 2026 conference on AI & security

Today
#
robots
#
uc
#
firewalls
Cambridge Wireless sets out a 2026 conference agenda spanning AI, cyber resilience, quantum networking and industrial automation.
Flux result 98c90454 e22b 40d3 87b0 b943c20a210c

Zscaler joins Anthropic Project Glasswing on cyber AI

Yesterday
#
firewalls
#
vpns
#
network security
Zscaler joins Anthropic's Project Glasswing to test Claude Mythos Preview in software scans, as the firm pushes zero trust against AI-driven attacks.
Flux result ad42d32c 7135 4932 a4cb b35aca0c1391

HackerOne launches h1 Validation to tackle AI flaws

Yesterday
#
devops
#
digital transformation
#
application security
HackerOne unveils h1 Validation as vulnerability reports surge 76% and AI tools speed up discovery, leaving firms struggling to triage real threats.
Flux result ebf65211 8555 4f44 8fa9 1d2df642919d

CIS launches AI security guides for models & agents

Yesterday
#
digital transformation
#
application security
#
physical security
CIS, Astrix and Cequence publish AI security guides for large language models, autonomous agents and MCP environments.
Email attachment20260422 2057652 b8k57y

SUSE launches AI Factory with NVIDIA for enterprise control

Yesterday
#
virtualisation
#
private cloud
#
devops
SUSE and NVIDIA unveil an enterprise AI stack aimed at regulated sectors, offering on-premise control, governance and sovereignty for production use.
Flux result f2267c48 0574 4902 827d 0f5954093a18

Chainguard & Cursor tackle AI code supply chain risks

Yesterday
#
devops
#
application security
#
devsecops
Chainguard and Cursor strike partnership to embed verified open source dependencies into AI coding, aiming to curb supply chain risks at machine speed.
Flux result 5b734eba 1444 4464 96e8 27cf5fa2f10a

Tenable flags Microsoft GitHub workflow flaw exposing code

Yesterday
#
devops
#
cloud security
#
application security
Tenable warns a GitHub Actions bug in Microsoft's Windows-driver-samples repo could let attackers run code and steal secrets via public issues.
Flux result 6b26a2e2 5d79 46e4 8f95 9bdff4bac76b

BlackBerry survey flags secure messaging gaps in government

Yesterday
#
data protection
#
encryption
#
mdm
BlackBerry survey finds government and infrastructure security chiefs relying on WhatsApp for sensitive talks despite major misunderstandings over encryption.
Flux result 1449a80a d271 47ab a1ef 916b32f14374

AI vulnerability discovery forces boards to rethink cyber risk

Yesterday
#
data protection
#
application security
#
iam
AI models that can hunt and chain software flaws are forcing boards to rethink cyber defences, while scrutiny grows over Anthropic's MCP design risks.
575

Cyber Scheme launches company accreditation programme

2 days ago
#
devops
#
iot security
#
socs
Cyber Scheme extends professional standards to firms with new company accreditation backed by UK council benchmarks and procurement access.
Flux result 808b973b 89ac 4abe 9c99 1ff6fe4ed0a5

LangWatch launches open-source tool for AI red-teaming

2 days ago
#
data protection
#
devops
#
data analytics
LangWatch releases open-source AI red-teaming framework to expose hidden vulnerabilities in production agents through multi-turn attack simulations.
Flux result 6b2914cf d0e4 4149 91cd 5329a22168ef

Proofpoint tracks cargo theft gang's post-breach tactics

2 days ago
#
endpoint protection
#
iot security
#
advanced persistent threat protection
Proofpoint says a cargo theft gang spent weeks inside a decoy network, probing banking, fleet payment and load board systems for fraud.
Flux result cbfa8703 77de 42c6 b26d 0085048d5349

Sysdig report says cloud security shifts to machine speed

3 days ago
#
digital transformation
#
pam
#
cloud security
Sysdig says companies are increasingly leaning on automated defence as AI-driven attacks accelerate, with machine identities now dominating cloud access.
Rishi

Mythos changes everything: Is your AI agent security ready?

3 days ago
#
firewalls
#
data protection
#
dr
Anthropic's Mythos spots corporate network attacks in hours, while security experts warn unmanaged AI agents are becoming a critical enterprise risk.
Flux result 648d1b86 1387 4d26 9306 60913d8cb5e6

FIRST conference highlights AI & CVE disclosure push

Last week
#
iot security
#
application security
#
supply chain
FIRST conference in Scottsdale draws 500-plus as security leaders and AI firms debate vulnerability disclosure, CWE's role and CVE's future.
Flux result b9088d52 ffc8 48b1 a485 cd96e7c6e378

OpenAI launches Trusted Access for Cyber with major names

Last week
#
firewalls
#
network security
#
cloud security
OpenAI expands Trusted Access for Cyber with Bank of America, BlackRock and others, backing defenders, researchers and open-source security teams.
Flux result 5c0ac3f7 bc8e 43da 945e f01ba9cf9f37

GitLab 18.11 adds AI agents for security & pipelines

Last week
#
devops
#
application security
#
devsecops
GitLab 18.11 rolls out AI agents for security remediation, pipeline setup and delivery analytics, plus new spending caps on GitLab Credits.