AI pulls open source dependencies faster than humans can vet them. The perimeter was never the problem.

The ingredients were.

We broke down where application layer security actually stands in 2026.

https://substack.com/home/post/p-193372464

#OpenSourceSecurity #SoftwareSupplyChain #CyberSecurity

The Illusion of the Clean Perimeter

The modern software development lifecycle is no longer operating at human scale.

πŸš€ NEW on We ❀️ Open Source πŸš€

Bryan Behrenshausen offers a clear look at OSPO work, from inbound and outbound efforts to upstream contributions.

The piece also explores why software supply chain visibility is important, but can increase pressure on maintainers without added support.

https://allthingsopen.org/articles/inside-ospo-open-source-program-managers

#WeLoveOpenSource #OpenSource #OSPO #SoftwareSupplyChain

Microsoft Disrupts Open-Source Projects with Sudden Account Suspensions

Microsoft's sudden suspension of developer accounts has left maintainers of popular open-source projects locked out, unable to publish crucial security patches and software updates for Windows users. This abrupt move has sparked concern, with many wondering who will keep the digital roof fixed when the people who…

https://osintsights.com/microsoft-disrupts-open-source-projects-with-sudden-account-suspensions?utm_source=mastodon&utm_medium=social

#Opensource #Microsoft #AccountSuspensions #EmergingThreats #SoftwareSupplyChain

Microsoft Disrupts Open-Source Projects with Sudden Account Suspensions

Microsoft suspends developer accounts used in open-source projects, blocking security patches. Learn how account suspensions impact Windows users and what happens next, read now.

OSINTSights

Anchore SBOM Score = CVSS + EPSS + KEV status πŸ“Š

Because not all vulnerabilities are created equal ⚠️

https://anchore.com/platform/sbom/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps

FedRAMP compliance in weeks, not months ⚑

Ready-to-deploy policy packs for instant compliance feedback πŸ“‹

https://anchore.com/platform/enforce/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance

Built on 30M+ download open source tools (Syft & Grype) πŸ”§

Community-proven, enterprise-hardened πŸ’ͺ

https://anchore.com/platform/secure/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps

"Bring Your Own SBOM" sounds simple...

Until you try to manage thousands of them πŸ“Š

Scale is everything πŸ“ˆ

https://anchore.com/platform/sbom/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps

False positives killing your team's productivity? πŸ˜΅β€πŸ’«

Anchore Secure gives you signal, not noise πŸ“‘

https://anchore.com/platform/secure/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps

Your MCP server might be the weakest linkβ€”here's the data. @josh.bressers.name scanned 161 MCP images and found 9,000 vulns / 263 criticals. Read the breakdown and fixes: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/

#MCP #SoftwareSupplyChain #ContainerSecurity #DevSecOps

Axios npm Account Hijacked, Malware Injected

Axios npm account hijacked, malware injected into popular JavaScript library. Developers using versions 1.14.1 or 0.30.4 are at risk. Learn how to protect your code.

#AxiosAttack, #npmSecurity, #JavaScriptMalware, #CyberSecurity, #SoftwareSupplyChain

https://newsletter.tf/axios-npm-malware-attack-developers-risk/