CISA expands SBOM minimum elements with new data fields such as hash values, licenses, and author signatures to enable organizations better software supply chain transparency.
Classical perimeter security is insufficient for AI-powered infrastructures; the network must become an active control instance for AI-specific threats.
Three critical VMware vulnerabilities (CVSS 9.3–9.8) enable authentication bypass, remote code execution, and VM escape; Broadcom recommends immediate patching as no workarounds are available.
Nvidia’s open-source-focused AI security initiative is criticized for allowing manufacturers to decentralize responsibility while keeping control centralized.
Laundry Bear exploits a half-click vulnerability in Outlook to compromise email inboxes of European and North American targets without requiring conscious user action.
Security architectures must realign: agents require unique identities, strict access controls over models, data, and tools, plus central control points – otherwise uncontrollable shadow IT emerges with significant abuse potential.