NHS England withdraws public software over AI hacking fears
NHS England가 AI 기반 해킹 우려로 인해 공개 소프트웨어 저장소를 임시로 철회하고 내부 개발 소프트웨어를 공개 플랫폼에서 제거하도록 지시했다. 이는 기존의 공개 소스 정책에서 전환된 조치로, 모든 소스 코드 저장소를 기본적으로 비공개로 전환하고 예외적인 경우에만 공개를 허용한다. 직원들은 5월 11일까지 이 지침을 준수해야 하며, AI 도구가 시스템 취약점을 악용할 가능성에 대한 선제적 대응이다.

https://www.computing.co.uk/news/2026/security/nhs-england-withdraws-public-software-over-hacking-fears

#nhsengland #aisecurity #opensource #softwaresecurity #cybersecurity

NHS England withdraws public software over AI hacking fears

NHS England is moving to take down publicly accessible software repositories, citing concerns that emerging AI tools such as Mythos could be used to uncover ...

Die Cyberagentur hat die Ausschreibung für 3S veröffentlicht. Gesucht werden Ansätze, die Softwaresicherheit nachvollziehbar, messbar und vergleichbar machen. Statt bloßer Siegel braucht es belastbare Bewertungen für den digitalen Alltag.
Bewerbungen bis 15.06.2026. https://t1p.de/5q5gg
#Cyberagentur #Cybersicherheit #SoftwareSecurity #3S #Ausschreibung
3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
https://t1p.de/m85ce
#3S #Cybersecurity #SoftwareSecurity
https://nachrichten.idw-online.de/2026/05/04/no-more-blind-trust-in-software
No more blind faith in software - Cyberagentur

3S aims to make software security comprehensible, measurable and comparable for end users The Agentur für Innovation in der Cybersicherheit GmbH (Cyberagentur) published the call for proposals for the “Software Security Score (3S)” research program on 28 April 2026. The aim of the program is to make software security traceable, measurable and comparable. A virtual […]

Cyberagentur
3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
https://t1p.de/m85ce
#3S #Cybersecurity #SoftwareSecurity
https://nachrichten.idw-online.de/2026/05/04/schluss-mit-blindem-softwarevertrauen
No more blind faith in software - Cyberagentur

3S aims to make software security comprehensible, measurable and comparable for end users The Agentur für Innovation in der Cybersicherheit GmbH (Cyberagentur) published the call for proposals for the “Software Security Score (3S)” research program on 28 April 2026. The aim of the program is to make software security traceable, measurable and comparable. A virtual […]

Cyberagentur

Security Tip: Your security is only as strong as your deepest dependency. 🛡️

While auditing direct libraries is standard, transitive dependencies (libraries your dependencies rely on) are often overlooked. Regularly generate dependency trees to visualize these hidden layers and identify vulnerable sub-components.

Stay ahead of emerging threats at https://cvedatabase.com

#InfoSec #CyberSecurity #AppSec #SoftwareSecurity #CVE

CVEDatabase.com - Search & Analyze CVE Vulnerabilities

Search and analyze CVE vulnerabilities with instant access to CVSS scores, affected products, and AI-powered remediation guidance.

CVEDatabase.com
SAP unter Beschuss: Lieferkettenangriff auf npm-Pakete! Gestern, am 29. April 2026, traf ein gezielter Supply-Chain-Angriff – intern "Mini Shai-Hulud" genannt – die SAP-Entwicklungslandschaft. Angreifer schleusten bösartige Versionen dieser Pakete ein, mutmaßlich über einen kompromittierten Entwickleraccount. Dieser Vorfall zeigt einmal mehr: Software-Lieferketten sind kritische Angriffsflächen. #Cybersecurity #SupplyChain #SAP #npm #SoftwareSecurity #Cybercrime

Warning: CVE-2025-40739 (CWEs: ['CWE-125']) found no CAPEC relationships.
Warning: CVE-2025-40741 (CWEs: ['CWE-121']) found no CAPEC relationships.

#SoftwareSecurity #MemorySafety #CWE #ADBE
2/2

KI-Modell findet 271 Sicherheitslücken in Firefox 150 – Mozilla sieht Zeitenwende für Softwaresicherheit

Seit Februar arbeitet das Firefox-Sicherheitsteam mit KI-Modellen von Anthropic zusammen, um latente Schwachstellen im Browsercode aufzudecken.

https://www.all-about-security.de/ki-modell-findet-271-sicherheitsluecken-in-firefox-150-mozilla-sieht-zeitenwende-fuer-softwaresicherheit/

#firefox #anthropic #mozilla #softwaresicherheit #softwaresecurity

KI-gestützte Schwachstellenanalyse: 271 Lücken in Firefox

Mozilla hat 271 Sicherheitslücken in Firefox 150 entdeckt, dank KI-gestützter Schwachstellenanalyse mit Claude Mythos Preview.

All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing, IT-Sicherheit, Netzwerksicherheit, KI, Threats, DDoS, Identity & Access, Plattformsicherheit
Embedding AI in chat platforms is transforming software development, enabling rapid code generation but raising security, governance, and control challenges. Ensuring responsible use is critical to avoiding chaos.
Discover more at https://dev.to/rawveg/when-code-lives-in-chat-42h2
#HumanInTheLoop #AIinDevelopment #SoftwareSecurity #ChatOps
When Code Lives in Chat

Somewhere in a Fortune 500 company's engineering Slack, a product manager types a casual message:...

DEV Community

📌 Added to the BSides Luxembourg 2026 Lineup

🛠️🔐 𝗢𝗨𝗧 𝗢𝗙 𝗦𝗘𝗖𝗨𝗥𝗜𝗧𝗬 𝗘𝗫𝗖𝗘𝗣𝗧𝗜𝗢𝗡: 𝗪𝗛𝗔𝗧 𝗧𝗢 𝗗𝗢 𝗪𝗜𝗧𝗛𝗢𝗨𝗧 𝗔𝗡 𝗘𝗫𝗣𝗘𝗥𝗧 𝗧𝗢 𝗦𝗘𝗖𝗨𝗥𝗘 𝗬𝗢𝗨𝗥 𝗦𝗢𝗙𝗧𝗪𝗔𝗥𝗘 — Lisi Hocke ( @lisihocke )

💡 Take control in this Talk (40 min) and learn how development teams can build secure software even without dedicated security experts.

Security shouldn’t be a blocker waiting on experts. This session shows how everyday engineering activities—like planning features, collaborating across teams, and maintaining code—can be leveraged to significantly improve your product’s security posture without slowing down delivery.

Discover how to integrate threat modeling into regular workflows, catch vulnerabilities earlier through collaboration, and use production insights to detect malicious behavior. This talk empowers teams to shift from dependency on security teams to building “secure enough” systems through practical, developer-driven approaches.

Lisi Hocke (@lisihocke ) is a security engineer focused on product security, with a passion for quality, collaboration, and continuous learning. A strong advocate for whole-team approaches, she shares her experiences to help teams build resilient and secure software while delivering real value.

📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/

📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/

📲 View full schedule & build your agenda: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #SecureDevelopment #AppSec #DevSecOps #SoftwareSecurity #CyberSecurity