AI & software security
-
Claude Code alert becomes trust test
China’s warning over Claude Code should be treated as a disputed product-security and geopolitical trust story, not a confirmed backdoor case.
-
Fake payment SDKs target developer secrets
Malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs show how payment-brand trust is being used to reach developer credentials and cloud tokens.
-
OpenMandriva case exposes maintainer risk
OpenMandriva says it faced attempted distribution sabotage, putting maintainer privilege, repository control, and recovery discipline back into software supply chain focus.
-
Estonia puts identity around AI agents
Estonia’s plan to create digital identities for AI agents turns machine identity, delegated authority, and auditability into a public-sector governance issue.
-
Rubrik makes London EMEA headquarters
Rubrik plans to invest more than $500 million in the UK and make London its EMEA headquarters, linking the move to cyber recovery, sovereign cloud, and AI resilience.
-
NCSC sets out Cyber Shield plan
The NCSC and DSIT are developing Cyber Shield, a proposed national-scale approach to agentic AI cyber defence for critical UK networks and wider resilience.
-
EDPB tightens AI scraping rules
The European Data Protection Board has adopted guidance on anonymisation, generative AI web scraping, and blockchain data processing, sharpening compliance expectations for data-intensive systems.
-
ENISA warns on frontier AI cyber pressure
ENISA says frontier AI could compress vulnerability and patch cycles, forcing European authorities, providers, and defenders to adapt cyber resilience to machine-speed threats.
-
ECB gives banks AI cyber deadline
Eurozone banks have until 31 October to submit AI cyber action plans, with supervisors tying frontier AI risk to DORA, patching, exposed assets, suppliers, and board accountability.
-
Ransomware groups target software supply chains
Sophos researchers say Vect and TeamPCP have linked supply chain credential theft with ransomware deployment, putting developer ecosystems in the extortion path.









