AI & software security
-
FCA warns agentic AI could scale financial crime
The FCA’s 2026 horizon scan warns that agentic AI could automate fraud, phishing, vulnerability discovery, synthetic identities, and market manipulation.
-
NCSC warns software dependencies are becoming attack paths
The NCSC has warned that compromised open source packages can carry malware through dependency chains, software builds, and automated deployment pipelines.
-
Anthropic’s Fable 5 forces AI data governance questions
Anthropic’s guarded frontier model brings advanced software engineering capability to wider use while its retention policy and cyber safeguards create new enterprise governance decisions.
-
Gogs flaw puts self-hosted Git servers at risk
Rapid7 says an authenticated command execution flaw in Gogs can expose private repositories, credentials, and development infrastructure where self-hosted Git is weakly governed.
-
Microsoft repos restored after GitHub removals
Microsoft-owned GitHub repositories were temporarily removed while potential malicious content was investigated, disrupting Azure Functions deployment workflows and exposing CI/CD dependency risk.
-
UK presses device makers on child safety
The UK Government says technology companies must introduce device-level controls to stop children taking, sharing, receiving, or viewing nude images, with legislation threatened if industry does not act.
-
G7 sets cyber resilience priorities
The European Commission has backed a G7 cybersecurity declaration focused on post-quantum migration, AI security, telecoms resilience, SMEs, and software supply chain transparency.
-
ENISA ties SBOM adoption to CRA
ENISA says the Cyber Resilience Act is accelerating SBOM adoption, moving software component transparency deeper into procurement, vulnerability management, supplier assurance, and product-risk governance.
-
OpenAI expands ChatGPT Lockdown Mode
OpenAI has expanded Lockdown Mode across logged-in ChatGPT users, giving organisations a concrete control for reducing prompt-injection data-exfiltration paths.
-
Shai-Hulud hits scientific Python packages
A new Shai-Hulud wave has compromised science-focused PyPI packages, putting developer secrets, research workflows, and bioinformatics environments back in the software supply chain spotlight.



