CISA’s expanded SBOM guidance increases data collection requirements, but fails to address the core challenge of converting SBOM data into operational risk mitigation.
CISA expands SBOM minimum elements with new data fields such as hash values, licenses, and author signatures to enable organizations better software supply chain transparency.
The CRA requires manufacturers from September 2026 onwards to report actively exploited vulnerabilities, demanding full transparency on machine identities and secrets in the supply chain earlier than the December 2027 deadline.
Supply chain protection becomes a strategic priority – organisations must involve third-party providers on a least-information basis and integrate their control mechanisms into their cyber-resilience strategy.
Dependabot will now wait three days by default after a new package release before automatically creating pull requests — the cooldown is configurable in dependabot.yml.
Google and Microsoft pulled the 1.6-million-times-installed header-editing extension ModHeader after researchers discovered a dormant browsing-history-collector component.
Autonomous AI code scanners can be tricked by seemingly legitimate instructions in README files to execute malware without triggering classical security checks.