KEDB #001 — Nx Console Supply Chain Attack: Four Lessons for CISO Teams
In May 2026, the VS Code extension Nx Console 18.95.0 was compromised and stole developer credentials en masse via auto-update; this KEDB entry draws four lessons for CISO teams: uncontrolled extension trust chains, auto-update as a double-edged sword, token hygiene, and build pipeline isolation — with concrete action
AI Omnibus: What the EU Agreement of 7 May 2026 Actually Changes
The EU Council and Parliament reached a political agreement on 7 May 2026 on the so-called AI Omnibus package, sharpening definitions of providers and deployers, deferring certain deadlines by six to twelve months, and adjusting high-risk thresholds; criticism from EDPB and EDPS was softened but not fully resolved.


